SBOM generation, cosign image signing, and Sigstore policy enforcement * Automate OS image builds using Packer (QEMU, vSphere) targeting RHEL, AlmaLinux, Debian/Ubuntu, and Windows * Manage secrets ...
SBOM generation, cosign image signing, and Sigstore policy enforcement * Automate OS image builds using Packer (QEMU, vSphere) targeting RHEL, AlmaLinux, Debian/Ubuntu, and Windows * Manage secrets ...
DevSecOps Engineer
Sarasota, FL · On-site
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Quick apply
DevSecOps Engineer
Sarasota, FL · On-site
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Quick apply
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Senior DevSecOps Software Engineer (Onsite)
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis,container security reporting tools likesnyk,trivyandgrype,code signing tools likesigstoreand cosign,Yoctobuild system for Embedded ...
Senior DevSecOps Software Engineer (Onsite)
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis,container security reporting tools likesnyk,trivyandgrype,code signing tools likesigstoreand cosign,Yoctobuild system for Embedded ...
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Quick apply
Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation. * Familiarity with OpenStack, Ceph, or other large-scale open ...
Senior DevSecOps Software Engineer (Onsite)
Saint Petersburg, FL · On-site
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis, container security reporting tools like snyk, trivy and grype, code signing tools like sigstore and cosign, Yocto build system for ...
Senior DevSecOps Software Engineer (Onsite)
Saint Petersburg, FL · On-site
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis, container security reporting tools like snyk, trivy and grype, code signing tools like sigstore and cosign, Yocto build system for ...
Senior DevSecOps Software Engineer (Onsite)
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis, container security reporting tools like snyk, trivy and grype, code signing tools like sigstore and cosign, Yocto build system for ...
Senior DevSecOps Software Engineer (Onsite)
$115K - $152K/yr
Experience configuring and managing Coverity static code analysis, container security reporting tools like snyk, trivy and grype, code signing tools like sigstore and cosign, Yocto build system for ...
Cosign information
What is the difference between Cosign vs Loan Officer?
| Aspect | Cosign | Loan Officer |
|---|---|---|
| Required Credentials | Minimal; often no formal certification needed | Typically requires a mortgage or finance license, certifications vary by state |
| Work Environment | Personal, often informal; assisting individuals with credit | Bank or lending institution; office-based or remote |
| Industry Usage | Used in credit and lending contexts to support borrowers | Used in banking, mortgage, and lending industries |
| Common Search/Comparison | Often compared for credit support roles | Compared for lending and mortgage services |
While a cosign helps a borrower secure credit by vouching for them, a loan officer evaluates and approves loan applications, often working within financial institutions. Both roles are integral to lending but differ in responsibilities, credentials, and work environment.

Other
Posted 7 hours ago
Job description
We are seeking a DevSecOps Engineer with deep Kubernetes expertise to design, implement, and maintain secure, scalable cloud-native platforms. This role bridges development, security, and operations to embed security throughout the software delivery lifecycle while enabling high-velocity engineering teams. U.S. Citizenship Requirement: Due to contractual requirements and the nature of our work supporting U.S. Government customers, this position requires U.S. citizenship. Key Responsibilities (Principal Duties and Accountabilities *Essential Functions) Platform & Infrastructure * Design, provision, and maintain production Kubernetes clusters (RKE2 / EKS / GKE / AKS) across cloud and on-premises environments
* Manage cluster lifecycle: upgrades, node pool scaling, multi-tenancy, and namespace governance
* Implement and maintain CNI solutions (Calico, Cilium, Multus) including advanced networking topologies such as macvlan and SR-IOV
* Operate GitOps workflows (e. g. ArgoCD) for declarative, auditable cluster state management
* Develop and maintain Helm charts for platform and application services DevSecOps & CI/CD * Build and maintain CI/CD pipelines in GitLab CI (and/or GitHub Actions) with integrated security scanning and artifact signing
* Integrate SAST, DAST, SCA, and container image scanning (Trivy, Grype, Semgrep) into pipeline gates
* Implement supply-chain security controls: SBOM generation, cosign image signing, and Sigstore policy enforcement
* Automate OS image builds using Packer (QEMU, vSphere) targeting RHEL, AlmaLinux, Debian/Ubuntu, and Windows
* Manage secrets at scale using Vault, External Secrets Operator, or equivalent solutions Security & Compliance * Enforce runtime security through admission controllers (Kyverno / OPA Gatekeeper), Pod Security Standards, and network policies
* Own vulnerability management processes including scheduled scanning, triage, and remediation SLAs
* Support compliance initiatives (SOC 2, FedRAMP, NIST 800-53) by maintaining audit-ready infrastructure-as-code and evidence artifacts
* Conduct threat modeling and security architecture reviews for new platform capabilities
* Respond to and lead post-mortems for security incidents and infrastructure outages Observability & Reliability * Deploy and operate observability stacks: Prometheus, Grafana, Loki, and OpenTelemetry collectors
* Define and track SLOs/SLAs; build alerting and on-call runbooks to drive reliability improvements
* Implement cost observability and right-sizing workflows for cloud and on-prem workloads Collaboration & Developer Enablement * Partner with development teams to design deployment patterns, resource quotas, and autoscaling strategies
* Produce clear documentation, runbooks, and internal training materials for platform capabilities
* Mentor junior engineers and participate in architecture decision records (ADRs)