Schneider Electric

Principal DevSecOps Engineer

Schneider Electric • $142K — $213K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, or related field.
  • 8+ years in cybersecurity engineering, application security, or related roles.
  • 3+ years supporting Azure-based cloud-native platforms.
  • Experience leading security implementation in software product organizations.
  • Proven track record in vulnerability management and remediation.

Responsibilities

  • Own the operational security posture of the EcoStruxure Building Data Platform.
  • Establish and maintain security baselines across various components.
  • Continuously assess security maturity and identify improvement opportunities.
  • Implement security controls and automation to reduce platform risk.
  • Lead vulnerability management activities and coordinate remediation efforts.

Benefits

  • Lead transformative projects that protect critical infrastructure.
  • Work with cutting-edge technologies and solve complex cybersecurity challenges.
  • Collaborative culture that values technical excellence and innovation.
  • Access to certifications, training, and resources for career growth.
Full Job Description
Role Overview

We are seeking a Principal DevSecOps Engineer to own the implementation, operation, and continuous improvement of the security posture of the EcoStruxure Building Data Platform.

This role serves as the hands-on security leader embedded within the engineering organization. The successful candidate will lead security tooling, security automation, vulnerability remediation coordination, software supply chain security, Secure SDLC implementation, release security readiness, and cloud security enablement across the platform.

The Principal DevSecOps Engineer is accountable for the implementation and operational execution of product security controls.

This role works closely with:
  • Security Advisor
  • Principal Systems Engineer
  • Engineering Technical Leads
  • Principal Cloud Operations & Infrastructure Engineer
  • Product Owners
  • Schneider Electric Product Security
  • 24x7 Operation Support Team

The Security Advisor remains responsible for independent governance, risk assessment, policy interpretation, CPCERT alignment, risk acceptance guidance, and security oversight.

In this role, you are responsible for implementation, execution, automation, evidence generation, and remediation coordination.

Key Responsibilities

Security Posture Management
  • Own the operational security posture of the EcoStruxure Building Data Platform.
  • Establish and maintain security baselines across applications, cloud services, containers, APIs, CI/CD systems, and supporting platform components.
  • Continuously assess security maturity and identify opportunities for improvement.
  • Implement security controls and automation that reduce platform risk.
  • Report operational security health, remediation status, and security trends.


Vulnerability Management & Remediation
  • Operate vulnerability management activities in accordance with Schneider Electric CPCERT processes and security requirements.
  • Perform technical triage of findings from SonarQube, Black Duck Binary Analysis (BDBA), penetration tests, container security scans, dependency analysis tools, and cloud security assessments.
  • Assess technical applicability of vulnerabilities and identify remediation approaches for affected platform components.
  • Partner with the Security Advisor on vulnerability prioritization, risk evaluation, exception reviews, and remediation timelines.
  • Lead remediation planning and coordinate execution with Technical Leads and engineering teams.
  • Track remediation progress, closure status, security debt metrics, and vulnerability trends.
  • Support vulnerability reporting and evidence requirements for security reviews, audits, and compliance activities.


Secure SDLC Implementation & Automation
  • Partner with the Security Advisor to implement Secure SDLC requirements across the EcoStruxure Building Data Platform.
  • Embed automated security controls and validation activities into GitHub Actions workflows and deployment pipelines.
  • Implement approved security gates and release readiness checks within software delivery processes.
  • Generate and maintain security evidence required for product release reviews and compliance activities.
  • Support developer enablement through practical guidance, tooling, templates, and automation that promote secure engineering practices.
  • Improve security visibility within the software development lifecycle through automation and metrics.


Software Supply Chain Security
  • Own Software Bill of Materials (SBOM) generation and management processes.
  • Establish software supply chain security controls across development and release processes.
  • Manage dependency analysis, artifact validation, and binary scanning programs.
  • Ensure container image integrity and security compliance.
  • Drive adoption of software provenance and artifact attestation practices.


Security Tooling Ownership

Own project level configuration, operational effectiveness, and continuous improvement of:
  • SonarQube
  • Black Duck Binary Analysis (BDBA)
  • SBOM Studio
  • GitHub Security
  • Secret scanning solutions
  • Container security platforms
  • Dependency analysis solutions
  • Security reporting and dashboarding tools

Partner with engineering teams to ensure security tooling is effective, adopted, and integrated into day-to-day development activities.

Security Operations & Compliance Enablement
  • Implement approved security requirements through engineering controls, automation, and security tooling.
  • Partner with the Security Advisor, Product Owners, and Technical Leads to plan and execute security remediation initiatives.
  • Support penetration testing, CPCERT reviews, compliance activities, and security assessments.
  • Coordinate operational activities supporting release security reviews.
  • Maintain security dashboards, remediation reporting, and evidence repositories.
  • Drive continuous improvement of security tooling, visibility, operational processes, and security engineering practices.


