Role OverviewWe are seeking a
Principal DevSecOps Engineer to own the implementation, operation, and continuous improvement of the security posture of the EcoStruxure Building Data Platform.
This role serves as the hands-on security leader embedded within the engineering organization. The successful candidate will lead security tooling, security automation, vulnerability remediation coordination, software supply chain security, Secure SDLC implementation, release security readiness, and cloud security enablement across the platform.
The Principal DevSecOps Engineer is accountable for the implementation and operational execution of product security controls.
This role works closely with:
- Security Advisor
- Principal Systems Engineer
- Engineering Technical Leads
- Principal Cloud Operations & Infrastructure Engineer
- Product Owners
- Schneider Electric Product Security
- 24x7 Operation Support Team
The Security Advisor remains responsible for independent governance, risk assessment, policy interpretation, CPCERT alignment, risk acceptance guidance, and security oversight.
In this role, you are responsible for implementation, execution, automation, evidence generation, and remediation coordination.
Key ResponsibilitiesSecurity Posture Management- Own the operational security posture of the EcoStruxure Building Data Platform.
- Establish and maintain security baselines across applications, cloud services, containers, APIs, CI/CD systems, and supporting platform components.
- Continuously assess security maturity and identify opportunities for improvement.
- Implement security controls and automation that reduce platform risk.
- Report operational security health, remediation status, and security trends.
Vulnerability Management & Remediation- Operate vulnerability management activities in accordance with Schneider Electric CPCERT processes and security requirements.
- Perform technical triage of findings from SonarQube, Black Duck Binary Analysis (BDBA), penetration tests, container security scans, dependency analysis tools, and cloud security assessments.
- Assess technical applicability of vulnerabilities and identify remediation approaches for affected platform components.
- Partner with the Security Advisor on vulnerability prioritization, risk evaluation, exception reviews, and remediation timelines.
- Lead remediation planning and coordinate execution with Technical Leads and engineering teams.
- Track remediation progress, closure status, security debt metrics, and vulnerability trends.
- Support vulnerability reporting and evidence requirements for security reviews, audits, and compliance activities.
Secure SDLC Implementation & Automation- Partner with the Security Advisor to implement Secure SDLC requirements across the EcoStruxure Building Data Platform.
- Embed automated security controls and validation activities into GitHub Actions workflows and deployment pipelines.
- Implement approved security gates and release readiness checks within software delivery processes.
- Generate and maintain security evidence required for product release reviews and compliance activities.
- Support developer enablement through practical guidance, tooling, templates, and automation that promote secure engineering practices.
- Improve security visibility within the software development lifecycle through automation and metrics.
Software Supply Chain Security- Own Software Bill of Materials (SBOM) generation and management processes.
- Establish software supply chain security controls across development and release processes.
- Manage dependency analysis, artifact validation, and binary scanning programs.
- Ensure container image integrity and security compliance.
- Drive adoption of software provenance and artifact attestation practices.
Security Tooling OwnershipOwn project level configuration, operational effectiveness, and continuous improvement of:
- SonarQube
- Black Duck Binary Analysis (BDBA)
- SBOM Studio
- GitHub Security
- Secret scanning solutions
- Container security platforms
- Dependency analysis solutions
- Security reporting and dashboarding tools
Partner with engineering teams to ensure security tooling is effective, adopted, and integrated into day-to-day development activities.
Security Operations & Compliance Enablement- Implement approved security requirements through engineering controls, automation, and security tooling.
- Partner with the Security Advisor, Product Owners, and Technical Leads to plan and execute security remediation initiatives.
- Support penetration testing, CPCERT reviews, compliance activities, and security assessments.
- Coordinate operational activities supporting release security reviews.
- Maintain security dashboards, remediation reporting, and evidence repositories.
- Drive continuous improvement of security tooling, visibility, operational processes, and security engineering practices.
