Required Skills: DevSecOps Security
Job Description
We are seeking an experienced DevSecOps Security Engineer to join our client's security engineering team. In this role, you will support day-to-day security operations across application security, infrastructure security, and CI/CD pipelines while helping development teams build and deploy secure applications. The ideal candidate has hands-on experience with DevSecOps tools, security automation, vulnerability management, and cloud-native environments.
Key Responsibilities
Perform security operations across application, infrastructure, and CI/CD pipeline security.
Manage and maintain application security scanning programs and ensure complete scan coverage.
Support developer onboarding for security tools, processes, and best practices.
Automate repetitive security tasks to improve operational efficiency.
Track vulnerabilities, ownership, remediation progress, and policy compliance.
Support compliance initiatives by documenting exceptions and monitoring adherence to security standards.
Handle ServiceNow security tickets, user stories, and participate in on-call rotations.
Improve security workflows through automation and process optimization.
Coach development teams on secure coding practices and DevSecOps principles.
Collaborate with engineering teams to integrate security into the software development lifecycle.
Required Qualifications
3+ years of experience in Security Engineering, DevSecOps, or Application Security.
Strong understanding of secure software development and modern DevOps practices.
Hands-on experience with CI/CD security and application security tools.
Experience with security scanning technologies including:
SAST
SCA
DAST
MAST
Container Security
Infrastructure as Code (IaC) Security
Experience with vulnerability management and security automation.
Familiarity with cloud platforms such as AWS, Azure, or GCP.
Experience with Docker and Kubernetes.
Strong communication skills with the ability to support and train development teams.
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
Preferred Qualifications
Experience securing mobile applications.
Knowledge of compliance frameworks including HIPAA, PCI-DSS, NIST, GDPR, and CCPA.
Experience with developer security enablement and coaching.
Security certifications such as CISSP, CISM, or CEH are a plus.