Cloud & Platform Security

Partner with the Principal Cloud Operations & Infrastructure Engineer to secure:
  • Azure Kubernetes Service (AKS)
  • Azure Container Registry (ACR)
  • Azure Entra ID
  • Azure Key Vault
  • Workload identities
  • Role-Based Access Control (RBAC)
  • Container platforms
  • Network security controls
  • Cloud platform configurations

Provide guidance and implementation support for secure cloud architecture patterns.

Cross-Functional Collaboration
  • Work closely with Technical Leads to integrate security practices into product development.
  • Partner with the Principal Systems Engineer on security-related architecture decisions and standards.
  • Collaborate with the Security Advisor on risk reviews, security findings, mitigation strategies, and compliance activities.
  • Support 24x7 operations teams with security operational procedures, monitoring guidance, and escalation processes.
  • Act as the primary security implementation lead within the EcoStruxure Building Data Platform organization.


Required Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Computer Engineering, or a related technical discipline.
  • Equivalent combination of education, professional training, and relevant industry experience may be considered.

Required Experience
  • 8+ years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, software engineering, or related security-focused roles.
  • 3+ years of experience supporting Azure-based cloud-native platforms.
  • Experience owning or leading security implementation activities within a software product organization.
  • Experience implementing Secure Software Development Lifecycle (Secure SDLC) practices within engineering teams.
  • Experience driving vulnerability management and remediation programs across multiple product or engineering teams.
  • Experience performing vulnerability assessment, technical triage, remediation planning, and risk reduction activities.
  • Experience working with application security testing, dependency analysis, software composition analysis, and container security tools.
  • Experience implementing software supply chain security controls and Software Bill of Materials (SBOM) processes.
  • Experience integrating security controls, validation, and automation into CI/CD pipelines and software delivery workflows.
  • Experience supporting release security reviews, compliance activities, audits, penetration testing, or security assessments.
  • Experience securing cloud-native platforms, containerized workloads, APIs, and Kubernetes-based environments.
  • Experience working with identity and access management, secrets management, and role-based access control models.
  • Experience generating security evidence, remediation reporting, and security metrics for leadership and compliance stakeholders.
  • Experience working within Agile software delivery environments.
  • Experience influencing engineering teams and driving security improvements without direct organizational authority.
  • Experience collaborating effectively with software engineering, architecture, operations, security, and product management teams.

Preferred Experience
  • Experience supporting SaaS, IoT, telemetry, or real-time data platforms.
  • Experience supporting platforms operating under 24x7 availability requirements.
  • Experience supporting Azure-based data platforms.
  • Experience working within globally distributed engineering organizations.
  • Experience supporting external audits, penetration testing programs, and compliance initiatives.
  • Experience working within regulated enterprise environments.
  • Experience supporting ISO 27001-aligned environments.
  • Experience applying IEC 62443 security principles within industrial or operational technology environments.
  • Experience supporting SOC 2 readiness programs or equivalent security control frameworks.
  • Experience implementing security programs aligned with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), or similar industry frameworks.

Preferred Qualifications
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • Microsoft Certified: Azure DevOps Engineer Expert (AZ-400).
  • Certified Information Systems Security Professional (CISSP).
  • Certified Cloud Security Professional (CCSP).
  • Certified Secure Software Lifecycle Professional (CSSLP).
  • Certified Kubernetes Security Specialist (CKS).
  • GIAC Cloud Security Automation (GCSA).

Success Measures

Success in this role will be measured by:
  • Reduction of security debt and vulnerability backlog.
  • Timely remediation of critical and high-risk vulnerabilities.
  • Effective operation and adoption of SonarQube, BDBA, SBOM, and security automation tooling.
  • Improved Secure SDLC adoption across engineering teams.
  • High-quality and audit-ready release security evidence.
  • Successful support of CPCERT, penetration testing, and security review activities.
  • Reduction in recurring security findings.
  • Improved visibility into platform security posture through actionable metrics and reporting.
  • Sustainable alignment with Schneider Electric security requirements and engineering standards.

What's in it for me?
  • Lead transformative projects that protect critical infrastructure and make a measurable impact
  • Work with cutting-edge technologies and solve complex cybersecurity challenges across diverse industries
  • Collaborative culture that values technical excellence, innovation, and continuous professional development
  • Access to certifications, training, and resources that accelerate your career growth

Bring your cybersecurity expertise to a team that's ready to support your success - apply today!

About Schneider Electric

Schneider Electric is a multinational corporation that specializes in energy management and automation solutions. The company was founded in 1836 and is headquartered in Rueil-Malmaison, France. Schneider Electric offers a wide range of products and services including electrical distribution, automation and control, and energy management. The company operates in over 100 countries and has a strong presence in the industrial and commercial sectors. Schneider Electric is committed to sustainability and has set ambitious targets to reduce its environmental impact. The company has received numerous awards for its sustainability efforts and is recognized as a leader in the industry.
Learn more about Schneider Electric
Size
166,025 employees
Industry
Founded
1836
NASDAQ

Similar Jobs

More Jobs at Schneider Electric

More Information Technology Jobs

Find similar Principal DevSecOps Engineer jobs: