Role: DevSecOps Engineer
Location: Atlanta, GA
Hire Type: Direct Hire
Position Type: Full Time
Responsibilities
Lead the design and enablement of enterprise software supply chain initiatives to support secure software delivery.
Enhance Sonatype Repository artifact management, IQ firewall policy governance, and open-source software lifecycle processes.
Define and automate software approval workflows, quarantine waiver processes, and lifecycle management practices.
Design and enable repository proxy strategies across supported software ecosystems.
Drive dependency upgrade initiatives and vulnerability remediation workflows.
Support the design and onboarding of emerging ecosystems, including AI/ML frameworks.
Design and implement reporting and metrics capabilities to measure software supply chain health, policy compliance, and repository utilization.
Design and enable CI/CD artifact signing and verification capabilities for software builds.
Design and implement SLSA build provenance and attestation frameworks across CI/CD platforms.
Integrate SBOM generation and software metadata into build and deployment pipelines.
Collaborate closely with security and development teams to enhance software supply chain visibility, integrity, and compliance.
Required Technical Skills
Minimum 9+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain Engineering.
Hands-on experience with Sonatype Lifecycle (IQ Server) and Nexus Repository (or comparable tooling, e.g., jFrog).
Proven experience creating and maintaining automated Open-Source Software Evaluation policies and workflows.
Experience implementing artifact signing technologies such as Sigstore/Cosign, GPG, Notary, or similar solutions.
Strong understanding of SLSA provenance, in-toto attestations, or comparable software supply chain security frameworks.
Experience with SBOM generation tools and standards, including CycloneDX, SPDX, and Syft.
CI/CD experience with GitLab preferred, or comparable platforms such as GitHub Actions.
Strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Function, and CloudWatch.
Experience integrating security tools and controls into CI/CD pipelines.
Strong scripting and automation skills using Python, Bash, or Go.
Experience designing, implementing, and maintaining enterprise Open-Source platforms.
Familiarity with OCI registries and package ecosystems, including Maven, npm, PyPI, and NuGet.
Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives.
Skills Required
- Minimum 9+ years of experience in DevSecOps, Platform Engineering, or Software Supply Chain Engineering
- Hands-on experience with Sonatype Lifecycle IQ Server and Nexus Repository or comparable tooling
- Experience creating and maintaining automated open-source software evaluation policies and workflows
- Experience implementing artifact signing technologies such as Sigstore/Cosign, GPG, or Notary
- Strong understanding of SLSA provenance, in-toto attestations, or comparable software supply chain security frameworks
- Experience with SBOM generation tools and standards, including CycloneDX, SPDX, and Syft
- CI/CD experience with GitLab preferred or comparable platforms such as GitHub Actions
- Strong AWS experience across IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch
- Experience integrating security tools and controls into CI/CD pipelines
- Strong scripting and automation skills using Python, Bash, or Go
- Experience designing, implementing, and maintaining enterprise open-source platforms
- Familiarity with OCI registries and package ecosystems including Maven, npm, PyPI, and NuGet
- Knowledge of NIST SSDF, Executive Order 14028, and Secure by Design initiatives
Hexaware Technologies Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Hexaware Technologies and has not been reviewed or approved by Hexaware Technologies.
-
Healthcare Strength — Feedback suggests health insurance is a standout element, often described as strong and comparable or better than many employers. Medical coverage and related protections are repeatedly highlighted as reliable pillars of the package.
-
Parental & Family Support — Parental leave options, including extended paid leave in some locations, are offered and seen as valuable for family needs. Feedback suggests these policies complement core medical coverage for a more complete family safety net.
-
Wellbeing & Lifestyle Benefits — Wellbeing resources such as an Employee Assistance Program, wellness initiatives, on-site gyms, and engagement activities provide lifestyle support. These offerings are reinforced by flexible work options and shift-related extras where applicable.
Hexaware Technologies Insights
What We Do
At Hexaware, we're not just a global technology and business process services company; we're a community of 27,000 Hexawarians dedicated to one singular purpose: creating smiles through the power of great people and technology. With a presence in 40+ offices across 19 countries, we empower enterprises worldwide to embark on their digital transformation journey with unparalleled scale and speed. As an employer, we're more than just a workplace. We put our people first, foster diversity and inclusivity, and prioritize their growth through robust learning and development programs. Our culture is a canvas for innovation as we work toward our shared vision of becoming the world’s most loved digital transformation partner. Exciting, isn’t it? Visit www.hexaware.com to join us in embracing the magic of technology, as we passionately advocate for its potential to transform lives today and shape a brighter future. Together, we'll make the digital world a better place.








