1

Devsecops Consultant Jobs (NOW HIRING)

DevSecOps & Supply Chain Security Consultant Role Summary * Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security. * The role covers ...

DevSecOps Engineer

Austin, TX · On-site

$58.25 - $77.75/hr

Overview Allied Consultants, Inc is a proudly Austin based firm with over 34 years of experience ... Responsibilities The DevSecOps Engineer will support the administration, implementation ...

Jr DevSecOps

Washington, DC · On-site

$75K - $90K/yr

The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...

The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...

Jr DevSecOps

Washington, DC · On-site

$75K - $90K/yr

The DevSecOps Engineer builds and operates secure delivery pipelines for the platform using AWS ... Dunbar Consulting, Inc. is fully committed to Equal Employment Opportunity and to attracting ...

Verstärken Sie unser Team als Cyber Security Consultant - DevSecOps & Container Security (m/w/d) an einem unserer Standorte deutschlandweit. Ob Architektur, Forensik oder Cloud - unser ...

DevSecOps Engineer

Bethesda, MD · On-site

$56.25 - $77/hr

Job Summary : Spark Tek Inc is seeking a DevSecOps Engineer to oversee the development ... and consulting for various industries. Founded in 2021, the company is headquartered in Farmers ...

DevSecOps SME

MD · On-site

$90K - $160K/yr

Join Barrow Wise Consulting, LLC today. Responsibilities: The DevSecOps SME will support Barrow Wise's DHS project and perform the following duties: * Evaluate software delivery practices and help ...

POSITION SUMMARY As a DevSecOps Engineer at Rancher Government Solutions, you will be a strategic ... consultative environment. #J-18808-Ljbffr

Title: Agentic AI and DevSecOps Engineer Location: Hybrid in Columbia, MD - 2x a week Clearance ... Since 2007, we've partnered with federal and state agencies to deliver IT, training, and consulting ...

DevSecOps Engineer

Herndon, VA

$54.25 - $74.25/hr

Description LT Consulting is seeking a DevSecOps Engineer with an active TS/SCI with polygraph to to design, build, and automate secure cloud-based infrastructure and workflows for mission-critical ...

Showing results 41-60

Devsecops Consultant information

See salary details

$10

$41

$87

How much do devsecops consultant jobs pay per hour?

As of Sep 10, 2026, the average hourly pay for devsecops consultant in the United States is $41.55, according to ZipRecruiter salary data. Most workers in this role earn between $29.33 and $49.52 per hour, depending on experience, location, and employer.

What is a DevSecOps consultant?

A DevSecOps Consultant is a professional who integrates security practices into the DevOps process, ensuring that security is considered at every stage of software development and deployment. They work closely with development, operations, and security teams to automate security checks, identify vulnerabilities early, and implement best practices for secure coding and infrastructure. Their goal is to create a culture where security is everyone's responsibility, reducing risks and enabling faster, safer software releases.

What are the key skills and qualifications needed to thrive as a DevSecOps consultant, and why are they important?

To thrive as a DevSecOps Consultant, you need expertise in cloud security, secure software development, and automation, often supported by a degree in computer science or related fields and certifications like AWS Certified Security or Certified DevSecOps Professional. Familiarity with CI/CD tools (e.g., Jenkins, GitLab), security scanning tools (e.g., Snyk, SonarQube), and container orchestration platforms (e.g., Kubernetes) is typically required. Strong problem-solving skills, effective communication, and a collaborative mindset help consultants guide teams in integrating security throughout the development lifecycle. These skills and qualities are vital to ensure secure, efficient software delivery and to help organizations proactively mitigate risks.

What are some common challenges DevSecOps consultants face when implementing security practices in CI/CD pipelines?

DevSecOps Consultants often encounter challenges such as integrating security tools without disrupting existing development workflows and ensuring that security measures do not slow down deployment speeds. Balancing the needs of development, operations, and security teams requires strong communication and collaboration skills. Additionally, consultants must stay current with emerging security threats and technologies, adapting processes to protect against vulnerabilities while fostering a culture of shared security responsibility within cross-functional teams.

What is the difference between Devsecops Consultant vs Security Engineer?

AspectDevsecops ConsultantSecurity Engineer
CertificationsCertified DevSecOps Professional, CISSP, CISACISSP, CEH, Security+
Work EnvironmentCollaborates across development, operations, and security teams in cloud and on-premises environmentsFocuses on implementing security measures within IT infrastructure and applications
Employer & Industry UsageConsulting firms, tech companies, organizations adopting DevSecOps practicesIT departments, cybersecurity firms, enterprise organizations

While both roles focus on security, a Devsecops Consultant integrates security into the development and operations pipeline, promoting automation and collaboration. A Security Engineer primarily implements and manages security measures within IT systems. The roles often overlap but differ in scope and focus areas.

