BackDevSecOps Engineer *
@ CGI
Position Description:
CGI is seeking a DevSecOps Engineer to strengthen our software supply chain security program within a large scale, AWS based financial services environment. In this role, you will help secure the software delivery lifecycle — from open source governance to CI/CD artifact integrity — ensuring that software built and deployed across the organization meets rigorous compliance and security standards.
You'll work hands on with tools like Sonatype Nexus/IQ Server, implement artifact signing and provenance frameworks (SLSA, Sigstore/Cosign), and build automation that supports vulnerability remediation, SBOM generation, and open source policy enforcement. This is a great opportunity for someone who enjoys solving real security problems at scale, working across CI/CD pipelines, cloud infrastructure, and emerging technology ecosystems (including AI/ML tooling).
This position is required in one of the following locations: Lafayette, LA, Knoxville, TN, Birmingham, AL
Your future duties and responsibilities:
- . Support secure software delivery through enterprise supply chain initiatives
- . Manage and enhance artifact repository tooling and open source policy governance
- . Build and maintain software approval, quarantine, and lifecycle workflows
- . Drive dependency upgrades and vulnerability remediation efforts
- . Onboard new/emerging technology ecosystems (including AI/ML frameworks)
- . Create dashboards and metrics for supply chain health and compliance
- . Implement CI/CD artifact signing, build provenance (SLSA), and SBOM integration
Qualifications:
Required qualifications to be successful in this role:
- 5+ years working in DevSecOps, Platform Engineering, or Software Supply Chain roles
- Hands on experience with Sonatype Nexus and IQ Server (or similar — jFrog Artifactory is fine too)
- Comfortable building and maintaining automated open source policy workflows
- Experience with artifact signing tools like Sigstore/Cosign, GPG, or Notary
- Familiarity with SLSA provenance and in toto attestations (or similar supply chain security frameworks)
- Know your way around SBOM generation tools — CycloneDX, SPDX, or Syft
- Solid CI/CD background, ideally with GitLab (GitHub Actions also welcome)
- Strong AWS chops — IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, CloudWatch
- Scripting ability in Python, Bash, or Go
- Exposure to OCI registries and package ecosystems like Maven, npm, PyPI, or NuGet
Educational Requirement:
- Bachelor's degree in Computer Science, Information Systems, or a related field.
Skills:
- Amazon Web Services Cloud
- BASH
- DevOps Security
- GitHub
- GitLab
- Python
How to Apply:
Apply online at: https://www.cgi.com/en/careers
Visit Site to Apply
Location: Lafayette, LA
Date Posted: September 28, 2026
Application Deadline: October 28, 2026
Job Type: Full-time