Haystack
← Back to Jobs
Remote
Technology

Security Engineer - DevSecOps

Fixity TechnologiesAK🇺🇸United StatesPosted 6 Aug 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

Job Title: Security Engineer DevSecOps
Location: 100% Remote (USA)
Employment Type: Contract
Job Description
CVS Health is hiring a Security Engineer DevSecOps to support the day-to-day operations of the DevSecOps team. This role focuses on executing security tasks, maintaining application and CI/CD pipeline security, enabling developer teams, and driving operational efficiency through automation.
The ideal candidate is detail-oriented, operationally strong, and comfortable working across security tooling, engineering teams, and development processes.
Key Responsibilities
  • Perform security operations across application security, infrastructure security, and CI/CD pipeline security.
  • Support developer onboarding for security tools and processes by providing guidance and training.
  • Ensure complete and consistent security scan coverage for assigned applications.
  • Identify opportunities to automate recurring security tasks and reduce manual effort.
  • Support compliance and risk management by tracking policy adherence and documenting exceptions.
  • Improve operational efficiency through automation of security scans, vulnerability triage, and workflow enhancements.
  • Manage vulnerability tracking through accurate tagging, ownership assignment, and remediation workflows.
  • Increase developer security awareness through continuous support, coaching, and enablement.
  • Participate in ServiceNow ticket handling, daily user story updates, and on-call rotations.
  • Automate security workflows within a DevSecOps environment.
Required Qualifications
  • 3+ years of experience in Security Engineering, DevSecOps, or a related field.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Hands-on experience with application security and CI/CD security tools.
  • Strong understanding of secure coding principles and modern software development practices.
  • Experience with:
    • SAST (Static Application Security Testing)
    • SCA (Software Composition Analysis)
    • DAST (Dynamic Application Security Testing)
    • MAST (Mobile Application Security Testing)
    • Container Security Scanning
    • Infrastructure as Code (IaC) Security Scanning
  • Experience with ServiceNow ticket management and Agile development processes.
  • Experience automating security workflows in DevSecOps environments.
  • Strong verbal and written communication skills.
  • Ability to explain security concepts to both technical and non-technical stakeholders.
  • Experience coaching or training developers on security best practices.
Preferred Qualifications
  • Experience with mobile application security.
  • Knowledge of compliance and regulatory frameworks including:
    • HIPAA
    • PCI-DSS
    • NIST
    • GDPR
    • CCPA
  • Experience with cloud platforms:
    • AWS
    • Azure
    • Google Cloud Platform
  • Experience with container technologies:
    • Docker
    • Kubernetes
  • Security certifications are a plus:
    • CISSP
    • CISM
    • CEH
Technical Skills
  • DevSecOps
  • Application Security
  • Infrastructure Security
  • CI/CD Pipeline Security
  • SAST
  • SCA
  • DAST
  • MAST
  • IaC Security
  • Container Security
  • Docker
  • Kubernetes
  • AWS
  • Azure
  • Google Cloud Platform
  • Secure Coding
  • Security Automation
  • Vulnerability Management
  • ServiceNow
  • Agile/Scrum
  • Risk Management
  • Compliance
  • HIPAA
  • PCI
  • NIST
  • GDPR
  • CCPA
Soft Skills
  • Excellent communication skills
  • Problem-solving mindset
  • Detail-oriented
  • Team collaboration
  • Developer enablement
  • Process improvement
  • Strong documentation skills

Skills

Docker
AWS
Scrum
Agile
Azure
GDPR
Google Cloud
HIPAA
Kubernetes

Similar jobs