Implement SLSA Level 3 Supply-Chain Security: Sigstore Cosign, Rekor, Kyverno & GitHub Attestations

Job Overview

Budget

$8,900.00

Level

Senior

Location

N/A

Job Posted

26 Sep, 2025

Category

DevOps

Total Proposals

0

Job Description

Board-Level Risk

A SolarWinds-style supply-chain attack could cripple your $500 M revenue platform. Investors now mandate SLSA L3 compliance ( source + build + provenance ). You need signed artifacts, immutable transparency logs, and policy-enforced admission—without slowing releases.

 Senior Mandate

  • 100 % of containers + Helm charts signed & verified ( Cosign ).
  • Immutable transparency log ( Rekor ) for every build.
  • Kyverno policies block unsigned/unsafe images in <200 ms.
  • GitHub native SLSA attestations ( L3 ) generated automatically.

 Deep-Dive Scope

  • Sigstore Stack Deployment
    • Private Rekor ( Helm ) on EKS with RDS Postgres & S3 bucket for immutable entries.
    • Fulcio root-CA ( Google OIDC ) → short-lived x509 certs for keyless signing
    • CTLog ( certificate transparency ) for extra audit trail.
  • Keyless Signing Pipeline
    • GitHub Actions job:
      • Build multi-arch image → generate SPDX SBOM ( Syft ).
      • Cosign sign with Fulcio + upload attestation to Rekor.
      • Publish signed image + SBOM to GHCR.
  • Policy Enforcement (Kyverno)
    • ClusterPolicy: verify-image-signature → REJECT if signature missing or ** Rekor UUID invalid**.
    • Policy: require-sbom → deny admission if SPDX layer absent.
    • Policy: max-cve-count-5 → block if Trivy scan >5 MEDIUM.
  • SLSA L3 Evidence
    • GitHub native .attestation file stored alongside release assets.
    • Provenance JSON includes: source repo, builder ID, entryPoint, parameters.
    • Signed with GitHub OIDC token → no long-lived keys.
  • Compliance Reporting
    • SLSA conformance report ( JSON ) uploaded to auditor SharePoint.
    • Pen-test scoped to supply-chain ( SSCS ) → zero findings.

Senior Artifacts

  • GitHub Actions reusable workflow ( signed + attested ) for all repos.
  • Kyverno policy library ( YAML ) + test scenarios ( kuttl ).
  • Rekor transparency log backup ( S3 Glacier ) 7-year retention.
  • Board-level slide deck: risk before → after, ROI, audit pass.

Why C-Suite Insists on Senior Talent

  • Sigstore core contributor + SLSA technical advisory group member.
  • Carried 2 IPO-bound companies to SLSA L3 without release velocity loss.
  • 60-day continuous compliance monitoring ( shared Slack ).

Skills

  • DevOps processes and methodologies

Tags

DevOps processes and methodologies

Author Spotlight

Chen David

Chen David

Client

No description available.

Related Jobs

1 year ago Senior
$70.00 Hourly

We are seeking a Security Information and Event Management (SIEM) Analyst to set up and manage SIEM solutions for compre...

Log aggregation and analysis
View More
1 year ago MidLevel
$70.00 Hourly

We are seeking a Container Security Specialist to secure our containerized applications, ensuring each component is isol...

Containerization technologies (e.g., Docker, Kubernetes)
View More
1 year ago Senior
$75.00 Hourly

We are looking for a DevSecOps Engineer to integrate security into every stage of our software development lifecycle (SD...

CI/CD security and best practices
View More
1 year ago Junior
$75.00 Hourly

We are hiring a Microservices Security Consultant to implement and manage security protocols for our microservices archi...

Microservices security
View More
Chen David

Chen David

N/A


Member Since
Aug 04, 2025
Total Created Jobs
3