Hospital for Special Surgery

DevSecOps Engineer

Hospital for Special Surgery$125K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in computer science, IT, cybersecurity or related field, or equivalent experience.
  • 7+ years of professional IT experience with 5+ years in DevSecOps or related technical roles.
  • Knowledge of secure software development lifecycle and vulnerability management.
  • Experience with CI/CD platforms like GitHub Actions, Jenkins, or similar.
  • Familiarity with cloud platforms such as AWS or Azure.
  • Experience with application security tools like SAST and SCA.
  • Strong communication and analytical skills.

Responsibilities

  • Partner with cross-functional teams to integrate security into applications and infrastructure.
  • Design and maintain security controls within CI/CD pipelines.
  • Manage application security tools for vulnerability scanning and testing.
  • Identify security risks in applications and recommend remediation strategies.
  • Support secure development practices and threat modeling.
  • Validate and track application, cloud, and infrastructure vulnerabilities.
  • Conduct audits and support compliance activities.

Benefits

  • Flexible work environment with remote work options.
  • Professional development opportunities and training.
  • Access to cutting-edge security tools and technologies.
  • Collaborative team culture focused on continuous improvement.
  • Contributions to building a positive cybersecurity culture.
Full Job Description
What you will be doing
Position Activities
  • Partner with application development, data and analytics, infrastructure, cloud, architecture, and cybersecurity teams to embed secure-by-design principles into applications, services, pipelines, platforms, and infrastructure.
  • Design, implement, and maintain security controls within CI/CD pipelines, including automated testing, security gates, build and deployment checks, and risk-based exception workflows.
  • Manage and support application security capabilities such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), secrets detection, dependency review, and code security scanning using tools such as Snyk, Wiz, and GitHub.
  • Review application designs, architecture patterns, data flows, APIs, cloud workloads, and integration points to identify security risks and recommend practical remediation or compensating controls.
  • Support threat modeling, secure code review, and security design reviews throughout the software development lifecycle.
  • Validate, prioritize, and track remediation of application, cloud, container, infrastructure, and development environment vulnerabilities using platforms such as Snyk, Wiz, Sysdig, Tenable, GitHub, and related tools.
  • Review cloud resources, Infrastructure as Code templates, container images, and deployment configurations against organizational policies, secure configuration baselines, and industry best practices.
  • Develop scripts, integrations, dashboards, and automated workflows that improve security testing, vulnerability management, reporting, evidence collection, and developer self-service.
  • Create metrics, reports, diagrams, runbooks, standards, and technical documentation that communicate application security posture, pipeline security effectiveness, vulnerability trends, and remediation status to technical and non-technical audiences.
  • Support audits, assessments, compliance activities, and control validation requests related to application security, cloud security, software supply chain security, and secure development practices.
  • Perform other related duties as assigned.

Minimum Qualifications
  • Bachelor’s degree in computer science, information technology, cybersecurity, software engineering, data engineering, or a related field, or equivalent experience.
  • Seven or more years of professional IT experience with five or more years in DevSecOps, application security, cloud security, software engineering, infrastructure engineering, security engineering, or a related technical role.
  • Working knowledge of secure software development lifecycle practices, application security principles, cloud security concepts, CI/CD security, and vulnerability management.
  • Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or similar tools.
  • Experience with cloud platforms such as Microsoft Azure, AWS, or similar environments.
  • Familiarity with application security and software supply chain security capabilities such as SAST, SCA, secrets scanning, dependency analysis, container scanning, and Infrastructure as Code scanning.
  • Experience with scripting, automation, source control, code review processes, and development workflows using tools and languages such as Git, Python, PowerShell, Bash, JavaScript, or similar.
  • Ability to assess technical environments, identify security gaps, evaluate risk, and recommend practical remediation activities.
  • Strong written and verbal communication skills, including the ability to explain technical security concepts to developers, engineers, security teams, and non-technical stakeholders.
  • Excellent analytical, problem-solving, troubleshooting, organizational, and prioritization skills.

Preferred Experience
  • Experience with tools such as Snyk, Wiz, Sysdig, Tenable, GitHub Advanced Security, GitHub Dependabot, or similar security platforms.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, CloudFormation, Bicep, Open Policy Agent, YAML, JSON, or similar.
  • Experience securing containers, Kubernetes, container registries, cloud-native workloads, APIs, secrets, and microservices architectures.
  • Experience building security automation, integrations, dashboards, reporting, and developer self-service capabilities.
  • Experience working with data and analytics platforms, data pipelines, APIs, reporting platforms, or related engineering teams.
  • Experience supporting audit readiness, compliance activities, control testing, or automated evidence collection in a regulated environment.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, OWASP Top 10, MITRE ATT&CK, HIPAA, HITRUST, ISO 27001, SOC 2, or similar.
  • Security, cloud, or software security certifications such as Security+, CSSLP, GWEB, GCSA, AWS Security Specialty, Azure Security Engineer, CCSP, CISSP, or similar.
  • Experience in healthcare or another highly regulated environment.

Skills and Abilities
  • Ability to connect security requirements to practical software development, cloud deployment, and engineering outcomes.
  • Ability to automate, standardize, and improve repeatable application security, cloud security, and DevSecOps processes.
  • Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
  • Ability to collaborate effectively with application development, data and analytics, infrastructure, cloud, architecture, cybersecurity, compliance, and business stakeholders.
  • Ability to produce professional-level documentation, reports, diagrams, runbooks, standards, and technical guidance.
  • Ability to think critically, make independent decisions, and recommend practical solutions.
  • Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
  • Ability to communicate application security risks, control gaps, remediation needs, and technical recommendations clearly to both technical and non-technical audiences.
  • Ability to support a positive cybersecurity culture by promoting secure development practices, accountability, and continuous improvement.

About Hospital for Special Surgery

Hospital for Special Surgery (HSS) is a hospital in New York City that specializes in orthopedic surgery and the treatment of rheumatologic conditions. Founded in 1863 by James Knight, HSS is the oldest orthopedic hospital in the United States. The hospital has been ranked the top orthopedic hospital in the United States by U.S. News & World Report for 11 consecutive years. HSS has a staff of over 4000 employees, including more than 200 physicians and surgeons, and treats over 32,000 inpatients and 300,000 outpatients annually.
Learn more about Hospital for Special Surgery
Size
4,000 employees
Industry
Founded
1863

Similar Jobs

More Jobs at Hospital for Special Surgery

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: