





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Tier-1 brand, mid-level generalist title, and Bangalore location increase applicant competition.
Security-focused SecDevOps skills transfer across software companies but are specialized, so sensitivity is medium.
Explicit 6+ years requirement and many mandatory technologies make shortlisting highly strict.
Design and develop next-gen Software Supply Chain Security (SSCS) tools, including secure-by-default frameworks, automation, IDE plugins, CI libraries, and a centralized product security application.
Lead development of secure CI/CD pipelines, artifact signing, build provenance, SBOM generation, and trusted release workflows aligned to standards like SLSA, Sigstore, SPDX, and CycloneDX.
Collaborate with security, platform, and compliance teams to implement policy-driven automation and provide expert technical security advice.
6+ years of software development experience with Golang (backend) and JavaScript (VueJS frontend).
Proven expertise in developing robust, scalable REST APIs; GraphQL experience is a plus.
Working proficiency with building secure CI/CD pipelines using GitHub Actions and AWS services (IAM, S3, Lambda, DynamoDB, EKS, EC2).
Familiarity with software supply chain security concepts and tooling (SBOMs, artifact signing, provenance, SLSA, Sigstore, in-toto, SPDX), and Bachelor's degree in Computer Science preferred.
Experienced in secure DevSecOps and supply chain security automation with knowledge of secure software development lifecycle (S-SDLC) and security standards compliance.
Comfortable working cross-functionally with security, compliance, platform, and engineering teams to build scalable security frameworks and policy automation.
Technical leader capable of owning complex secure infrastructure tooling, strong automation mindset, skilled in cloud native environments, Terraform, and security controls implementation.