Senior DevSecOps Engineer

CGI•Lafayette, LA
•Onsite

About The Position

CGI is seeking a Supply Chain Engineer to lead and enable enterprise initiatives that strengthen secure software delivery. This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL. In this role, you'll enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository. You'll build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems. You'll drive dependency upgrades and vulnerability remediation efforts, support onboarding of emerging ecosystems including AI/ML frameworks, and build reporting and metrics to track software supply chain health, policy compliance, and repository utilization. This role also involves enabling CI/CD artifact signing and verification, implementing SLSA build provenance and attestations, and integrating SBOM generation into build and deployment pipelines. You'll work closely with security and development teams to improve software supply chain visibility and integrity across the organization. This is a great opportunity for someone passionate about DevSecOps and building secure, trustworthy software delivery pipelines at scale.

Requirements

  • 5+ years in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
  • Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository, or similar tools like jFrog
  • Experience building and maintaining automated Open Source Software evaluation policies and workflows
  • Familiarity with artifact signing technologies such as Sigstore/Cosign, GPG, or Notary
  • Experience with SLSA provenance, in toto attestations, or similar frameworks
  • Background generating SBOMs using CycloneDX, SPDX, or Syft
  • CI/CD experience, ideally with GitLab (GitHub Actions also welcome)
  • Strong AWS skills across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch
  • Experience integrating security tooling directly into CI/CD pipelines
  • Solid scripting ability in Python, Bash, or Go
  • Experience maintaining enterprise open source platforms
  • Familiarity with OCI registries and package ecosystems (Maven, npm, PyPI, NuGet)
  • Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design principles

Responsibilities

  • Enhance artifact management, policy governance, and open source lifecycle processes using tools like Sonatype and Nexus Repository.
  • Build and automate software approval workflows, quarantine/waiver processes, and repository proxy strategies across supported ecosystems.
  • Drive dependency upgrades and vulnerability remediation efforts.
  • Support onboarding of emerging ecosystems including AI/ML frameworks.
  • Build reporting and metrics to track software supply chain health, policy compliance, and repository utilization.
  • Enable CI/CD artifact signing and verification.
  • Implement SLSA build provenance and attestations.
  • Integrate SBOM generation into build and deployment pipelines.
  • Work closely with security and development teams to improve software supply chain visibility and integrity across the organization.

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan and the share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well being programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service