DevSecOps Engineer
Job SummaryWe are hiring a DevSecOps Engineer to join the Applications team responsible for embedding security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of on-premise and cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.
Job Duties- Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
- Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
- Track production and cloud environments in real-time to detect, log, and respond to misconfigurations or intrusions.
- Drive cloud-native security architecture across AWS and Azure environments, implement security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
- Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
- Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
- Collaborate with developers on secure coding and advise IT on safe cloud configurations.
- Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level
Qualifications- 5+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
- Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift)
- Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
- Proven ability to build and maintain internal tooling with experience in scripting languages such as Python or Bash, alongside a strong grasp of Linux and Git
- Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
- Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
- Experience with modern development practices including Jenkins CI/CD pipeline design, version control systems like Git, and agile development methodologies
- Demonstrates working knowledge of Agile and Scrum practices
Preferred Qualifications- Advanced DevSecOps platform experience include building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, SonarQube, Nexus, or equivalent security testing solutions
- Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments
- Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials
- Knowledge in languages like Python, Java, JavaScript, Bash, PowerShell, and Perl
Travel Requirements- Occasional travel to off-site business meetings or conferences. (5% proficiency)
The starting pay range for this position is:
$109,500.00 - $146,200.00
Additionally, for full time positions, you will be eligible to participate in our incentive program based upon the achievement of organization, team and personal performance.
Remarkable benefits:• Health coverage for medical, dental, vision
• 401(K) saving plans with company match AND Pension
• Tuition assistance
• Floating holidays and PTO for community volunteer programs
• Paid parental leave
• Wellness programs
• Employee discounts (membership, insurance,
travel, entertainment, services and more!)