> Markdown version of [/jobs/ext/3022121-opensource-security-engineer](https://www.wearedevelopers.com/jobs/ext/3022121-opensource-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # OpenSource Security Engineer - **Company:** Infosys - **Location:** Tempe, AZ, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Bash Shell, Cloud Computing, Continuous Delivery, Continuous Integration, DevOps, Github, Identity and Access Management, Interoperability, Python (Programming Language), Apache Maven, Cisco Nexus Switches, NuGet, Open Source Technology, Software Tools, Requirements Management, Software Engineering, Systems Integration, Web Services, Scripting, Cloud Platform System, Sonatype, Software Security, State Machines, AWS Lambda, Gitlab, Free and Open-Source Software, Npm(Software), Functional Programming, Cloudwatch, Oracle Cloud Infrastructure, Devsecops - **Published:** September 21, 2026 - **Apply:** https://www.careerbuilder.com/job-details/opensource-security-engineer-tempe-az--55954876-ed2b-4059-92e7-254fa2ae3048 ## About the Role A collaborative spirit and excellent communication skills. Ability to analyze complex requirements and propose effective solutions basis engineering tools and methodologies Innovative mindset to address challenges and improve processes in line with industry trends Commitment to continuous improvement and knowledge sharing, Technology Lead - Engineering - USTechnology|Cloud Platform|Amazon Webservices DevOps Technology|Application Security|DevSecOps Technology|data science|PYTHON Foundational|Development process generic|Platform Engineering process * Experience in DevSecOps, Platform Engineering, or Software Supply Chain Security. * Hands-on experience with Sonatype Lifecycle (IQ Server), Nexus Repository, or comparable solutions such as JFrog. * Experience developing and managing Open-Source Software (OSS) governance policies, evaluation workflows, and automation. * Knowledge of artifact signing and integrity verification technologies, including Sigstore/Cosign, GPG, and Notary. * Experience implementing SLSA provenance, in-toto attestations, and software supply chain security controls. * Hands-on experience generating and managing SBOMs using tools such as CycloneDX, SPDX, or Syft. * Strong experience with AWS services, including IAM, ECS/EKS, EC2, S3, Lambda, Step Functions, and CloudWatch. * Experience integrating security and compliance controls into CI/CD pipelines. * Proficiency in scripting and automation using Python, Bash, or Go. * Experience designing, deploying, and supporting enterprise Open-Source platforms and repositories. * Familiarity with OCI registries and package ecosystems such as Maven, npm, PyPI, and NuGet. * Strong understanding of NIST SSDF, Executive Order 14028, Secure by Design principles, and modern software supply chain security practices. * Experience securing and onboarding AI/ML open-source ecosystems. * Enterprise Open-Source Platform Engineering experience. * Experience developing software supply chain governance metrics, reporting, and dashboards. * CI/CD experience with GitLab, GitHub Actions, or similar platforms. * Bachelor's degree or foreign equivalent required from an accredited institution. Will also consider three years of progressive experience in the specialty in lieu of every year of education. * This position may require relocation and/or travel to work/project location. * All applicants authorized to work in the United States are encouraged to apply., AWS Lambda, Amazon Elastic Compute Cloud (EC2), Amazon Simple Storage Service (S3), Amazon Web Services (AWS), Applications Security, Artificial Intelligence (AI), Automation, Bank Management, Bash Scripting, Business Growth, Cloud Computing, Communication Skills, Consulting, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Cross-Functional, Customer Experience, Data Science, DevOps, Ecosystems, Engineering, Establish Priorities, Financial Services, GitHub, Healthcare Reimbursement, Hospital, Industry/Trade Analysis, Insurance, Interoperability, Leading Edge Technology, Legal, Life Insurance, Maven, Medical Conditions, Metrics, Onboarding, Open Source, Operational Support Systems (OSS), Policy Evaluation, Problem Solving Skills, Process Improvement, Prototyping, Python Programming/Scripting Language, Reporting Dashboards, Requirements Management, Scripting (Scripting Languages), Software Development, Supply Chain, Systems Administration/Management, Team Player, Technical Leadership, Technical Writing, Technical/Engineering Design, Testing, U.S. National Institute of Standards and Technology (NIST), Vision Plan, Wealth Management, Web Services, Willing to Travel, Workflow Analysis ## Description 2251630No5439237910.00.009/13/2026OpenSource Security EngineerIn the assigned Job Role of Engineering Consultant 2, your Area Of Responsibility will be as below: Elicit and document business and technical requirements, translating them into actionable specifications for the team Participate in design meetings, create initial design concepts, and support the development of design sketches and models using established engineering tools and techniques Participate in iterative engineering design cycles, refine prototypes, and coordinate with teams to implement feedback effectively Develop and refine solution specifications and perform validation activities, including simulations, to ensure that engineering solutions meet design specifications and criteria Build and refine prototypes, incorporating testing results and feedback received from cross-functional team, to enhance functionality Undertake technical integration efforts, ensure system functionality, identify and resolve interoperability issues Develop and maintain comprehensive technical documentation and assist in organizing knowledge-sharing sessions among team members ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [How your .NET software supply chain is open to attack : and how to fix it](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)