DevSecOps Engineer

American Automobile Association

$109K — $146K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in software engineering, DevOps, or DevSecOps in enterprise or regulated environments
  • Hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms (AWS, Azure, Google Cloud) and containerization technologies (Docker, Kubernetes)
  • Experience scripting in Python or Bash, with solid knowledge of Linux and Git
  • Strong technical communication skills for articulating security risks and solutions
  • Experience working collaboratively within engineering teams
  • Familiarity with Jenkins CI/CD pipeline design and Agile methodologies

Responsibilities

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages
  • Build and maintain internal DevSecOps tooling and platform extensions
  • Track production and cloud environments in real-time to detect security issues
  • Drive cloud-native security architecture for AWS and Azure environments
  • Evaluate and integrate security tools for application, pipeline, and cloud security
  • Support continuous compliance and governance through automated controls
  • Collaborate with developers on secure coding and advise on safe cloud configurations
  • Lead vulnerability management and ensure security is embedded at the design level

Benefits

  • Health coverage for medical, dental, and vision
  • 401(K) saving plans with company match and pension
  • Tuition assistance for continued education
  • Floating holidays and PTO for community volunteer work
  • Paid parental leave
  • Wellness programs to promote health
  • Employee discounts on various services and products
Full Job Description
DevSecOps Engineer


Job Summary
We are hiring a DevSecOps Engineer to join the Applications team responsible for embedding security directly into engineering platforms, CI/CD pipelines, and developer workflows. This role addresses the growing complexity of on-premise and cloud-native applications, containerized workloads, and automated delivery pipelines by providing hands-on technical leadership focused on secure-by-default developer experiences and scalable internal security tooling.

Job Duties

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
  • Track production and cloud environments in real-time to detect, log, and respond to misconfigurations or intrusions. 
  • Drive cloud-native security architecture across AWS and Azure environments, implement security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
  • Collaborate with developers on secure coding and advise IT on safe cloud configurations. 
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level


Qualifications

  • 5+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift)
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python or Bash, alongside a strong grasp of Linux and Git
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
  • Experience with modern development practices including Jenkins CI/CD pipeline design, version control systems like Git, and agile development methodologies
  • Demonstrates working knowledge of Agile and Scrum practices

Preferred Qualifications

  • Advanced DevSecOps platform experience include building or extending internal developer platforms, security tooling, and experience with SAST/DAST/SCA platforms such as Snyk, SonarQube, Nexus, or equivalent security testing solutions
  • Financial services or regulated industry experience with knowledge of compliance frameworks, audit requirements, and experience implementing security controls in highly regulated environments
  • Professional security certifications such as CISSP, CISM, CCSP, or cloud security certifications including AWS Certified Security Specialty, Azure Security Engineer, or equivalent industry-recognized credentials
  • Knowledge in languages like Python, Java, JavaScript, Bash, PowerShell, and Perl

Travel Requirements

  • Occasional travel to off-site business meetings or conferences. (5% proficiency)

The starting pay range for this position is:

$109,500.00 - $146,200.00

Additionally, for full time positions, you will be eligible to participate in our incentive program based upon the achievement of organization, team and personal performance.

.

Remarkable benefits:
•    Health coverage for medical, dental, vision

•    401(K) saving plans with company match AND Pension    

•    Tuition assistance

•    Floating holidays and PTO for community volunteer programs

•    Paid parental leave

•    Wellness programs

•    Employee discounts (membership, insurance,

travel, entertainment, services and more!)

Similar Jobs

More Jobs at American Automobile Association

  • DevSecOps Engineer
    $109K — $146K *
    Costa Mesa, CA 92627 (Orange County)
    Information Technology
    In-Person
  • Senior Operations Analyst
    $80K — $107K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Product Manager
    $120K — $160K *
    Costa Mesa, CA 92627 (Orange County)
    Business Services
    In-Person
  • Senior Salesforce Developer
    $120K — $145K *
    Coppell, TX 75019 (Dallas County)
    Information Technology
    In-Person
  • DevSecOps Engineer
    $109K — $146K *
    St. Louis, MO 63129 (Saint Louis County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: