Why This Role Stands Out
This hybrid DevSecOps Engineer role offers a fantastic opportunity to shape secure development practices and advance your cloud security expertise within a reputable company. You'll thrive here if you have 3-5 years of experience in DevOps or AppSec, enjoy automating security into CI/CD pipelines, and are skilled with cloud infrastructure and IaC tools. Apply now to build secure, resilient systems and grow your career!
Quick Overview
Job Description
JOB DESCRIPTION DevSecOps Engineer (Mid-Level) Position Overview
We are seeking a Mid-Level DevSecOps Engineer with 3 to 5 years of experience to integrate automated security practices directly into our software development lifecycle (SDLC). In this role, you will act as a bridge between development, security, and operations teams to ensure our cloud infrastructure and applications are secure by design. Your primary focus will be implementing "shift-left" security, automating security testing, and maintaining secure, resilient CI/CD pipelines.
Key Responsibilities
- Pipeline Automation: Embed and maintain automated security gates (SAST, DAST, SCA) within our existing CI/CD pipelines.
- Vulnerability Triage: Analyze vulnerability scan results, eliminate false positives, and collaborate with developers to remediate real risks.
- Infrastructure as Code: Write and secure cloud infrastructure using IaC frameworks while enforcing policy-as-code rules.
- Secret Management: Implement and manage secure secret, token, and credential storage systems across all deployment environments.
- Compliance & Monitoring: Monitor cloud infrastructure for compliance drift, track audit logs, and configure security alerts.
- Threat Modeling: Participate in architectural security reviews and assist development teams with basic threat modeling. Required Qualifications
- Experience: 3–5 years of professional experience in DevOps, Cloud Engineering, or AppSec roles.
- Cloud Infrastructure: Solid hands-on experience managing infrastructure with at least one major cloud provider (AWS, Azure, or GCP).
- Containers & Orchestration: Proven ability to build, secure, and debug Docker containers and Kubernetes workloads.
- IaC Tools: Practical experience writing reusable, secure code with tools like Terraform, OpenTofu, or CloudFormation.
- Security Tooling: Active experience using vulnerability scanners such as Snyk, SonarQube, Aqua Security, Checkmarx, or Trivy. ,• Automation & Scripting: Competency in writing automation scripts using Python, Bash, or Go.
- CI/CD Platforms: Familiarity with configuring automation pipelines using GitHub Actions, GitLab CI, or Jenkins.
Preferred Qualifications
- Certifications: Holder of (or working toward) certifications like Certified Kubernetes Security Specialist (CKS) or AWS Certified Security - Specialty.
- Network Security: Basic understanding of VPC architecture, IAM roles, firewalls, and WAF configurations.
Similar jobs
- PI
Senior Database Reliability Engineer
NewPro Integrate
New York, NY🇺🇸$120k - $150k/yrRemoteYesterdayAWSETLPostgreSQL+1Technology - JG
Senior DevOps/Enablement Engineer
NewJudge Group, Inc.
Urbandale, IA🇺🇸HybridYesterdayAWSTDDAgile+5Technology - TA
Mainframe SCM & DevOps Migration Specialist
NewTalentrix AI INC
United States🇺🇸HybridYesterdayShellSonarQubeCOBOL+5Technology - QT
Cloud & Application Platform Engineer
NewQUANTUM TECHNOLOGIES LLC
Georgetown, TX🇺🇸$87/hrHybridYesterdayAPI GatewayLoad Balancing.NET+1Technology - RD
DevOps Engineer
NewRandstad Digital
Troy, MI🇺🇸$42 - $52/hrHybridYesterdayDockerDatadogGitHub Actions+6Technology - RD
Desktop/Helpdesk/Production Support - ITSM Tools ServiceNow, Azure DevOps, JIRA
NewRandstad Digital
Tallahassee, FL🇺🇸$25 - $28/hrOn-siteYesterdayJiraProcess ImprovementRoot Cause AnalysisManufacturing