DevSecOps Architect

Cynet SystemsSeattle, WA

About The Position

This role involves assessing current DevSecOps, CI/CD, container build, registry, scanning, and deployment practices. The architect will identify gaps related to container security, image provenance, vulnerability management, artifact signing, SBOM generation, disconnected deployment, and operational controls. A key responsibility is to design a secure reference architecture for trusted container construction, scanning, signing, transfer, deployment, upgrade, and tracking. The architect will also define and implement a foundational trusted container build pipeline, support the creation of hardened container image patterns, and configure or integrate SBOM generation, vulnerability scanning, artifact signing, and signature verification. Additionally, the role includes defining approaches for offline vulnerability feed updates and scanner database refresh for disconnected environments, supporting the packaging and transfer of container artifacts across air-gapped processes, and assisting with the deployment and validation of container workloads in disconnected or lab environments. The architect will also define image upgrade, rollback, re-scan, and operational support processes, design asset tracking for deployed images and related metadata, prepare comprehensive documentation, and conduct knowledge-transfer sessions.

Requirements

  • 8+ years of experience in DevSecOps.

Responsibilities

  • Assess current DevSecOps, CI/CD, container build, registry, scanning, and deployment practices.
  • Identify gaps related to container security, image provenance, vulnerability management, artifact signing, SBOM generation, disconnected deployment, and operational controls.
  • Design a secure reference architecture for trusted container construction, scanning, signing, transfer, deployment, upgrade, and tracking.
  • Define and implement a foundational trusted container build pipeline using approved and known-good sources.
  • Support creation of hardened and minimal container image patterns.
  • Configure or integrate SBOM generation, vulnerability scanning, artifact signing, and signature verification.
  • Define an approach for offline vulnerability feed updates and scanner database refresh for disconnected environments.
  • Support packaging and transfer of container images, SBOMs, signatures, scan results, and related metadata across an air-gapped process.
  • Support deployment and validation of a representative container workload in a disconnected or representative lab environment.
  • Define image upgrade, rollback, re-scan, and operational support processes.
  • Design or support asset tracking for deployed images, versions, SBOMs, signatures, provenance, and patch status.
  • Prepare architecture documentation, gap analysis, risk findings, implementation roadmap, runbooks, and POC validation report.
  • Conduct knowledge-transfer sessions with engineering, security, and operations teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service