DevSecOps & Supply Chain Security Consultant Role Summary * Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. * The role covers ...
DevSecOps & Supply Chain Security Consultant Role Summary * Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. * The role covers ...
DevSecOps & Supply Chain Security Consultant Role Summary * Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. * The role covers ...
Quick apply
DevSecOps & Supply Chain Security Consultant Role Summary * Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. * The role covers ...
DevSecOps Engineer
Austin, TX · On-site
$58.25 - $77.75/hr
Overview Allied Consultants, Inc is a proudly Austin based firm with over 34 years of experience ... Responsibilities The DevSecOps Engineer will support the administration, implementation ...
DevSecOps Engineer
Austin, TX · On-site
$58.25 - $77.75/hr
Overview Allied Consultants, Inc is a proudly Austin based firm with over 34 years of experience ... Responsibilities The DevSecOps Engineer will support the administration, implementation ...
Jr DevSecOps
Washington, DC · On-site
$75K - $90K/yr
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
Jr DevSecOps
Washington, DC · On-site
$75K - $90K/yr
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
Jr DevSecOps
Washington, DC · On-site
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
Quick apply
Jr DevSecOps
Washington, DC · On-site
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
Jr DevSecOps
Washington, DC · On-site
$75K - $90K/yr
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
Jr DevSecOps
Washington, DC · On-site
$75K - $90K/yr
The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...
DevSecOps - Open Call
Washington, DC · On-site
DevSecOps Project Manager A few things worth knowing Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies ...
DevSecOps - Open Call
Washington, DC · On-site
DevSecOps Project Manager A few things worth knowing Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies ...
DevSecOps - Open Call
Washington, DC · On-site
DevSecOps Project Manager A few things worth knowing Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies ...
Quick apply
DevSecOps - Open Call
Washington, DC · On-site
DevSecOps Project Manager A few things worth knowing Devis is a leading provider of innovative software development, management, and consulting services, specializing in cutting-edge technologies ...
Senior DevSecOps / Cloud Governance Consultant
$60 - $81.75/hr
Trility Consulting is seeking a Senior DevSecOps/Cloud Governance Consultant to lead an eight-week engagement focused on establishing practical cloud governance, financial management, and policy ...
Senior DevSecOps / Cloud Governance Consultant
$60 - $81.75/hr
Trility Consulting is seeking a Senior DevSecOps/Cloud Governance Consultant to lead an eight-week engagement focused on establishing practical cloud governance, financial management, and policy ...
Verstärken Sie unser Team als Cyber Security Consultant - DevSecOps & Container Security (m/w/d) an einem unserer Standorte deutschlandweit. Ob Architektur, Forensik oder Cloud - unser ...
Verstärken Sie unser Team als Cyber Security Consultant - DevSecOps & Container Security (m/w/d) an einem unserer Standorte deutschlandweit. Ob Architektur, Forensik oder Cloud - unser ...
DevSecOps Engineer
Bethesda, MD · On-site
$56.25 - $77/hr
Job Summary : Spark Tek Inc is seeking a DevSecOps Engineer to oversee the development ... and consulting for various industries. Founded in 2021, the company is headquartered in Farmers ...
DevSecOps Engineer
Bethesda, MD · On-site
$56.25 - $77/hr
Job Summary : Spark Tek Inc is seeking a DevSecOps Engineer to oversee the development ... and consulting for various industries. Founded in 2021, the company is headquartered in Farmers ...
DevSecOps Engineer
Reston, VA · On-site
DevSecOps Engineer Full Time Professional Reston, VA, US Requisition ID: 1081 Apply COMPANY ... consultative environment. #CJ
DevSecOps Engineer
Reston, VA · On-site
DevSecOps Engineer Full Time Professional Reston, VA, US Requisition ID: 1081 Apply COMPANY ... consultative environment. #CJ
DevSecOps SME
MD · On-site
$90K - $160K/yr
Join Barrow Wise Consulting, LLC today. Responsibilities: The DevSecOps SME will support Barrow Wise's DHS project and perform the following duties: * Evaluate software delivery practices and help ...
