8+ years of experience in security engineering, DevSecOps, or application security in enterprise environments
Strong expertise in GitHub Enterprise, focusing on scanning and securing repositories
Proven track record in identifying and remediating text-based secrets in codebases
Experience with GitGuardian or similar secret detection tools
Familiarity with ServiceNow or similar platforms for triaging security issues
Ability to assess security posture and establish governance frameworks
Strong communication skills for guiding both technical and non-technical audiences
Responsibilities
Lead the DevSecOps strategy and implementation of secure source code practices
Drive assessment and mitigation of plaintext credentials and secrets in codebases
Define and enforce governance policies for secrets and public repositories
Evaluate and support GitGuardian integration for proactive secret scanning
Design and oversee remediation workflows via ServiceNow
Continuously assess and improve the security posture of internal repositories through compliance processes
Create and maintain dashboards and metrics for remediation progress and hygiene improvement
Develop training content and lead outreach campaigns for secure development practices
Contribute to identifying AI-enhanced security solutions
Benefits
Leadership role in a high-visibility DevSecOps initiative
Partnership with a world-class consultancy delivering critical security solutions
Opportunity to shape and implement secure development practices
Drive innovation through AI-assisted remediation strategies
Remote-first engagement with long-term potential and technical ownership
Full Job Description
About the Opportunity
We are a leading technology consultancy supporting a Fortune 50 enterprise IT organization in the delivery of complex, security-focused engineering initiatives. As part of a critical enterprise-wide program, we are seeking a Security Engineering Lead to drive strategy, execution, and coordination across DevSecOps enablement, code security, and secret hygiene.
This is a high-impact, long-term opportunity ideal for a seasoned cybersecurity professional with expertise in DevSecOps, GitHub Enterprise, and secret management architecture-with a passion for improving enterprise security posture through modern tools, automation, and emerging technologies. Experience at global consultancies, Big 4 firms, or other large-scale IT environments is highly valued.
This is a remote role with limited travel, which may be requested but is not required.
Role Summary
As the Security Engineering Lead - DevSecOps, you will play a strategic and hands-on leadership role in improving the enterprise's source code security posture. The initial focus of this engagement involves the identification and remediation of exposed, unprotected text-form secrets embedded in GitHub repositories. You will lead efforts to assess repository risk, build scalable remediation workflows, and align practices with long-term governance and compliance goals.
You will also guide tooling integrations, such as GitGuardian, and support continuous monitoring through platforms like Azure DevOps, ServiceNow, and others. Familiarity with AI or GenAI use cases that enhance security operations is preferred.
Key Responsibilities
Lead the DevSecOps strategy and implementation of secure source code practices, with an initial focus on remediating exposed secrets in GitHub repositories
Drive the assessment and mitigation of plaintext credentials, tokens, and secrets in codebases, aligning with security best practices
Define and enforce governance policies for secrets, PATs, SSH keys, and rogue/public repositories
Evaluate and support enterprise-wide GitGuardian integration for proactive secret scanning and alerting
Design and oversee remediation workflows via ServiceNow, including SLA definitions and resolution tracking
Continuously assess and improve the security posture of internal repositories through automated and repeatable compliance processes
Create and maintain dashboards and metrics to measure remediation progress and hygiene improvement
Develop training content and lead outreach campaigns to promote secure development practices
Contribute to identifying AI/GenAI-enhanced security solutions that improve detection, remediation, and reporting efficiency
Required Qualifications
8+ years of experience in security engineering, DevSecOps, or application security in enterprise-scale environments
Strong expertise in GitHub Enterprise, especially in scanning, securing, and managing sensitive content within repositories
Demonstrated success in identifying and remediating text-based secrets and credentials within code repositories
Experience with GitGuardian or similar secret detection tools
Familiarity with ServiceNow or equivalent platforms for triaging security issues and tracking remediation
Proven ability to assess security posture and implement governance frameworks for secure development
Strong communication skills and experience guiding both technical and non-technical audiences through security initiatives
Comfortable working across collaboration tools such as Microsoft Teams and Outlook
Preferred Qualifications
Experience working in or consulting for Big 4 firms, global consultancies, or large enterprise IT organizations
Exposure to AI/GenAI use cases in security automation, threat detection, or posture monitoring
Hands-on experience with secure SDLC and DevSecOps pipeline integrations
Understanding of GRC frameworks such as NIST, CIS Controls, or ISO 27001
Experience managing or collaborating with onshore/offshore security delivery teams
Why Join Us?
Take a leadership role in a high-visibility DevSecOps initiative within a global enterprise environment
Partner with a world-class consultancy delivering critical, modernized security solutions
Shape and implement secure development practices using tools like GitHub Enterprise, GitGuardian, and ServiceNow
Help drive innovation through AI-assisted remediation strategies
Enjoy a remote-first engagement with long-term potential and technical ownership
Apply Now
If you're a security engineering leader ready to take on complex code security challenges and drive DevSecOps excellence at scale, we invite you to apply.