Security Engineer
  • Fixity Technologies
2 Days Ago
NA
W2, 1099
Remote
5-10 Years
Required Skills: DevSecOps, Application Security, Infrastructure Security, CI/CD Pipeline Security, SAST, SCA, DAST, MAST, IaC Security, Container Security, Docker, Kubernetes, AWS, Azure, GCP, Secure Coding, Security Automation, Vulnerability Management, ServiceNow, Agile, Scrum, Risk Management, Compliance, HIPAA, PCI, NIST, GDPR, CCPA
Job Description
CVS Health is hiring a Security Engineer – DevSecOps to support the day-to-day operations of the DevSecOps team. This role focuses on executing security tasks, maintaining application and CI/CD pipeline security, enabling developer teams, and driving operational efficiency through automation.
The ideal candidate is detail-oriented, operationally strong, and comfortable working across security tooling, engineering teams, and development processes.
 
Key Responsibilities
  • Perform security operations across application security, infrastructure security, and CI/CD pipeline security.
  • Support developer onboarding for security tools and processes by providing guidance and training.
  • Ensure complete and consistent security scan coverage for assigned applications.
  • Identify opportunities to automate recurring security tasks and reduce manual effort.
  • Support compliance and risk management by tracking policy adherence and documenting exceptions.
  • Improve operational efficiency through automation of security scans, vulnerability triage, and workflow enhancements.
  • Manage vulnerability tracking through accurate tagging, ownership assignment, and remediation workflows.
  • Increase developer security awareness through continuous support, coaching, and enablement.
  • Participate in ServiceNow ticket handling, daily user story updates, and on-call rotations.
  • Automate security workflows within a DevSecOps environment.
Required Qualifications
  • 3+ years of experience in Security Engineering, DevSecOps, or a related field.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Hands-on experience with application security and CI/CD security tools.
  • Strong understanding of secure coding principles and modern software development practices.
  • Experience with:
    • SAST (Static Application Security Testing)
    • SCA (Software Composition Analysis)
    • DAST (Dynamic Application Security Testing)
    • MAST (Mobile Application Security Testing)
    • Container Security Scanning
    • Infrastructure as Code (IaC) Security Scanning
  • Experience with ServiceNow ticket management and Agile development processes.
  • Experience automating security workflows in DevSecOps environments.
  • Strong verbal and written communication skills.
  • Ability to explain security concepts to both technical and non-technical stakeholders.
  • Experience coaching or training developers on security best practices.
Preferred Qualifications
  • Experience with mobile application security.
  • Knowledge of compliance and regulatory frameworks including:
    • HIPAA
    • PCI-DSS
    • NIST
    • GDPR
    • CCPA
  • Experience with cloud platforms:
    • AWS
    • Azure
    • GCP
  • Experience with container technologies:
    • Docker
    • Kubernetes
  • Security certifications are a plus:
    • CISSP
    • CISM
    • CEH
Technical Skills
  • DevSecOps
  • Application Security
  • Infrastructure Security
  • CI/CD Pipeline Security
  • SAST
  • SCA
  • DAST
  • MAST
  • IaC Security
  • Container Security
  • Docker
  • Kubernetes
  • AWS
  • Azure
  • GCP
  • Secure Coding
  • Security Automation
  • Vulnerability Management
  • ServiceNow
  • Agile/Scrum
  • Risk Management
  • Compliance
  • HIPAA
  • PCI
  • NIST
  • GDPR
  • CCPA
Soft Skills
  • Excellent communication skills
  • Problem-solving mindset
  • Detail-oriented
  • Team collaboration
  • Developer enablement
  • Process improvement
  • Strong documentation skills
Job Summary
This is an excellent opportunity for a Security Engineer with strong DevSecOps experience who enjoys securing modern development environments, automating security processes, and working closely with development teams to build security into the software development lifecycle.

Jobseeker

Looking For Job?
Search Jobs

Recruiter

Are You Recruiting?
Search Candidates