DevSecOps SME
MD · On-site
$90K - $160K/yr
Join Barrow Wise Consulting, LLC today. Responsibilities: The DevSecOps SME will support Barrow Wise's DHS project and perform the following duties: * Evaluate software delivery practices and help ...
... DevSecOps/Security & Compliance Consultant, you will implement technical solutions as part of a team for customer engagements. This role requires strong teamwork, communication, patience and ...
Quick apply
... DevSecOps/Security & Compliance Consultant, you will implement technical solutions as part of a team for customer engagements. This role requires strong teamwork, communication, patience and ...
Senior DevSecOps, Cloud Consultant
Manhattan, NY · On-site +1
You must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future As an AWS DevSecOps/Security & Compliance Consultant, you will ...
Senior DevSecOps, Cloud Consultant
Manhattan, NY · On-site +1
You must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future As an AWS DevSecOps/Security & Compliance Consultant, you will ...
Senior DevSecOps Engineer with Security Clearance
King Of Prussia, PA · On-site
$111K - $153K/yr
King of Prussia, PA Type of Role: Full-Time, Onsite Shift: 9x80 Schedule (Every other Friday off) Position Overview The Global Edge Consultants, LLC is seeking a Senior DevSecOps Engineer to support ...
Senior DevSecOps Engineer with Security Clearance
King Of Prussia, PA · On-site
$111K - $153K/yr
King of Prussia, PA Type of Role: Full-Time, Onsite Shift: 9x80 Schedule (Every other Friday off) Position Overview The Global Edge Consultants, LLC is seeking a Senior DevSecOps Engineer to support ...
King of Prussia, PA Type of Role: Full-Time, Onsite Shift: 9x80 Schedule (Every other Friday off) POSITION OVERVIEW The Global Edge Consultants, LLC is seeking a Staff DevSecOps Engineer to support ...
King of Prussia, PA Type of Role: Full-Time, Onsite Shift: 9x80 Schedule (Every other Friday off) POSITION OVERVIEW The Global Edge Consultants, LLC is seeking a Staff DevSecOps Engineer to support ...
DevSecOps Engineer
Reston, VA · On-site
POSITION SUMMARY As a DevSecOps Engineer at Rancher Government Solutions, you will be a strategic ... consultative environment. #J-18808-Ljbffr
DevSecOps Engineer
Reston, VA · On-site
POSITION SUMMARY As a DevSecOps Engineer at Rancher Government Solutions, you will be a strategic ... consultative environment. #J-18808-Ljbffr
DevSecOps Engineer
Columbia, MD · On-site
Title: Agentic AI and DevSecOps Engineer Location: Hybrid in Columbia, MD - 2x a week Clearance ... Since 2007, we've partnered with federal and state agencies to deliver IT, training, and consulting ...
DevSecOps Engineer
Columbia, MD · On-site
Title: Agentic AI and DevSecOps Engineer Location: Hybrid in Columbia, MD - 2x a week Clearance ... Since 2007, we've partnered with federal and state agencies to deliver IT, training, and consulting ...
DevSecOps Engineer
$54.25 - $74.25/hr
Description LT Consulting is seeking a DevSecOps Engineer with an active TS/SCI with polygraph to to design, build, and automate secure cloud-based infrastructure and workflows for mission-critical ...
Quick apply
DevSecOps Engineer
$54.25 - $74.25/hr
Description LT Consulting is seeking a DevSecOps Engineer with an active TS/SCI with polygraph to to design, build, and automate secure cloud-based infrastructure and workflows for mission-critical ...
Devsecops Consultant information
See salary details
$10.34 - $17.31
5% of jobs
$17.31 - $24.28
6% of jobs
$28.14 is the 25th percentile. Wages below this are outliers.
$24.28 - $31.25
24% of jobs
The median wage is $35.17 / hr.
