Job Type
Full-time
Description
This is a fully remote position, allowing you to work from home or location of record within the U.S. with no in-office requirements. You must be available five days per week during designated work hours. The work arrangement for this role is subject to change based on business needs and individual performance. This may include adjustments to on-site requirements or schedule expectations, as necessary.
Position Overview The DevSecOps Engineer is responsible for understanding and providing guidance to internal teams on best practices in software security and architecture for Paylocity's Information Systems. Responsibilities will also include development and maintenance of internal application security tools and performing static and dynamic analysis of our web and mobile applications.
Primary ResponsibilitiesThe below represents the primary duties of the position, others may be assigned as needed. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Develop and maintain internal application security tooling.
- Integrate security into the build/deployment process.
- Promote a proactive approach to addressing the changing threat landscape by recommending and implementing architectural improvements to security infrastructure.
- Provide expert guidance and recommendations for strategic and tactical security architecture topics through risk advisory services.
- Assist developers in remediating vulnerabilities by providing line-by-line guidance.
- Provide training and education to developers on software security best practices in various cloud-based systems.
Education and Experience - Bachelor's degree in InfoSec, Computer Science, Engineering, or a related field, or equivalent practical experience.
- Minimum 3 years' experience with full-stack web development.
- Experience developing and working with Web APIs.
- Experience with scaling secure-by-design security solutions for developers.
- Experience interpreting results from Static Code Scanning tools and third party dependency scanning tools
- Strong knowledge of Security Token Services, Federated Identity Providers, SAML 2.0, claims-based security and other SSO technologies.
- Experience in remediating security vulnerabilities beyond OWASP Top 10.
- Experience in assessing security of native and hybrid mobile applications beyond the use of automated tools.
- Strong experience developing in Python.
- Experience developing in .NET is a plus.
- Functional knowledge of container-based application infrastructure with Docker is a plus.
- Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus.
- Experience with Privileged Access Management and/or Secrets Management is a plus.
Physical requirements - Ability to sit for extended periods: The role requires sitting at a desk or workstation for long periods, typically 7-8 hours a day.
- Use of computer and phone systems: The employee must be able to operate a computer, use phone systems, and type. This includes using multiple software programs and inquiries simultaneously.
The base pay range for this position is $96k - $130k/yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via www.paylocity.com/careers.