DevSecOps Engineer *

Back

DevSecOps Engineer *

@ CGI

Position Description:

CGI is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle — from open source governance to CI/CD artifact integrity — ensuring that software built and deployed across the organization meets rigorous compliance and security standards.

You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).

This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL

Your future duties and responsibilities:

  • . Support secure software delivery through enterprise supply chain initiatives
  • . Manage and enhance artifact repository tooling and open source policy governance
  • . Build and maintain software approval, quarantine, and lifecycle workflows
  • . Drive dependency upgrades and vulnerability remediation efforts
  • . Onboard new/emerging technology ecosystems (including AI/ML frameworks)
  • . Create dashboards and metrics for supply chain health and compliance
  • . Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration


Qualifications:

Required qualifications to be successful in this role:

  • 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
  • Hands on experience with Sonatype Nexus and IQ Server (or similar — jFrog Artifactory is fine too)
  • Comfortable building and maintaining automated open source policy workflows
  • Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
  • Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
  • Know your way around SBOM generation tools — CycloneDX, SPDX, or Syft
  • Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
  • Strong AWS chops — IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
  • Scripting ability in Python, Bash, or Go
  • Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet

Educational Requirement:

  • Bachelor's degree in Computer Science, Information Systems, or a related field.

Skills:

  • Amazon Web Services Cloud
  • BASH
  • DevOps Security
  • GitHub
  • GitLab
  • Python


How to Apply:

Apply online at: https://www.cgi.com/en/careers 

Visit Site to Apply

Location: Lafayette, LA
Date Posted: September 28, 2026
Application Deadline: October 28, 2026
Job Type: Full-time