DevSecOps Engineer

Ova Technologies

$120K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in DevSecOps or related field
  • Strong understanding of CI/CD pipeline development and security practices
  • Proficiency with DevOps tools like Jenkins, GitLab CI/CD, or Azure DevOps
  • Experience with cloud platforms, specifically AWS, Azure, or GCP
  • Familiarity with Infrastructure as Code tools such as Terraform or Ansible
  • Knowledge of security scanning methods including SAST, DAST, and SCA
  • Ability to collaborate effectively across development, QA, and security teams

Responsibilities

  • Design and maintain secure CI/CD pipelines
  • Integrate security practices into the software development lifecycle
  • Automate various security scanning processes
  • Implement and manage DevOps tools for continuous integration
  • Manage and secure cloud infrastructure
  • Utilize Infrastructure as Code for environment setup
  • Monitor for security threats and perform vulnerability assessments
  • Automate security compliance checks
  • Investigate security incidents and document findings

Benefits

  • Flexible working arrangements
  • Opportunities for professional development and training
  • Access to cutting-edge technology and tools
  • Collaborative team environment
  • Health and wellness benefits
Full Job Description
DevSecOps Engineer - Job Description

Job Title

DevSecOps Engineer

Job Summary

We are looking for an experienced DevSecOps Engineer to integrate security practices throughout the software development and deployment lifecycle. The role involves building secure CI/CD pipelines, automating infrastructure and security testing, managing cloud environments, and identifying and remediating vulnerabilities.

Key Responsibilities
  • Design, implement, and maintain CI/CD pipelines with security controls.
  • Integrate DevSecOps practices into development, testing, deployment, and operations.
  • Automate security scanning such as:
    • SAST - Static Application Security Testing
    • DAST - Dynamic Application Security Testing
    • SCA - Software Composition Analysis
    • Container security scanning
    • Infrastructure-as-Code security scanning
  • Implement and manage DevOps tools such as Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, or similar.
  • Manage cloud infrastructure across AWS, Azure, or GCP.
  • Implement Infrastructure as Code using Terraform, CloudFormation, or Ansible.
  • Secure containerized applications using Docker and Kubernetes.
  • Monitor applications and infrastructure for security threats and vulnerabilities.
  • Perform vulnerability assessment, remediation, and security compliance activities.
  • Implement secrets management using tools such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault.
  • Configure IAM, RBAC, authentication, authorization, and least-privilege access.
  • Integrate security gates into CI/CD pipelines to prevent vulnerable code from reaching production.
  • Collaborate with developers, QA, DevOps, cloud, and security teams.
  • Automate security and compliance checks wherever possible.
  • Investigate security incidents and support root-cause analysis.
  • Maintain security documentation, standards, and operational procedures.

Similar Jobs

More Jobs at Ova Technologies

  • DevSecOps Engineer
    $120K — $145K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Java Developer
    $95K — $115K *
    Atlanta, GA 30349 (Fulton County)
    Information Technology
    In-Person
  • Java Automation Developer
    $95K — $115K *
    Alpharetta, GA 30022 (Fulton County)
    Information Technology
    Hybrid
  • Workday Consultant
    $110K — $130K *
    New York, NY 10025 (New York County)
    Business Services
    Hybrid
  • Microsoft Dynamics Consultant
    $110K — $130K *
    New York, NY 10025 (New York County)
    Enterprise Technology
    Hybrid

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: