Apply

DevSecOps Engineer

Posted 3 months agoViewed

View full description

💎 Seniority level: Middle, Minimum of 2 years

📍 Location: United States

💸 Salary: 145000.0 - 155000.0 USD per year

🔍 Industry: Software as a Service (SaaS)

🏢 Company: Authorium👥 51-100💰 $12,000,000 Series A almost 2 years agoConsultingGovernmentInformation TechnologySoftware

🗣️ Languages: English

⏳ Experience: Minimum of 2 years

🪄 Skills: AWSBashGitKubernetesCI/CDLinuxDevOpsTerraformComplianceScripting

Requirements:
  • Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
  • Minimum of 2 years of experience in information security or a related field.
  • Working knowledge of FedRAMP/StateRAMP compliance frameworks.
  • Experience with continuous monitoring tools.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and in teams.
  • Nice to Have: Certifications (CISSP, CISM, CISA, etc.) and knowledge of scripting languages (Python, Bash).
Responsibilities:
  • Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
  • Manage vulnerability and code scanning tools.
  • Conduct security reviews of code, APIs, and infrastructure.
  • Design and deploy secure infrastructure on AWS using Infrastructure as Code.
  • Automate security tasks and monitor security alerts.
  • Collaborate with DevOps to integrate security into development processes.
Apply

Related Jobs

Apply
🔥 DevSecOps Engineer
Posted 6 days ago

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: Broadway Ventures👥 51-100ConsultingInsuranceCommercialProfessional Services

  • Strong proficiency in secure software development (Linux, Windows, macOS environments)
  • Deep familiarity with DISA STIGs, RMF, POA&M generation, and compliance scanning
  • Experience with CI/CD pipelines, STIG, automation, and data ingestion/reporting systems
  • Web/database development for centralized and distributed environments
  • Open-source software management and secure authentication integration (CAC/SIPRNET Token)
  • Develop a client-side compliance scanner
  • Build a centralized and distributable web/database interface
  • Support CI/CD development and release cycles
  • Ensure ongoing software assurance and compatibility with DoD security mandates

Software DevelopmentCybersecurityCI/CDLinuxComplianceScripting

Posted 6 days ago
Apply
Apply

📍 United States, United Kingdom

🧭 Contract

💸 129502.0 - 144444.0 USD per year

🔍 Software Development

🏢 Company: Slingshot Aerospace👥 101-250💰 $30,000,000 Debt Financing 7 months agoAerospaceAnalyticsSimulationSoftware

  • 3+ years of professional experience in a DevSecOps or similar role
  • Experience with container security practices within Kubernetes and Helm
  • Experience with security configuration of AWS Cloud Native Technologies
  • Deep working knowledge of version control (Git) and CI/CD tools (GitHub Actions)
  • Experience with infrastructure as code frameworks including Terraform
  • Good understanding of networking, routing, firewalls, VPN, SSL
  • Knowledge of programming/scripting languages (Python, Bash, JavaScript) used in DevSecOps life cycles
  • Keen attention to detail and industry best practices pertaining to privacy, security, and compliance
  • Work within Engineering teams to interweave security with the scalability, performance, reliability, and functional requirements to virtualized/cloud computing solutions
  • Leverage industry best practices and experience to ensure that security is baked into deliverables from the start and that each product and program fully embrace a DevSecOps and “shift-left on security” mentality
  • Develop automated build and test pipeline strategies including aspects of security and compliance to ensure viability of cloud deployment solutions
  • Secure and manage cloud-native resource on providers like AWS and Azure through infrastructure-as-code and compliance-as-code
  • Administer and support developer and user access to cloud resources
  • Leverage observability tools to monitor security metrics for applications virtualized resources
  • Participate in Agile software develop and deployment processes
  • Provide ongoing support for the services and applications that are critical to our business needs
  • Communicate methods, findings, and hypotheses with stakeholders
  • Perform other duties as assigned (to be less than 10% of the responsibilities listed above)

AWSPythonAgileBashCloud ComputingGitKubernetesAzureCI/CDDevOpsTerraformMicroservicesCompliance

