The Capital Group Companies, Inc

Senior DevSecOps Engineer

The Capital Group Companies, Inc$168K — $270K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or a related field or 7+ years in IT/security
  • Experience with agile methodologies like Scrum and Kanban
  • Hands-on experience with containers like Docker and orchestration like Kubernetes
  • Familiarity with DevSecOps tools such as Terraform and Ansible
  • Experience with AWS operations and security
  • Ability to influence collaboration across technical teams
  • Proficient in designing and deploying complex engineering solutions
  • Expertise in programming with Python and familiarity with other languages.

Responsibilities

  • Simplify security automation for CI/CD pipelines
  • Continuously enhance team skills and practices
  • Build relationships to integrate security into designs and deployments
  • Supervise application security controls testing
  • Implement defensive practices across infrastructure and applications
  • Draft and uphold CI/CD security strategy
  • Manage security-related escalations and resolution
  • Develop tools that help engineers use security components
  • Promote early incorporation of security into the development lifecycle
  • Communicate vulnerabilities effectively to varied audiences
  • Leverage vulnerability databases for risk understanding and remediation
  • Integrate security principles into architecture and code
  • Research new security tactics and techniques
  • Enhance DevOps architecture with security standards
  • Define KPIs and metrics in collaboration with teams.

Benefits

  • Annual performance bonus eligibility
  • Participation in Capital's profitability bonus
  • Retirement plan with a 15% contribution on eligible earnings
  • Hybrid work model of 3 days in office per week.
Full Job Description
"I can succeed as a Senior DevSecOps Engineer at Capital Group."

As a Senior DevSecOps Engineer within the Application Security team, you'll support, secure, manage and deploy solutions that secure the software delivery lifecycle for enterprise applications. This is a highly technical role, so you will need a strong understanding of automation, CI/CD infrastructure, software development, and cloud services. Knowledge of information security and application security tools is highly desirable.

The DevSecOps engineer supports the security of continuous integration and continuous deployment (CI/CD) initiatives and is an integrated team member working with software developers, system engineers, cybersecurity engineers and systems administrators. The role is security-focused and helps CI/CD pipelines deliver secure software in a scalable manner while showing developer empathy and engineering excellence such as obsession with security tool output quality, false positive removal, using data / metrics to improve tools that integrate into the CI/CD pipeline. This role is hybrid (in-office 3 days/week) in New York NY.

Responsibilities:
  • Simplify automation that applies security inter-workings with CI/CD pipelines.
  • Work to consistently learn and share advanced skills and practices that promote team excellence.
  • Build relationships with developers, stakeholders and scrum master's to incorporate security principles into engineering design and deployments.
  • Supervise testing and validation in application security controls across projects.
  • Oversee implementation of defensive practices and countermeasures across infrastructure and applications.
  • Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads.
  • Serve as a point of contact for security-based escalations and remain tightly involved through resolution.
  • Build services and tools to enable developers and engineers to easily use security components produced by Application Security team members.
  • Support the ability to "shift left" and incorporate security early on and throughout the development lifecycle.
  • Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging.
  • Leverage Vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors as well as workarounds.
  • Join forces and provision security principles in architecture, infrastructure and code.
  • Regularly research and learn new tactics, techniques and procedures (TTPs) in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary through the CI/CD pipeline.
  • Enrich DevOps architecture with security standards and best practices.
  • Partner with teams to define key performance indicators (KPIs) and metrics across business units.


"I am the person Capital Group is looking for"

  • Bachelor's degree in Computer Science or related field and/or at least 7+ years' experience in information technology, information security administration or security operations.
  • Experience with agile workflows, including Scrum and Kanban.
  • Hands-on experience of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes).
  • Understanding DevSecOps tooling, including Terraform, Ansible, and CI/CD Pipelines.
  • Experience with operations and security across Amazon Web Services (AWS).
  • Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface while performing rapid, continuous implementation.
  • Proficient in designing, building, and deploying complex engineering solutions
  • Expert Programming knowledge in Python. Other Languages a bonus.
  • Interested in Agentic software development, including developing agentic Skills to accelerate feature requests and improve the quality of solutions delivered.
  • Excellence in communicating business risk and remediation requirements from assessments.


"I can apply in less than 4 minutes."

You've reviewed this job posting and you're ready to start the candidate journey with us. Apply now to move to the next step in our recruiting process. If this role isn't what you're looking for, check out our other opportunities and join our talent community.

"I can learn more about Capital Group."

Charlotte Base Salary Range: $136,749-$218,798

Southern California Base Salary Range: $159,354-$254,966

New York Base Salary Range: $168,924-$270,278

In addition to a highly competitive base salary, per plan guidelines, restrictions and vesting requirements, you also will be eligible for an individual annual performance bonus, plus Capital's annual profitability bonus plus a retirement plan where Capital contributes 15% of your eligible earnings.

You can learn more about our compensation and benefits here.

* Temporary positions in the United States are excluded from the above mentioned compensation and benefit plans.

Similar Jobs

More Jobs at The Capital Group Companies, Inc

More Information Technology Jobs

Find similar Senior DevSecOps Engineer jobs: