Ubique Systems

TRPD-26-04704

DevSecOps / Software Supply Chain Security Lead

Senior DevSecOps / Application Security professional to lead enterprise-wide software supply chain security and DevSecOps initiatives. The role focuses on embedding secure CI/CD practices, open source security and SCA, SBOM generation/governance (SPDX/CycloneDX), and security scanning across the SDLC (SAST, SCA, IaC, container, secrets, API). You will drive secure build and artifact integrity (signing/provenance), support vulnerability remediation, align programs to standards like NIST SSDF, SLSA, DORA, PCI DSS and ISO 27001, and mentor engineering teams through security automation and developer enablement.

Position summary

Location
India
Workplace
Hybrid
Employment
Full Time
Experience
Minimum 8 years and Maximum 12 years
Apply now

Role overview

Why This Role Matters.

Senior DevSecOps / Application Security professional to lead enterprise-wide software supply chain security and DevSecOps initiatives. The role focuses on embedding secure CI/CD practices, open source security and SCA, SBOM generation/governance (SPDX/CycloneDX), and security scanning across the SDLC (SAST, SCA, IaC, container, secrets, API). You will drive secure build and artifact integrity (signing/provenance), support vulnerability remediation, align programs to standards like NIST SSDF, SLSA, DORA, PCI DSS and ISO 27001, and mentor engineering teams through security automation and developer enablement.

Your Impact

Deliver Enterprise Value

Help organisations solve complex business problems through modern technology, consulting expertise and measurable outcomes.

Collaboration

Work Across Teams

Collaborate with consultants, architects, engineers and client stakeholders throughout the project lifecycle.

Growth

Learn Continuously

Gain exposure to enterprise technologies, certifications, mentoring and real-world project experience.

Career Path

Grow With Ubique

Build a long-term consulting career with opportunities to take on greater responsibility and leadership over time.

Responsibilities

What You'll Be Doing.

Every role at Ubique contributes directly to solving meaningful business challenges for our clients.

01

Lead DevSecOps and Software Supply Chain Security initiatives across the SDLC.

02

Implement and optimize SCA, Open Source Security, SBOM governance, and secure CI/CD pipelines.

03

Generate and manage SBOMs (SPDX/CycloneDX) and support vulnerability remediation.

04

Implement SAST, SCA, IaC, Container, Secrets, and API security scanning.

05

Establish secure build, artifact signing, provenance, and dependency governance.

06

Support compliance with NIST SSDF, SLSA, DORA, PCI DSS, and ISO 27001.

07

Mentor engineering teams and drive security automation and developer enablement.

08

8+ years in DevSecOps, Application Security, or Software Security.

09

Hands-on experience with Snyk, Sonatype, Mend, Black Duck, or equivalent.

10

Strong expertise in Software Supply Chain Security, Open Source Security, SBOM, CI/CD Security, Containers, Kubernetes, AWS/Azure/GCP.

11

Knowledge of SLSA, Sigstore, SPDX, CycloneDX, CVE/CVSS, Python/Bash scripting.

12

Exposure to AI Software Supply Chain Security, AIBOM concepts, and AI/LLM security is preferred.

Technology stack

Tools & Technologies.

The platforms and technologies you'll use to build modern, enterprise-grade solutions.

01

DevSecOps

02

Software Supply Chain Security

03

Open Source Security

04

SCA

05

SBOM

06

SPDX

07

CycloneDX

08

CI/CD security

09

SAST

10

IaC scanning

11

Container security

12

Secrets scanning

13

API security

14

Kubernetes

15

AWS

16

Azure

17

GCP

18

SLSA

19

Sigstore

20

CVE

Requirements

Skills & Experience.

We value curiosity, collaboration and continuous learning. If you don't meet every requirement but believe you can make an impact, we'd still love to hear from you.

Essential

Required Qualifications

DevSecOps / Application Security / Software Security (8+ years)

Software Supply Chain Security

Open Source Security and Software Composition Analysis (SCA)

SBOM generation and governance (SPDX, CycloneDX)

Secure CI/CD pipeline security

Security scanning: SAST, SCA, IaC scanning, container scanning, secrets scanning, API security scanning

Containers and Kubernetes security

Cloud security exposure across AWS and/or Azure and/or GCP

CVE/CVSS understanding and vulnerability remediation support

Dependency management ecosystems (e.g., Maven, npm, pip)

Scripting (Python and/or Bash)

Secure build practices including artifact signing, provenance, and dependency governance

Strong communication to explain security concepts to non-technical stakeholders

Preferred

Nice to Have

Hands-on with specific SCA tools: Snyk, Sonatype, Mend, Black Duck (or equivalent)

Knowledge of SLSA

Knowledge of Sigstore

Compliance exposure: NIST SSDF, DORA, PCI DSS, ISO 27001

AI software supply chain security / AIBOM concepts

AI/LLM security exposure

Cybersecurity certifications (CISSP, CRISC, CISM, OSCP)

What you'll gain

More Than Just A Job.

We're committed to helping every team member grow professionally, personally and technically while working on meaningful projects.

Global Exposure

Collaborate with international clients and multicultural teams on enterprise programmes.

Continuous Learning

Expand your expertise through mentoring, certifications and hands-on project experience.

Career Growth

Take ownership, develop leadership skills and grow your consulting career over time.

Flexible Working

Hybrid and remote collaboration designed around trust and delivering exceptional outcomes.

People First

Join a supportive culture where collaboration, respect and long-term relationships come first.

Enterprise Projects

Work on meaningful technology initiatives for leading organisations across industries.

Apply

Apply for DevSecOps / Software Supply Chain Security Lead

One page, about two minutes. We only ask for what we actually need to have a first conversation.

Your CV

Optional. A line or two is plenty.