Job Summary
We are looking for one senior, hands-on DevSecOps resource to support a customer project focused on designing and validating a secure container supply chain for disconnected / air-gapped lab environments.
The resource will be responsible for assessing the current container build and delivery process, defining the target DevSecOps reference architecture, creating a trusted container build approach, supporting SBOM generation, vulnerability scanning, artifact signing, offline transfer, deployment into disconnected environments, asset tracking, operational runbooks, and end-to-end proof-of-concept execution.
This is a hands-on architect role. The candidate must be able to lead customer discussions as well as perform technical implementation and POC configuration.
Key Responsibilities
- Assess current DevSecOps, CI/CD, container build, registry, scanning, and deployment practices.
- Identify gaps related to container security, image provenance, vulnerability management, artifact signing, SBOM generation, disconnected deployment, and operational controls.
- Design a secure reference architecture for trusted container construction, scanning, signing, transfer, deployment, upgrade, and tracking.
- Define and implement a foundational trusted container build pipeline using approved and known-good sources.
- Support creation of hardened and minimal container image patterns.
- Configure or integrate SBOM generation, vulnerability scanning, artifact signing, and signature verification.
- Define an approach for offline vulnerability feed updates and scanner database refresh for disconnected environments.
- Support packaging and transfer of container images, SBOMs, signatures, scan results, and related metadata across an air-gapped process.
- Support deployment and validation of a representative container workload in a disconnected or representative lab environment.
- Define image upgrade, rollback, re-scan, and operational support processes.
- Design or support asset tracking for deployed images, versions, SBOMs, signatures, provenance, and patch status.
- Prepare architecture documentation, gap analysis, risk findings, implementation roadmap, runbooks, and POC validation report.
- Conduct knowledge-transfer sessions with customer engineering, security, and operations teams.
Skill Requirements
- Strong hands-on experience in DevOps / DevSecOps implementation.
- Strong experience with CI/CD tools such as Jenkins, GitLab CI, GitHub Actions, Azure DevOps, Tekton, or equivalent.
- Strong experience with container technologies such as Docker, Podman, Buildah, BuildKit, Kaniko, or equivalent.
- Experience with Kubernetes, OpenShift, Rancher, or similar container platforms.
- Experience with container registries and artifact repositories such as Harbor, JFrog Artifactory, Nexus, OpenShift Registry, or equivalent.
- Experience with secure container image build, image hardening, dependency pinning, minimal base images, and image immutability.
- Experience with SBOM generation and management using tools/formats such as SPDX, CycloneDX, Syft, Trivy, Anchore, or equivalent.
- Experience with container vulnerability scanning tools such as Trivy, Grype, Anchore, Prisma Cloud, Snyk, Clair, Black Duck, or equivalent.
- Experience with artifact signing, signature verification, provenance, and attestation using tools such as Cosign, Notation, Sigstore, GPG, in-toto, or equivalent.
- Understanding of secure software supply-chain concepts including SLSA, NIST SSDF, trusted sources, approved repositories, and build provenance.
- Experience with offline / air-gapped / disconnected environment patterns, including offline artifact movement, vulnerability feed updates, and restricted-network deployments.
- Experience with Helm, Kustomize, Kubernetes manifests, deployment automation, upgrade, rollback, and re-scan processes.
- Ability to prepare technical architecture documents, operational runbooks, risk analysis, and POC findings.
- Strong customer-facing communication skills and ability to work with security, engineering, infrastructure, and operations stakeholders.
Other Requirements
Preferred Skills
- Prior experience in aerospace, defense, federal, classified lab, or highly regulated environments.
- Experience with OpenShift or Kubernetes in disconnected environments.
- Experience with CUI, ITAR, EAR, or similar controlled-data environments.
- Experience designing secure software factories or enterprise DevSecOps platforms.
- Relevant certifications such as CKA, CKAD, CKS, CISSP, CCSP, DevSecOps, Kubernetes Security Specialist, AWS Security, Azure Security, or equivalent.
Expected Deliverables
- Current-state assessment.
- Target DevSecOps reference architecture.
- Gap and risk analysis.
- Secure container build approach.
- Foundational trusted build pipeline for representative workload.
- SBOM and vulnerability scanning approach.
- Artifact signing and verification approach.
- Offline transfer and disconnected lab operations approach.
- Asset tracking and inventory approach.
- Operations runbooks.
- End-to-end POC support.
- POC findings and validation report.
- Knowledge-transfer material.
Soft Skills
- Strong ownership and hands-on problem-solving ability.
- Ability to work independently as the single primary resource.
- Ability to lead customer workshops and technical discussions.
- Strong documentation and presentation skills.
- Ability to identify assumptions, risks, dependencies, and customer action items.
- Ability to operate effectively in a T&M engagement with evolving customer inputs and dependencies.
Suggested Profile Summary for Resourcing Team
Need one senior hands-on DevSecOps / container security architect with 8+ years of experience, preferably 10+ years, who can independently lead assessment, architecture, secure container pipeline design, SBOM, vulnerability scanning, artifact signing, Kubernetes/container registry integration, air-gapped deployment process, runbook creation, and POC execution for disconnected lab environments.