SBOM & DevSecOps Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

ACL Digital · 9 hours ago

SBOM & DevSecOps Engineer

ACL Digital is hiring a Software Supply Chain & SBOM Specialist to help secure embedded software and ensure compliance with emerging regulations like the EU Cyber Resilience Act (CRA). The role involves implementing SBOM standards, validating compliance, and leading initiatives in software supply chain security.

Business IntelligenceCloud ComputingDevOpsHardwareInformation TechnologyInternet of ThingsMobile AppsRetail TechnologySaaSSoftware
check
H1B Sponsor Likelynote

Responsibilities

Implement and maintain SBOM standards (SPDX, CycloneDX) and tooling (Syft, CycloneDX CLI)
Validate SBOMs against regulatory and CRA requirements
Apply secure development practices in embedded C/C++ environments
Lead software supply chain security initiatives: component analysis, provenance, and vulnerability scanning (SCA tools like Snyk, Black Duck)
Integrate SBOM and security workflows into CI/CD pipelines
Leverage DevSecOps and automation to streamline compliance and security processes
Collaborate effectively with cross-functional teams including engineering, security, and product

Qualification

SBOM standardsEmbedded C/C++ securitySoftware supply chain securityCI/CD integrationCommunication skillsCollaboration skills

Required

Implement and maintain SBOM standards (SPDX, CycloneDX) and tooling (Syft, CycloneDX CLI)
Validate SBOMs against regulatory and CRA requirements
Apply secure development practices in embedded C/C++ environments
Lead software supply chain security initiatives: component analysis, provenance, and vulnerability scanning (SCA tools like Snyk, Black Duck)
Integrate SBOM and security workflows into CI/CD pipelines
Leverage DevSecOps and automation to streamline compliance and security processes
Collaborate effectively with cross-functional teams including engineering, security, and product
Strong experience with SBOM standards, generation, and validation
Expertise in embedded C/C++ security practices and secure build/toolchain management
Hands-on knowledge of software supply chain security and CI/CD integration
Strong communication and collaboration skills

Company

ACL Digital

company-logo
ACL Digital is a design-led digital engineering and transformation firm.

H1B Sponsorship

ACL Digital has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (38)
2024 (29)
2023 (26)
2022 (33)
2021 (20)
2020 (19)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Srikanth Raghavan
Associate Vice President
linkedin
Company data provided by crunchbase