Posted 13 days ago
Apply
Apply
🔥 DevSecOps Engineer
Posted 26 days ago

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: 540

  • 6+ years of experience in DevSecOps, cloud security, or related roles
  • Strong AWS experience, including IAM, VPC security, KMS, GuardDuty, and AWS Security Hub
  • Experience with STIG hardening and compliance enforcement in cloud and on-prem environments
  • Hands-on experience with ACAS (Tenable Nessus SecurityCenter) for vulnerability scanning and remediation
  • Proficiency with CI/CD tools such as GitLab CI/CD, Jenkins, or AWS CodePipeline
  • Experience with scripting and automation (Python, Bash, PowerShell, etc.)
  • Familiarity with compliance frameworks (NIST 800-53, FedRAMP, DoD RMF)
  • Experience with container security for Kubernetes, Docker, or AWS ECS/EKS
  • Strong knowledge of security monitoring tools (SIEM, IDS/IPS, etc.)
  • Develop a data transformation and workflow solution for the US Army
  • Deploy and operate a replacement for a legacy financial system to the cloud
  • Innovate new cloud-first solutions for the US Army’s data management ecosystem
  • Integrate security into DevOps pipelines
  • Ensure compliance with security policies
  • Conduct vulnerability assessments and remediation

AWSDockerPythonBashCybersecurityJenkinsKubernetesCI/CDDevOpsCompliance

Posted 26 days ago
Apply
Apply
🔥 DevSecOps Engineer II
Posted 28 days ago

📍 United States

🔍 Information Security

  • Minimum five (5) years of supporting / implementing network security platforms & strategies.
  • Minimum three (3) years of experience in information security.
  • Thorough understanding of information security—call it a security ethos—capable of being shared as best practices that provide guidance to other organizations within Allegiant as well as provide skills uplift to the information security engineering team.
  • Hands-on experience with security engineering tasks in DevSecOps workflows.
  • Strong knowledge of, and long working experience with, Terraform Infrastructure as Code.
  • Capable of utilizing and maintaining popular code linting tools such as Bandit, JShint, ShellCheck, ESLint, Pylint, Checkov (IAC) and Rubocop to enforce coding standards and improve code quality.
  • Skilled in the creation and maintenance of scripts in Python, Bash or Powershell to automate security tasks and improve efficiency.
  • Strong knowledge of public cloud security and private cloud security constructs, and the effective deployment of cloud security tools such as network security groups, NGFW, IAM.
  • Familiarity and experiences with Amazon routing and load balancing technologies including ALB (Application Load Balancers), NLB, and Gateway Load Balancer.
  • Experience Network routing protocols such as BGP, OSPF, EIGRP, IGRP, RIP, and RIPv2 with accompanying best practices.
  • Experience with Cloud network resources such as VPC (Virtual Private Cloud) peering and Transit Gateway.
  • Experience and proven ability to work under time constraints and pressure.
  • Ability to work independently and as part of a team, and being comfortable working in a fast-paced, dynamic environment.
  • Capable of advising and implementing CloudFormation & Terraform IAC best practices and security.
  • Develop and maintain Infrastructure as Code (IaC) pipelines on AWS and Azure.
  • Work closely with development and security teams to ensure that our infrastructure meets the highest standards of security and compliance.
  • Build and maintain automated security and compliance checks for our infrastructure.
  • Develop and maintain monitoring and alerting systems for our infrastructure.
  • Automate security response and remediation processes.
  • Protect the organization's computer systems, networks, and data through the troubleshooting and maintenance of security measures.
  • Demonstrate excellent problem-solving skills, attention to detail, and effective communication skills.
  • Remain apprised of CSP (Cloud Service Provider) best practices and documentation, maintaining appropriate certifications and sharing findings with teams during weekly meetings.
  • Create and maintain scripts in Python, Bash or PowerShell to automate security tasks and improve efficiency.
  • Utilize and maintain popular code linting tools such as Bandit, JShint, ShellCheck, ESLint, Pylint, Checkov (IAC) and Rubocop to enforce coding standards and improve code quality.
  • Develop and maintain security policies and procedures for AWS IAM, AWS Key Management, and AWS Certificate Manager to ensure best practices are being followed.
  • Monitor and maintain Cloudflare WAF to ensure that web applications are protected from OWASP Top 10 vulnerabilities.
  • Manage and configure AWS Guard Duty to detect and respond to security incidents in real-time.
  • Work with SIEMs to ensure that logs and events are being captured and analyzed to identify potential security threats.
  • Use Terraform IAC to create and manage AWS infrastructure in a secure and compliant manner.
  • Write Python scripts to automate security tasks and improve efficiency.
  • Use Checkov IAC Linting to ensure that AWS infrastructure code is compliant with security best practices.
  • Create and manage AWS Lambda functions to automate incident response and remediation tasks.
  • Configure AWS Event Bridge and AWS CloudWatch to monitor infrastructure and trigger alerts when security events occur.
  • Work with the team to review and approve Github pull requests, and troubleshoot Github action and custom pipeline builds.
  • Troubleshoot AWS Network Infrastructure and infrastructure as code to promptly resolve incidents and minimize downtime and maximize uptime.
  • Advise on network protocol, operating system, cryptography, and AWS cloud security.
  • Maintain security controls, evaluate products and technologies, and integrate them into IT systems and applications.
  • Deploy AWS security measures and conduct regular security assessments.
  • Debug Terraform & CloudFormation infrastructure as code builds in custom pipelines as well as in GitHub Actions.
  • Work independently and as part of a team in a fast-paced, dynamic environment.
  • Deploy security measures to protect data stored on public clouds against unauthorized access.
  • Deploy identity and access management roles and permissions in Allegiant’s cloud providers.
  • Remain up to date on CSP best practices and documentation and share findings with teams.
  • Automate security tasks and improve efficiency with scripts in Python, Bash, Terraform or PowerShell.
  • Work effectively in an Agile Scrum workflow, demonstrating strong project management hygiene.
  • Provide advanced in-depth, top-level support for complex information security issues at all Allegiant locations.
  • Work with application developers to identify security requirements and issues.
  • Document components of the Allegiant information security systems.
  • Remain apprised of CSP (Cloud Service Provider) best practices and documentation, maintaining appropriate certifications and sharing findings with teams during weekly meetings.
  • Develop and implement AWS Lambda functions to automate incident response and remediation tasks.
  • Configure AWS Event Bridge and AWS CloudWatch to monitor infrastructure and immediately alert the team when security events occur.
  • Collaborate with the team to review and authorize Github pull requests, and identify and resolve issues with Github Actions and custom pipeline builds.
  • Model Allegiant’s customer service standards in personal actions and when providing direction.
  • Other duties as assigned.