What cities are hiring for Devsecops Consultant jobs?

Cities with the most Devsecops Consultant job openings:

What states have the most Devsecops Consultant jobs?

States with the most job openings for Devsecops Consultant jobs include:

What are popular job titles related to Devsecops Consultant jobs?

For Devsecops Consultant jobs, the most frequently searched job titles are:

DevSecOps & Supply Chain Security Consultant

On-site

Other

Posted 4 days ago


Job description

DevSecOps & Supply Chain Security Consultant Role Summary
  • Seeking a US Person with 10+ years of experience in secure software delivery, CI/CD and software supply-chain security.
  • The role covers secure SDLC, pipeline architecture and access, build provenance, artifact signing and promotion, SBOM/VEX/CSAF, dependencies, secrets, SAST/DAST, containers, IaC, vulnerability governance and regulatory evidence.
  • The consultant will validate source-to-release traceability, tamper resistance, SBOM accuracy, security gates, exceptions and remediation; produce audit-ready findings, release-readiness and residual-risk conclusions; and recommend finding-specific work. CRA, regulated-product and stakeholder-reporting experience is highly preferred.
Key Responsibilities
  • Assess software supply chain security, SDLC maturity, SBOM governance, CI/CD pipeline controls, secrets management, logging/auditability, and vulnerability management to support lifecycle security evaluation and compliance traceability.
  • Review SDLC processes, tooling, and secure development practices
  • Assess software supply chain security, including SCA, SBOM accuracy/completeness, dependency governance, and third-party risk
  • Evaluate CI/CD pipeline security, artifact integrity, and secure release controls
  • Review secrets management across development, build, deployment, and operational environments
  • Assess logging, auditability, and security event traceability controls
  • Evaluate vulnerability management, remediation tracking, and patch governance processes
  • Support lifecycle security assessment, compliance evidence mapping, and traceability
  • Contribute to assessment reporting, remediation guidance, and release governance reviews
  • Validate source-to-release traceability, build provenance, tamper resistance, artifact signing and promotion controls, SBOM accuracy, security gates, exceptions, remediation decisions, release-readiness conclusions and residual-risk positions.
  • Produce audit-ready findings, release-readiness reporting, residual-risk conclusions, stakeholder-ready executive communication and recommendations for finding-specific follow-up work.
  • Assess pipeline architecture and access, build-agent and CI/CD runner security, container and registry controls, infrastructure-as-code and pipeline-as-code security, policy-as-code implementation and automated security-gate effectiveness.
Required Skills & Experience Mandatory:
  • Strong understanding of DevSecOps and secure software delivery practices
  • Experience with SBOM frameworks (CycloneDX, SPDX) and SCA tooling
  • Familiarity with CI/CD security controls and artifact integrity validation
  • Experience with vulnerability management and dependency governance programs
  • Understanding of lifecycle security, auditability, and compliance evidence requirements
  • Experience with secrets management and secure release governance
  • SBOM Analysis (CycloneDX, SPDX, VEX/CSAF)
  • Artifact Integrity
  • SAST, DAST, Dependency & Secrets Scanning
  • Vulnerability Management & Remediation Governance
  • Secrets Management
  • Compliance Evidence & Audit Traceability
  • CRA / Regulatory Security Assessments
  • Syft and related SBOM tools
  • Secure Release Governance & Security Controls Validation
  • Build provenance and software-delivery traceability
  • Artifact signing, verification and tamper testing
  • Container, registry, build-agent and CI/CD runner security
  • Infrastructure-as-Code and pipeline-as-code security
  • Signing-key, certificate and HSM lifecycle controls
  • SBOM generation and binary-to-SBOM reconciliation
  • Open-source and third-party dependency governance
  • EOL/EOS and patch-lifecycle governance
  • Security exception and release-risk governance
  • Pipeline policy-as-code and automated security gates
  • Vulnerability metrics and release-readiness reporting
  • NIST SSDF and secure software supply-chain practices
  • Supplier security and software-acquisition assessments
  • Tools such as Syft, Grype, Trivy, Gitleaks, Dependency-Track, OpenSSL, Cosign, Sigstore, GitHub Actions, GitLab CI, Jenkins and Azure DevOps
  • US Citizen or Green Card holder (US Person)
Good to have:
  • Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
  • Experience participating in engagement related to export-controlled environments
  • Familiarity with SLSA or modern software supply chain security practices
  • Strong documentation skills
Preferred Certifications
  • CSSLP, Certified DevSecOps Professional or any other relevant product-security credentials
Years of Required Experience
  • 10+ years in secure CI/CD pipeline setup, governance and controls validation, including setting up, maintaining and validating Secure CI/CD pipelines across different types of technology stacks.
  • 2+ years of hands-on SBOM analysis experience.
#J-18808-Ljbffr