DevSecOps Engineer

Air InfoSec

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3 years of experience in DevSecOps methodologies and best practices.
  • 3 years of experience in CI/CD pipeline development and automation.
  • 3 years of experience in source code management and repository administration.
  • 3 years of experience with application security testing tools and practices.
  • 3 years of experience with scripting and automation.
  • 2 years of experience administering AWS and/or Azure cloud environments.

Responsibilities

  • Administer and maintain the Veracode platform for security governance and user management.
  • Support onboarding of application teams to Veracode's security scanning capabilities.
  • Assist development teams with vulnerability remediation and security best practices.
  • Administer and maintain SonarQube environments and integrate them with CI/CD pipelines.
  • Maintain GitLab Self-Managed environments and manage upgrades, monitoring, and troubleshooting.
  • Design and optimize CI/CD pipelines with automation frameworks and templates.
  • Manage Jira projects and their integrations with other enterprise tools.

Benefits

  • Work in a collaborative environment with diverse teams and stakeholders.
  • Gain experience with industry-standard tools like Veracode, SonarQube, and GitLab.
  • Opportunity to enhance security practices within software development lifecycles.
  • Local work location at the Texas Department of Transportation in Austin.
  • Regular business hours with occasional flexibility for after-hours work.
Full Job Description
Job Description
This is an onsite role; only local candidates will be considered.

The DevSecOps Engineer will support the Texas Department of Transportation (TxDOT). This role is responsible for the administration, implementation, maintenance, and adoption of enterprise software development, security, and delivery platforms. The engineer will serve as a technical subject matter expert, integrating security, automation, and operational best practices into the software development lifecycle (SDLC). This position will collaborate with development teams, infrastructure teams, cybersecurity personnel, and business stakeholders to improve software quality, security posture, and delivery efficiency. Core platform responsibilities include Veracode, SonarQube, GitLab, and Atlassian Jira administration, along with CI/CD pipeline development and automation.

Responsibilities

  • Administer and maintain the Veracode platform, including user provisioning, role management, policy configuration, and system governance.
  • Support onboarding of application teams to Veracode security scanning capabilities, including SAST, DAST, SCA, and container scanning services.
  • Assist development teams with vulnerability remediation activities and security best practices.
  • Administer and maintain SonarQube environments, projects, quality profiles, quality gates, and user access controls.
  • Onboard application teams and integrate SonarQube into CI/CD pipelines to support code quality initiatives.
  • Administer and maintain GitLab Self-Managed environments, including projects, groups, repositories, runners, permissions, and integrations.
  • Perform GitLab platform upgrades, maintenance, monitoring, troubleshooting, and capacity management.
  • Design, build, maintain, and optimize CI/CD pipelines, including reusable pipeline templates and automation frameworks.
  • Integrate security testing, code quality validation, compliance controls, and deployment automation into software delivery workflows.
  • Administer Jira projects, workflows, permissions, issue types, dashboards, reports, and automation rules, including integrations with GitLab and other enterprise tools.


Requirements

Minimum Qualifications

  • 3 years of experience with DevSecOps methodologies and best practices.
  • 3 years of experience with CI/CD pipeline development and automation.
  • 3 years of experience with source code management and repository administration.
  • 3 years of experience with application security testing tools and practices.
  • 3 years of experience with scripting and automation.
  • 2 years of experience administering and supporting AWS and/or Azure cloud environments, including cloud infrastructure, security, networking, automation, Infrastructure as Code (IaC), container platforms, and CI/CD integrations.

Preferred Qualifications

  • 2 years of experience administering code suggestion and AI-assisted development platforms.
  • 2 years of experience planning and executing migrations involving source code repositories, CI/CD platforms, or DevSecOps toolchains.
  • 2 years of experience supporting application modernization, cloud migration, and DevSecOps tool integrations within cloud-hosted environments.
  • Cloud certifications.

Additional Requirements

  • May be required to work outside the normal business hours on weekends, evenings and holidays
  • Local candidates only; must currently live within 50 miles of the Austin, Texas work location.

Work Location and Schedule

Location: 125 E. 11th Street, Austin, Texas 78701

Schedule: Monday through Friday, 8:00 AM to 5:00 PM, excluding State holidays

Work Arrangement: Onsite

Similar Jobs

More Jobs at Air InfoSec

  • DevSecOps Engineer
    $110K — $130K *
    Austin, TX 78745 (Travis County)
    Information Technology
    In-Person
  • Deputy Project Manager
    $100K — $120K *
    Austin, TX 78745 (Travis County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: