TRPD-26-04704
DevSecOps / Software Supply Chain Security Lead
Senior DevSecOps / Application Security professional to lead enterprise-wide software supply chain security and DevSecOps initiatives. The role focuses on embedding secure CI/CD practices, open source security and SCA, SBOM generation/governance (SPDX/CycloneDX), and security scanning across the SDLC (SAST, SCA, IaC, container, secrets, API). You will drive secure build and artifact integrity (signing/provenance), support vulnerability remediation, align programs to standards like NIST SSDF, SLSA, DORA, PCI DSS and ISO 27001, and mentor engineering teams through security automation and developer enablement.
Position summary
- Location
- India
- Workplace
- Hybrid
- Employment
- Full Time
- Experience
- Minimum 8 years and Maximum 12 years
Role overview
Why This Role Matters.
Senior DevSecOps / Application Security professional to lead enterprise-wide software supply chain security and DevSecOps initiatives. The role focuses on embedding secure CI/CD practices, open source security and SCA, SBOM generation/governance (SPDX/CycloneDX), and security scanning across the SDLC (SAST, SCA, IaC, container, secrets, API). You will drive secure build and artifact integrity (signing/provenance), support vulnerability remediation, align programs to standards like NIST SSDF, SLSA, DORA, PCI DSS and ISO 27001, and mentor engineering teams through security automation and developer enablement.
Your Impact
Deliver Enterprise Value
Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.
Collaboration
Work Across Teams
Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.
Growth
Learn Continuously
Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.
Career Path
Grow With Ubique
Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.
Responsibilities
What You'll Be Doing.
Every role at Ubique contributes directly to solving meaningful business challenges for our clients.
Implement and optimize SCA, Open Source Security, SBOM governance, and secure CI/CD pipelines.
Generate and manage SBOMs (SPDX/CycloneDX) and support vulnerability remediation.
Implement SAST, SCA, IaC, Container, Secrets, and API security scanning.
Establish secure build, artifact signing, provenance, and dependency governance.
Support compliance with NIST SSDF, SLSA, DORA, PCI DSS, and ISO 27001.
Mentor engineering teams and drive security automation and developer enablement.
8+ years in DevSecOps, Application Security, or Software Security.
Hands-on experience with Snyk, Sonatype, Mend, Black Duck, or equivalent.
Strong expertise in Software Supply Chain Security, Open Source Security, SBOM, CI/CD Security, Containers, Kubernetes, AWS/Azure/GCP.
Knowledge of SLSA, Sigstore, SPDX, CycloneDX, CVE/CVSS, Python/Bash scripting.
Exposure to AI Software Supply Chain Security, AIBOM concepts, and AI/LLM security is preferred.
Technology stack
Tools & Technologies.
The platforms and technologies you'll use to build modern, enterprise-grade solutions.
DevSecOps
Software Supply Chain Security
Open Source Security
SCA
SBOM
SPDX
CycloneDX
CI/CD security
SAST
IaC scanning
Container security
Secrets scanning
API security
Kubernetes
AWS
Azure
GCP
SLSA
Sigstore
CVE
Requirements
Skills & Experience.
We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.
Essential
Required Qualifications
DevSecOps / Application Security / Software Security (8+ years)
Software Supply Chain Security
Open Source Security and Software Composition Analysis (SCA)
SBOM generation and governance (SPDX, CycloneDX)
Secure CI/CD pipeline security
Security scanning: SAST, SCA, IaC scanning, container scanning, secrets scanning, API security scanning
Containers and Kubernetes security
Cloud security exposure across AWS and/or Azure and/or GCP
CVE/CVSS understanding and vulnerability remediation support
Dependency management ecosystems (e.g., Maven, npm, pip)
Scripting (Python and/or Bash)
Secure build practices including artifact signing, provenance, and dependency governance
Strong communication to explain security concepts to non-technical stakeholders
Preferred
Nice to Have
Hands-on with specific SCA tools: Snyk, Sonatype, Mend, Black Duck (or equivalent)
Knowledge of SLSA
Knowledge of Sigstore
Compliance exposure: NIST SSDF, DORA, PCI DSS, ISO 27001
AI software supply chain security / AIBOM concepts
AI/LLM security exposure
Cybersecurity certifications (CISSP, CRISC, CISM, OSCP)
What you'll gain
More Than Just A Job.
We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.
Global Exposure
Collaborate with international clients and multicultural teams on enterprise programmes.
Continuous Learning
Expand your expertise through mentoring, certifications and hands-on project experience.
Career Growth
Take ownership, develop leadership skills and grow your consulting career over time.
Flexible Working
Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.
People First
Join a supportive culture where collaboration, respect and long-term relationships come first.
Enterprise Projects
Work on meaningful technology initiatives for leading organisations across industries.
Apply
Apply for DevSecOps / Software Supply Chain Security Lead
One page, about two minutes. We only ask for what we actually need to have a first conversation.