AWSPythonBashCloud ComputingCybersecurityGitAzureCI/CDLinuxDevOpsTerraformMicroservices

Posted 28 days ago
Apply
Apply
🔥 Lead DevSecOps Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: 540

  • 7+ years of experience with Cloud Service Providers (AWS, GCP, Azure, etc.)
  • 5+ years of experience creating/maintaining CI/CD pipelines
  • Experience with infrastructure as code (Terraform, CloudFormation, etc.)
  • Experience with providing technical oversight and guidance on containerized application and microservices architecture (Docker, Kubernetes)
  • Configuration Management experience (Ansible, Puppet, etc)
  • Experience deploying applications in DoD or other accredited federal environments that require IA certification and accreditation to deploy
  • In-depth knowledge of DevSecOps best practices
  • Manage and mentor a team of DevSecOps Engineers
  • Drive the development and implementation of secure, scalable, and automated solutions for the DoD’s Air Force integration platform

DockerLeadershipPostgreSQLCloud ComputingCybersecurityGCPGitKubernetesMySQLCI/CDDevOpsTerraformMicroservicesNetworkingAnsible

Posted about 1 month ago
Apply
Apply
🔥 DevSecOps Engineer
Posted about 1 month ago

📍 United States

🧭 Full-Time

🔍 Software Development

🏢 Company: 540

  • 7+ years of professional experience
  • 3+ years of experience creating/maintaining CI/CD pipelines with Jenkins, Cloudbees and/or Harness
  • 3+ years of experience with containerized applications (Docker, Kubernetes, Helm Charts)
  • In-depth knowledge of DevOps best practices
  • Software development experience with Java and/or Groovy
  • Experience with AWS (ECS, RDS, etc.)
  • Experience with Ansible for automating infrastructure deployment, configuration management and system orchestration
  • Experience with infrastructure as code (Terraform, CloudFormation, etc.)
  • Experience with Git and the Gitflow development workflow
  • Excellent verbal and written communication skills
  • Strong problem solving and troubleshooting skills
  • Creating/maintaining CI/CD pipelines with Jenkins, Cloudbees and/or Harness
  • Experience with containerized applications (Docker, Kubernetes, Helm Charts)
  • Design and implement cloud infrastructure
  • Ensure the seamless and accurate exchange of information from different systems by facilitating the transfer of data

AWSDockerSoftware DevelopmentAmazon RDSGitJavaJenkinsKubernetesGroovyCI/CDLinuxDevOpsTerraformAnsible

Posted about 1 month ago
Apply
Apply
🔥 GCP DevSecops Engineer
Posted about 2 months ago

📍 USA

🧭 Contract

🔍 IT Consulting and Software Services

  • BS/BTech (or higher) in Computer Science, Information Technology, Cybersecurity or a related field, or equivalent experience.
  • 6+ years in securing and deploying applications within Cloud Native environments.
  • 8+ years of experience in GCP, including IaC (Terraform/Pulumi), data migration, and security controls.
  • 3+ years in a dedicated DevOps/DevSecOps/SRE role with focus on secure SDLC processes.
  • Working cross-functionally to design, build, and operate solutions that improve and mature security capabilities.
  • Leveraging data to understand trends and opportunities for security improvements and making recommendations.
  • Leading incident response efforts and ensuring effective resolution of security incidents.
  • Helping maintain security documentation related to policies and procedures.
  • Mentoring and coaching junior engineers or analysts.

