1

Contractual Supply Chain Security Jobs (NOW HIRING)

Showing results 21-40

Contractual Supply Chain Security information

See salary details

$46K

$144K

How much do contractual supply chain security jobs pay per year?

As of Sep 5, 2026, the average yearly pay for contractual supply chain security in the United States is $136,453.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $143,000.00 per year, depending on experience, location, and employer.

What is the difference between Contractual Supply Chain Security vs Supply Chain Security Coordinator?

AspectContractual Supply Chain SecuritySupply Chain Security Coordinator
CredentialsCertifications like CTPAT, TSA, or security managementCertifications such as CTPAT, TSA, or logistics security
Work EnvironmentContract-based, often involving multiple clients and vendorsIn-house or third-party logistics companies, coordinating security measures
Employer & Industry UsageLogistics, shipping, and supply chain companiesManufacturing, distribution, and logistics sectors

Contractual Supply Chain Security focuses on managing security through contractual agreements with vendors and partners, ensuring compliance and risk mitigation. In contrast, a Supply Chain Security Coordinator actively oversees security protocols within an organization or logistics team. Both roles require similar certifications and work in related environments, but their scope and focus differ—one emphasizes contractual compliance, the other operational security management.

What cities are hiring for Contractual Supply Chain Security jobs?

Cities with the most Contractual Supply Chain Security job openings:

What are the most commonly searched types of Supply Chain Security jobs?

The most popular types of Supply Chain Security jobs are:

What states have the most Contractual Supply Chain Security jobs?

States with the most job openings for Contractual Supply Chain Security jobs include:

DevSecOps & Supply Chain Security Consultant

Zappsec Inc.

Tewksbury, MA • On-site

Full-time

Posted 2 days ago

New


Job description

 

DevSecOps & Supply Chain Security Consultant

Role Summary

  • Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. 
  • The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence. 
  • The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.

Key Responsibilities

 
  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability. 
  • Review SDLC processes, tooling, and secure development practices
  • Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
  • Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
  • Review secrets management across development, build, deployment, and operational environments
  • Assess logging, auditability, and security event traceability controls
  • Evaluate vulnerability management, remediation tracking, and patch governance processes
  • Support lifecycle security assessment, compliance evidence mapping, and traceability
  • Contribute to assessment reporting, remediation guidance, and release governance reviews
  • Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.

Required Skills & Experience

Mandatory:

  • Strong understanding of DevSecOps and secure software delivery practices
  • Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
  • Familiarity with CI/CD security controls and artifact integrity validation
  • Experience with vulnerability management and dependency governance programs
  • Understanding of lifecycle security, auditability, and compliance evidence requirements
  • Experience with secrets management and secure release governance
  • SBOM Analysis (CycloneDX, SPDX, VEX/CSAF)
  • Artifact Integrity
  • SAST, DAST, Dependency & Secrets Scanning
  • Vulnerability Management & Remediation Governance
  • Secrets Management
  • Compliance Evidence & Audit Traceability
  • CRA / Regulatory Security Assessments
  • Syft and related SBOM tools
  • Secure Release Governance & Security Controls Validation
  • Build provenance and software-delivery traceability
  • Artifact signing, verification and tamper testing
  • Container, registry, build-agent and CI/CD runner security
  • Infrastructure-as-Code and pipeline-as-code security
  • Signing-key, certificate and HSM lifecycle controls
  • SBOM generation and binary-to-SBOM reconciliation
  • Open-source and third-party dependency governance
  • EOL/EOS and patch-lifecycle governance
  • Security exception and release-risk governance
  • Pipeline policy-as-code and automated security gates
  • Vulnerability metrics and release-readiness reporting
  • NIST SSDF and secure software supply-chain practices
  • Supplier security and software-acquisition assessments
  • Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
  • US Citizen or Green Card holder (US Person)

Good to have:

  • Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
  • Experience participating in engagement related to export-controlled environments
  • Familiarity with SLSA or modern software supply chain security practices
  • Strong documentation skills
 

Preferred Certifications

  • CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
 

Years of Required Experience

  • 10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
  • 2+ years of hands-on SBOM analysis experience.

 

Powered by JazzHR

oPM0jGmMGC