$31.25 - $38.22
25% of jobs
$38.22 - $45.19
14% of jobs
$45.39 is the 75th percentile. Wages above this are outliers.
$45.19 - $52.16
9% of jobs
$52.16 - $59.13
5% of jobs
$59.13 - $66.11
3% of jobs
$66.11 - $73.08
3% of jobs
$73.08 - $80.05
2% of jobs
$80.05 - $87.02
2% of jobs
$10
$41
$87
How much do devsecops consultant jobs pay per hour?
What is a DevSecOps consultant?
What are the key skills and qualifications needed to thrive as a DevSecOps consultant, and why are they important?
What are some common challenges DevSecOps consultants face when implementing security practices in CI/CD pipelines?
What is the difference between Devsecops Consultant vs Security Engineer?
| Aspect | Devsecops Consultant | Security Engineer |
|---|---|---|
| Certifications | Certified DevSecOps Professional, CISSP, CISA | CISSP, CEH, Security+ |
| Work Environment | Collaborates across development, operations, and security teams in cloud and on-premises environments | Focuses on implementing security measures within IT infrastructure and applications |
| Employer & Industry Usage | Consulting firms, tech companies, organizations adopting DevSecOps practices | IT departments, cybersecurity firms, enterprise organizations |
While both roles focus on security, a Devsecops Consultant integrates security into the development and operations pipeline, promoting automation and collaboration. A Security Engineer primarily implements and manages security measures within IT systems. The roles often overlap but differ in scope and focus areas.
What cities are hiring for Devsecops Consultant jobs?
Cities with the most Devsecops Consultant job openings:
What states have the most Devsecops Consultant jobs?
States with the most job openings for Devsecops Consultant jobs include:
What are popular job titles related to Devsecops Consultant jobs?
For Devsecops Consultant jobs, the most frequently searched job titles are:
DevSecOps & Supply Chain Security Consultant
On-site
Other
Posted 4 days ago
Job description
- Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security.
- The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence.
- The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.
- Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
- Review SDLC processes, tooling, and secure development practices
- Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
- Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
- Review secrets management across development, build, deployment, and operational environments
- Assess logging, auditability, and security event traceability controls
- Evaluate vulnerability management, remediation tracking, and patch governance processes
- Support lifecycle security assessment, compliance evidence mapping, and traceability
- Contribute to assessment reporting, remediation guidance, and release governance reviews
- Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions.
- Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
- Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
- Strong understanding of DevSecOps and secure software delivery practices
- Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
- Familiarity with CI/CD security controls and artifact integrity validation
- Experience with vulnerability management and dependency governance programs
- Understanding of lifecycle security, auditability, and compliance evidence requirements
- Experience with secrets management and secure release governance
- SBOM Analysis (CycloneDX, SPDX, VEX/CSAF)
- Artifact Integrity
- SAST, DAST, Dependency & Secrets Scanning
- Vulnerability Management & Remediation Governance
- Secrets Management
- Compliance Evidence & Audit Traceability
- CRA / Regulatory Security Assessments
- Syft and related SBOM tools
- Secure Release Governance & Security Controls Validation
- Build provenance and software-delivery traceability
- Artifact signing, verification and tamper testing
- Container, registry, build-agent and CI/CD runner security
- Infrastructure-as-Code and pipeline-as-code security
- Signing-key, certificate and HSM lifecycle controls
- SBOM generation and binary-to-SBOM reconciliation
- Open-source and third-party dependency governance
- EOL/EOS and patch-lifecycle governance
- Security exception and release-risk governance
- Pipeline policy-as-code and automated security gates
- Vulnerability metrics and release-readiness reporting
- NIST SSDF and secure software supply-chain practices
- Supplier security and software-acquisition assessments
- Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
- US Citizen or Green Card holder (US Person)
- Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
- Experience participating in engagement related to export-controlled environments
- Familiarity with SLSA or modern software supply chain security practices
- Strong documentation skills
- CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
- 10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
- 2+ years of hands-on SBOM analysis experience.