1 of 1 Sonatype Jobs in the UK

DevX Build Pipeline Engineer DevOps Engineer CGEMJP00342735

Hiring Organisation
Experis
Location
Sheffield, South Yorkshire, United Kingdom
Employment Type
Contract
steps (build, test, package, scan, deploy). Extend Python tooling for SLSA provenance, SBOM generation, hash/digest accuracy, and security scan aggregation (SonarQube, Sonatype IQ, SAST/Container). Optimize performance (parallel builds, caching, scope-reduced BOMs, dependency prefetch). Ensure artifact integrity (correct SHA1/SHA256 mapping, reproducible …/Python packaging knowledge; exposure to Helm/Terraform and container image metadata. Supply-chain security (SLSA, CycloneDX SBOM, digests). Experience with SonarQube, Sonatype IQ, container and SAST scanning. Proven performance tuning (caching, parallelization, dependency pruning). Compliance Awareness. Nice-to-Have Artifact signing/attestations (cosign, OCI). ...