Back to Jobs
Development 1h ago

Senior DevSecOps Engineer

United StatesUnited States
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOpsBestseller 🔥
Learn in 63 Hours
PythonBestseller 🔥
Learn in 56 Hours
CybersecurityAutomation EngineerAWS

Want to know if you're a match for this job?

Calculate My Match Score

Description of the Role

The Senior DevSecOps Engineer builds and operates the tooling, automation, and guardrails that embed security into how software is built, deployed, and run. This is a hands-on engineering role focused on CI/CD pipeline security, infrastructure-as-code, cloud configuration, and endpoint tooling. The role works day to day inside engineering and IT workflows, writing automation, tuning scanners, and driving fixes with the teams that own the code and infrastructure. Security policy, risk, and compliance requirements are set by the Information Security team; this role translates them into working technical controls. AI capabilities, including AWS AI services and Claude, are used to scale triage, remediation, and reporting.

Essential Functions of the Role

Secure Pipeline & SDLC Engineering:

  • Build and maintain security tooling in CI/CD pipelines, including SAST, DAST, software composition analysis, secret scanning, and container image scanning.
  • Implement policy-as-code gates, branch protections, and build and artifact integrity controls in GitHub.
  • Conduct threat modeling and secure design reviews for applications, services, and pipelines.

Cloud & Infrastructure Security Automation:

  • Implement and enforce AWS configuration baselines, including VPCs, security groups, IAM guardrails, and perimeter controls.
  • Scan infrastructure-as-code before deployment and remediate configuration drift and unintended network exposure.

Vulnerability Remediation Engineering:

  • Operate the vulnerability scanning stack across GitHub, AWS Inspector, Microsoft Defender, and CrowdStrike Falcon, including deployment, coverage, tuning, and integrations.
  • Triage findings, eliminate false positives, and work directly with engineering and IT owners to land fixes within defined SLAs.
  • Automate patching, dependency upgrades, and remediation workflows wherever possible.

Endpoint & Workload Hardening:

  • Configure and maintain endpoint and workload protection policies in Microsoft Defender and CrowdStrike Falcon.
  • Develop hardening baselines for servers, containers, and developer workstations, and automate their deployment.

Secrets & Pipeline Identity:

  • Implement secrets management and short-lived credential patterns, such as OIDC federation, for build and deployment systems.
  • Eliminate long-lived credentials and maintain hygiene of service accounts and pipeline permissions.

AI-Enabled Automation:

  • Apply AWS AI services and Claude to scale vulnerability triage, generate remediation guidance, and automate recurring security engineering work.
  • Ensure AI-assisted output is reviewed, auditable, and explainable.

Engineering Enablement & Reporting:

  • Partner with Engineering and IT teams to make the secure path the default path through guidance, documentation, and self-service tooling.
  • Produce coverage, remediation, and exception metrics, and supply technical evidence and telemetry to the Information Security team for audit and reporting purposes.

Qualifications

Experience: 5–7 years in DevSecOps, application security, cloud security, or platform engineering, with hands-on build and automation responsibility.
Education: Bachelor's degree or equivalent experience in Computer Science, Engineering, or related field.

Skills:

  • Strong hands-on experience with AWS, GitHub Actions, Microsoft Defender, and CrowdStrike Falcon.
  • Proficiency in scripting and automation (Python, Bash, or similar) and infrastructure-as-code (Terraform, CloudFormation, or similar).
  • Working knowledge of containers and orchestration, including securing container build and runtime.
  • Expertise in vulnerability management tooling and application threat modeling.
  • Proficiency using AI tools (AWS AI services, Claude) to improve engineering workflows.
  • Excellent documentation and communication skills, with the ability to influence engineering teams without direct authority.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More