2 of 2 SLSA Jobs in the North of England

DevX Build Pipeline/ DevOps Engineer CGEMJP00349975

Hiring Organisation
Experis
Location
Sheffield, South Yorkshire, Yorkshire, United Kingdom
Employment Type
Contract
Jenkins Shared Library powering multi-language builds (Java/Maven, Node/NPM, Python, Helm, Terraform, containers). Deliver fast, secure, provenance-rich pipelines (SLSA, SBOM, digests) and strengthen supplychain integrity across teams. Core Responsibilities : Design and maintain Groovy pipeline steps (build, test, package, scan, deploy). Extend Python tooling … for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container). Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch). Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible inputs, evidence modeling). Refactor legacy scripts (remove global state ...

Product Security Engineer

Location
Manchester, England, United Kingdom
dependencies, build pipelines, and CI providers. You'll engineer the systems that make our supply chain defensible: provenance and integrity for what we build (SLSA, sigstore patterns, signed artifacts), dependency trust as a real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When … people around you Desirable Detection engineering at production scale: runtime detection, anomaly detection, alert tuning (Sigma, OSQuery, Falco, or equivalent) Supply-chain security: SLSA, sigstore/cosign, in-toto, SBOM tooling used as a real control Cloud-native attack patterns on AWS: IAM privilege analysis, IMDS exploitation, cross-account paths ...