DevSecOps Engineer

American Automobile Association

$109K — $146K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in software engineering, DevOps, or DevSecOps in enterprise settings.
  • Experience with cloud platforms (AWS, Azure, Google Cloud) and containerization (Docker, Kubernetes).
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent experience.
  • Proficient in building internal tooling with scripting skills (Python, Bash) and strong Linux/Git knowledge.
  • Strong technical communication skills for articulating security risks to teams and stakeholders.
  • Proven track record of collaboration within engineering teams to promote security best practices.
  • Experience with CI/CD in modern development environments using Jenkins and agile methodologies.

Responsibilities

  • Embed security controls into CI/CD pipelines and integrate security testing.
  • Build and maintain scalable DevSecOps tooling for enterprise teams.
  • Monitor production and cloud environments for security incidents.
  • Drive security architecture in AWS and Azure, focusing on Kubernetes and infrastructure-as-code.
  • Evaluate and implement security tools to streamline application and cloud security.
  • Enable continuous compliance through automated engineering controls.
  • Collaborate with developers on secure coding and advise on cloud configurations.
  • Lead vulnerability management and participate in security architecture reviews.

Benefits

  • Health coverage for medical, dental, and vision.
  • 401(K) plans with company match and a pension.
  • Tuition assistance for further education.
  • Floating holidays and PTO for community service.
  • Paid parental leave benefits.
  • Wellness programs to support employee health.
  • Various employee discounts on memberships, insurance, travel, and services.
Full Job Description
DevSecOps Engineer


Job Summary
We are hiring a DevSecOps Engineer to join the Applications team responsible for embedding security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of on-premise and cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Job Duties

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
  • Track production and cloud environments in real-time to detect, log, and respond to misconfigurations or intrusions. 
  • Drive cloud-native security architecture across AWS and Azure environments, implement security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
  • Collaborate with developers on secure coding and advise IT on safe cloud configurations. 
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level


Qualifications

  • 5+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift)
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python or Bash, alongside a strong grasp of Linux and Git
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
  • Experience with modern development practices including Jenkins CI/CD pipeline design, version control systems like Git, and agile development methodologies
  • Demonstrates working knowledge of Agile and Scrum practices

Preferred Qualifications

  • Advanced DevSecOps platform experience include building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, SonarQube, Nexus, or equivalent security testing solutions
  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials
  • Knowledge in languages like Python, Java, JavaScript, Bash, PowerShell, and Perl

Travel Requirements

  • Occasional travel to off-site business meetings or conferences. (5% proficiency)

The starting pay range for this position is:

$109,500.00 - $146,200.00

Additionally, for full time positions, you will be eligible to participate in our incentive program based upon the achievement of organization, team and personal performance.

.

Remarkable benefits:
•    Health coverage for medical, dental, vision

•    401(K) saving plans with company match AND Pension    

•    Tuition assistance

•    Floating holidays and PTO for community volunteer programs

•    Paid parental leave

•    Wellness programs

•    Employee discounts (membership, insurance,

travel, entertainment, services and more!)

Similar Jobs

More Jobs at American Automobile Association

  • DevSecOps Engineer
    $109K — $146K *
    Costa Mesa, CA 92627 (Orange County)
    Information Technology
    In-Person
  • Senior Operations Analyst
    $80K — $107K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Product Manager
    $120K — $160K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Senior Salesforce Developer
    $120K — $145K *
    Coppell, TX 75019 (Dallas County)
    Information Technology
    In-Person
  • DevSecOps Engineer
    $109K — $146K *
    St. Louis, MO 63129 (Saint Louis County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: