Why This Role Stands Out
This hybrid DevSecOps Engineer role offers a fantastic opportunity to shape secure development practices and advance your cloud security expertise within a reputable company. You'll thrive here if you have 3-5 years of experience in DevOps or AppSec, enjoy automating security into CI/CD pipelines, and are skilled with cloud infrastructure and IaC tools. Apply now to build secure, resilient systems and grow your career!
Quick Overview
Job Description
JOB DESCRIPTION DevSecOps Engineer (Mid-Level) Position Overview
We are seeking a Mid-Level DevSecOps Engineer with 3 to 5 years of experience to integrate automated security practices directly into our software development lifecycle (SDLC). In this role, you will act as a bridge between development, security, and operations teams to ensure our cloud infrastructure and applications are secure by design. Your primary focus will be implementing "shift-left" security, automating security testing, and maintaining secure, resilient CI/CD pipelines.
Key Responsibilities
- Pipeline Automation: Embed and maintain automated security gates (SAST, DAST, SCA) within our existing CI/CD pipelines.
- Vulnerability Triage: Analyze vulnerability scan results, eliminate false positives, and collaborate with developers to remediate real risks.
- Infrastructure as Code: Write and secure cloud infrastructure using IaC frameworks while enforcing policy-as-code rules.
- Secret Management: Implement and manage secure secret, token, and credential storage systems across all deployment environments.
- Compliance & Monitoring: Monitor cloud infrastructure for compliance drift, track audit logs, and configure security alerts.
- Threat Modeling: Participate in architectural security reviews and assist development teams with basic threat modeling. Required Qualifications
- Experience: 3–5 years of professional experience in DevOps, Cloud Engineering, or AppSec roles.
- Cloud Infrastructure: Solid hands-on experience managing infrastructure with at least one major cloud provider (AWS, Azure, or GCP).
- Containers & Orchestration: Proven ability to build, secure, and debug Docker containers and Kubernetes workloads.
- IaC Tools: Practical experience writing reusable, secure code with tools like Terraform, OpenTofu, or CloudFormation.
- Security Tooling: Active experience using vulnerability scanners such as Snyk, SonarQube, Aqua Security, Checkmarx, or Trivy. ,• Automation & Scripting: Competency in writing automation scripts using Python, Bash, or Go.
- CI/CD Platforms: Familiarity with configuring automation pipelines using GitHub Actions, GitLab CI, or Jenkins.
Preferred Qualifications
- Certifications: Holder of (or working toward) certifications like Certified Kubernetes Security Specialist (CKS) or AWS Certified Security - Specialty.
- Network Security: Basic understanding of VPC architecture, IAM roles, firewalls, and WAF configurations.
Similar jobs
- AI
Site Reliability Engineer, Cyber with Security Clearance
NewAnduril Industries
Arlington, VA🇺🇸$146k - $220k/yrOn-site13 hours agoBashComputer VisionKubernetes+1Technology - PS
Sr. IT DevOps Engineer
NewPrecision System Design Inc.
Cleveland, OH🇺🇸Remote13 hours agoAWSAzureGit+3Technology - MM
Senior DevOps Engineer
NewMitchell Martin, Inc.
Irving, TX🇺🇸$54 - $64/hrHybrid13 hours agoTechnology - SG
Release Train Engineer
NewS&P Global
New York, NY🇺🇸$170k - $190k/yrHybrid13 hours agoSAFeScrumAgile+4Engineering - AT
Voice Network Engineer with Security Clearance
Abacus Technology
Scott AFB, IL🇺🇸Hybrid1 week agoExpressUnityTechnology - EM
Senior Software DevOps Developer, TS/SCI Poly required with Security Clearance
NewEmtak LLC
Columbia, MD🇺🇸$172k - $305k/yrRemoteYesterdayCUDAC++GitLab CI+4Technology