DockerBashCybersecurityGCPJenkinsKubernetesTerraformAnsible

Posted about 2 months ago
Apply
Apply
🔥 Lead DevSecOps Engineer
Posted 2 months ago

📍 USA

🔍 Defense and national security

🏢 Company: STR👥 501-1000HospitalityMarketplaceAnalytics

  • Active security clearance, for which U.S. citizenship is needed.
  • BS in Computer Science, Information Technology, or related technical field.
  • Experience with CI/CD tools like GitLab and pipeline automation.
  • Cloud platforms including AWS, Azure, or Google Cloud, and automated provisioning tools like Ansible, Chef, or TerraForm.
  • Containerization technologies such as Docker and Podman.
  • Kubernetes management solutions such as EKS and Rancher.
  • Experience deploying and monitoring Kubernetes clusters.
  • Basic knowledge of Linux System Administration.
  • Knowledge of Python and Linux Shell.
  • Knowledge of Cyber Security fundamentals.
  • Organized and detail-oriented with the ability to work independently and collaboratively.
  • Effective communication skills to technical and non-technical audiences.
  • Design and implement Continuous Integration/Continuous Deployment (CI/CD) pipelines utilizing GitLab or other systems.
  • Support Amazon Web Services (AWS) toolsets in an unclassified environment.
  • Maintain multiple CI/CD environments at various classification levels.
  • Configure CI/CD environments for application performance, security monitoring, and alerting.
  • Act as a point person with the corporate IT organization for infrastructure configurations.
  • Advocate for and educate engineers on DevOps fundamentals.

AWSDockerPythonAWS EKSCybersecurityKubernetesCI/CDLinuxTerraformAnsible

Posted 2 months ago
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Manufacturing

🏢 Company: Xometry👥 501-1000💰 $75,000,000 Series E over 4 years agoArtificial Intelligence (AI)3D PrintingIndustrial EngineeringSoftware

  • Minimum of 5+ years of experience in DevSecOps, DevOps, or related field with a focus on security.
  • Experience with AWS or deep knowledge in GCP or Azure.
  • Proficiency with CI/CD tools such as Github Actions, Jenkins, GitLab CI, or CircleCI.
  • Hands-on experience with Kubernetes and securing production clusters.
  • Proficiency with infrastructure as code (IaC) tools like Terraform, OpenTofu, or CloudFormation.
  • Strong programming skills in Python and shell scripting.
  • Knowledge of security best practices including secure coding and access control.
  • Excellent problem-solving and communication skills.
  • Collaborate with development, operations, and security teams to integrate security into the CI/CD pipeline.
  • Design, implement, and maintain security automation tools and processes.
  • Develop and enforce security policies for cloud and on-premises infrastructure.
  • Monitor security vulnerabilities and incidents, providing timely remediation.
  • Perform regular security assessments including code reviews and vulnerability scans.
  • Implement security tools like firewalls and endpoint protection.
  • Work with development teams on secure coding practices.
  • Secure Kubernetes clusters and containerized environments.
  • Manage infrastructure as code (IaC) with Terraform or similar.
  • Automate security tasks using Python and shell scripting.
  • Stay updated on security threats and technologies.
  • Participate in incident response and disaster recovery.

AWSPythonCybersecurityGCPJenkinsKubernetesAzureCI/CDTerraform

Posted 2 months ago
Apply
Apply

📍 United States of America

🧭 Full-Time

💸 145000.0 - 170000.0 USD per year

🔍 Software Engineering, Cloud Services, Scientific Research

🏢 Company: external

  • Minimum of a college or university degree in a related field.
  • 5-7 years of work experience in a related job discipline.
  • Strong understanding of security concepts including threat modeling and vulnerability management.
  • Knowledge of SDLC and cloud security principles.
  • Experience with container security and AWS services.
  • Skills in scripting (Python, Bash) and Linux administration.
  • Lead the implementation and monitoring of security procedures and controls.
  • Integrate security features into the software development life cycle.
  • Define and document cloud infrastructure architecture.
  • Deploy, operate, monitor, and maintain production Globus services.
  • Assist other team members in addressing operational issues.
  • Design new systems, features, and tools while solving complex problems.

AWSDockerPostgreSQLPythonBashDynamoDBElasticSearchNginxCI/CDRESTful APIsLinuxTerraformNetworking

Posted 3 months ago
Apply