DevSecOps Engineer

American Automobile Association

$109K — $146K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in software engineering, DevOps, or DevSecOps within enterprise or regulated environments, focusing on securing CI/CD pipelines and application stacks
  • Expertise with AWS, Azure or Google Cloud and containerization technologies like Docker and Kubernetes
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience
  • Proven ability to develop internal tools with scripting capabilities in Python or Bash, alongside Linux and Git proficiency
  • Strong technical communication skills to convey security risks and solutions to both technical and non-technical stakeholders
  • Demonstrated ability to collaborate and influence within embedded engineering teams to drive security adoption
  • Experience with Jenkins CI/CD, version control (Git), and agile methodologies

Responsibilities

  • Embed automated security controls into CI/CD pipelines for secure development
  • Build and maintain internal DevSecOps tooling to support enterprise engineering teams
  • Monitor production and cloud environments for misconfigurations and threats
  • Implement cloud-native security architecture across AWS and Azure, focusing on containers and infrastructure-as-code
  • Evaluate and integrate security tools tailored to the organization's security needs
  • Support continuous compliance by automating regulatory requirements and audit readiness
  • Collaborate with developers on secure coding practices and advise on safe cloud configurations
  • Lead vulnerability management through threat modeling and design-level security assessments

Benefits

  • Health coverage including medical, dental, and vision
  • 401(K) savings plan with company match and Pension
  • Tuition assistance for ongoing education
  • Floating holidays and PTO for community volunteering
  • Paid parental leave policy
  • Wellness programs available to employees
  • Employee discounts on memberships, insurance, travel, entertainment, and more
Full Job Description
DevSecOps Engineer

Job Summary
We are hiring a DevSecOps Engineer to join the Applications team responsible for embedding security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of on-premise and cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Job Duties
  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
  • Track production and cloud environments in real-time to detect, log, and respond to misconfigurations or intrusions.
  • Drive cloud-native security architecture across AWS and Azure environments, implement security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
  • Collaborate with developers on secure coding and advise IT on safe cloud configurations.
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level


Qualifications
  • 5+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift)
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python or Bash, alongside a strong grasp of Linux and Git
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
  • Experience with modern development practices including Jenkins CI/CD pipeline design, version control systems like Git, and agile development methodologies
  • Demonstrates working knowledge of Agile and Scrum practices


Preferred Qualifications
  • Advanced DevSecOps platform experience include building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, SonarQube, Nexus, or equivalent security testing solutions
  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials
  • Knowledge in languages like Python, Java, JavaScript, Bash, PowerShell, and Perl


Travel Requirements
  • Occasional travel to off-site business meetings or conferences. (5% proficiency)


The starting pay range for this position is:

$109,500.00 - $146,200.00
Additionally, for full time positions, you will be eligible to participate in our incentive program based upon the achievement of organization, team and personal performance.

Remarkable benefits:
• Health coverage for medical, dental, vision
• 401(K) saving plans with company match AND Pension
• Tuition assistance
• Floating holidays and PTO for community volunteer programs
• Paid parental leave
• Wellness programs
• Employee discounts (membership, insurance,

travel, entertainment, services and more!)

Similar Jobs

More Jobs at American Automobile Association

  • DevSecOps Engineer
    $109K — $146K *
    Costa Mesa, CA 92627 (Orange County)
    Information Technology
    In-Person
  • Senior Operations Analyst
    $80K — $107K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Product Manager
    $120K — $160K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Senior Salesforce Developer
    $120K — $145K *
    Coppell, TX 75019 (Dallas County)
    Information Technology
    In-Person
  • DevSecOps Engineer
    $109K — $146K *
    St. Louis, MO 63129 (Saint Louis County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: