Omgtech
DevSecOps & Supply Chain Security Consultant - (Onsite - Boston, MA)
Boston, Massachusetts
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Role family
- Supply chain
- Seniority
- Mid level
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 10 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
DevSecOps & Supply Chain Security Consultant - ( Onsite - Boston, MA)
We are looking to hire a candidate with the mentioned skill sets and experience for one of our clients,
Job Summary
We are seeking a DevSecOps & Supply Chain Security Consultant with 10+ years of experience in secure software delivery, CI/CD, and software supply-chain security. The consultant will focus on secure SDLC, CI/CD pipeline architecture and security, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependency and secrets management, SAST/DAST, containers, IaC, vulnerability governance, and regulatory evidence.
The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions, remediation, release readiness, and residual risk and will produce audit-ready findings and stakeholder-ready reporting.
Work Authorization: Must be a US Citizen or Green Card holder (US Person) .
Travel: Up to three (3) weeks of travel to the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be arranged and covered. Travel may be a single visit or split across multiple visits based on project requirements.
Key Responsibilities
Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management.
Review SDLC processes, security tooling, and secure development practices.
Assess SCA, SBOM accuracy/completeness, dependency governance, and third-party risk.
Evaluate CI/CD pipeline security, artifact integrity, secure release controls, and build provenance.
Validate source-to-release traceability, artifact signing and promotion, tamper resistance, SBOM accuracy, security gates, exceptions, and remediation decisions.
Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls.
Evaluate Infrastructure-as-Code, pipeline-as-code, policy-as-code, and automated security-gate effectiveness.
Review secrets management across development, build, deployment, and operational environments.
Evaluate vulnerability management, remediation tracking, patch governance, EOL/EOS, and release-risk governance.
Assess signing-key, certificate, and HSM lifecycle controls.
Validate SBOM generation and binary-to-SBOM reconciliation.
Support lifecycle security assessments, compliance evidence mapping, and audit traceability.
Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, remediation guidance, and stakeholder-ready executive communication.
Recommend finding-specific follow-up work and support release governance reviews.
Required Skills / Experience
10+ years of experience in secure CI/CD pipeline setup, governance, and controls validation across different technology stacks.
2+ years of hands-on SBOM analysis experience .
Strong understanding of DevSecOps and secure software delivery practices .
Strong experience with SBOM frameworks: CycloneDX, SPDX, VEX/CSAF .
Experience with SCA, SAST, DAST, dependency scanning, and secrets scanning .
Experience with artifact integrity, artifact signing, verification, tamper testing, and build provenance .
Strong knowledge of CI/CD security, secure release governance, and automated security gates .
Experience with vulnerability management, remediation governance, dependency governance, and patch lifecycle management .
Experience with secrets management and secure release controls .
Knowledge of container, registry, build-agent, and CI/CD runner security .
Experience with Infrastructure-as-Code and pipeline-as-code security .
Knowledge of policy-as-code and security controls validation .
Experience with compliance evidence, audit traceability, and regulatory security assessments .
Knowledge of NIST SSDF and secure software supply-chain practices.
Experience with supplier security and software-acquisition assessments .
Hands-on experience with tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins, and Azure DevOps .
Experience with CRA / regulatory security assessments is highly preferred.
Familiarity with SLSA or modern software supply-chain security practices is a plus.
Experience with regulated products, export-controlled environments, or compliance-driven cybersecurity assessments is preferred.
Strong documentation and stakeholder communication skills.
Candidate needs to be US Citizen or Green Card holder.
Preferred Certifications
CSSLP
Certified DevSecOps Professional
Other relevant product-security credentials.
Location & Travel
Location: Boston, MA
On-site: Ability to work from the Boston office for 4–6 weeks during the engagement .
Travel: Up to 3 weeks at the client’s Tewksbury, MA site during the engagement. Travel and accommodation expenses will be covered.
Other Job Details:
Job Type: C2C or W2.
Location: Boston, MA, USA.
Interviews: Video interviews.
Docs required: ID proof will be required.
Similar jobs
- Security ConsultantVoxai Solutions, Inc. · Coppell, TXFirst seen today
- Information Security ConsultantHatchit · RemoteFirst seen 5d agoremote
- Product Security ConsultantMymoose · US - RemoteFirst seen 11d agoremote
- Operational Technology Security ConsultantCoalfire · United StatesFirst seen 16d ago
- Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)Charlesriverassociates · Boston, MA, United States; Chicago, IL, United States; Dallas, Texas, United States; Houston, Texas, United States; New York, NY, United States; Oakland, CA, United States; Washington, DC, United StatesFirst seen 19d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job