Cloud & Platform SecurityPartner with the Principal Cloud Operations & Infrastructure Engineer to secure:
- Azure Kubernetes Service (AKS)
- Azure Container Registry (ACR)
- Azure Entra ID
- Azure Key Vault
- Workload identities
- Role-Based Access Control (RBAC)
- Container platforms
- Network security controls
- Cloud platform configurations
Provide guidance and implementation support for secure cloud architecture patterns.
Cross-Functional Collaboration- Work closely with Technical Leads to integrate security practices into product development.
- Partner with the Principal Systems Engineer on security-related architecture decisions and standards.
- Collaborate with the Security Advisor on risk reviews, security findings, mitigation strategies, and compliance activities.
- Support 24x7 operations teams with security operational procedures, monitoring guidance, and escalation processes.
- Act as the primary security implementation lead within the EcoStruxure Building Data Platform organization.
Required Qualifications- Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Computer Engineering, or a related technical discipline.
- Equivalent combination of education, professional training, and relevant industry experience may be considered.
Required Experience- 8+ years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, software engineering, or related security-focused roles.
- 3+ years of experience supporting Azure-based cloud-native platforms.
- Experience owning or leading security implementation activities within a software product organization.
- Experience implementing Secure Software Development Lifecycle (Secure SDLC) practices within engineering teams.
- Experience driving vulnerability management and remediation programs across multiple product or engineering teams.
- Experience performing vulnerability assessment, technical triage, remediation planning, and risk reduction activities.
- Experience working with application security testing, dependency analysis, software composition analysis, and container security tools.
- Experience implementing software supply chain security controls and Software Bill of Materials (SBOM) processes.
- Experience integrating security controls, validation, and automation into CI/CD pipelines and software delivery workflows.
- Experience supporting release security reviews, compliance activities, audits, penetration testing, or security assessments.
- Experience securing cloud-native platforms, containerized workloads, APIs, and Kubernetes-based environments.
- Experience working with identity and access management, secrets management, and role-based access control models.
- Experience generating security evidence, remediation reporting, and security metrics for leadership and compliance stakeholders.
- Experience working within Agile software delivery environments.
- Experience influencing engineering teams and driving security improvements without direct organizational authority.
- Experience collaborating effectively with software engineering, architecture, operations, security, and product management teams.
Preferred Experience- Experience supporting SaaS, IoT, telemetry, or real-time data platforms.
- Experience supporting platforms operating under 24x7 availability requirements.
- Experience supporting Azure-based data platforms.
- Experience working within globally distributed engineering organizations.
- Experience supporting external audits, penetration testing programs, and compliance initiatives.
- Experience working within regulated enterprise environments.
- Experience supporting ISO 27001-aligned environments.
- Experience applying IEC 62443 security principles within industrial or operational technology environments.
- Experience supporting SOC 2 readiness programs or equivalent security control frameworks.
- Experience implementing security programs aligned with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), or similar industry frameworks.
Preferred Qualifications- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Azure DevOps Engineer Expert (AZ-400).
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
- Certified Secure Software Lifecycle Professional (CSSLP).
- Certified Kubernetes Security Specialist (CKS).
- GIAC Cloud Security Automation (GCSA).
Success MeasuresSuccess in this role will be measured by:
- Reduction of security debt and vulnerability backlog.
- Timely remediation of critical and high-risk vulnerabilities.
- Effective operation and adoption of SonarQube, BDBA, SBOM, and security automation tooling.
- Improved Secure SDLC adoption across engineering teams.
- High-quality and audit-ready release security evidence.
- Successful support of CPCERT, penetration testing, and security review activities.
- Reduction in recurring security findings.
- Improved visibility into platform security posture through actionable metrics and reporting.
- Sustainable alignment with Schneider Electric security requirements and engineering standards.
What's in it for me?- Lead transformative projects that protect critical infrastructure and make a measurable impact
- Work with cutting-edge technologies and solve complex cybersecurity challenges across diverse industries
- Collaborative culture that values technical excellence, innovation, and continuous professional development
- Access to certifications, training, and resources that accelerate your career growth
Bring your cybersecurity expertise to a team that's ready to support your success - apply today!