Senior DevSecOps Engineer

Open 29d posting dated 2 weeks ago

The Senior DevSecOps Engineer will be responsible for embedding security controls, architecture patterns, and operational security practices into the software delivery lifecycle. The role combines hands-on DevSecOps engineering, security architecture advisory, vulnerability management, secure CI/CD enablement, and close collaboration with development teams. This position is especially focused on securing application delivery pipelines, improving vulnerability detection and remediation, supporting development teams in secure engineering practices, and ensuring that source code, dependencies, container images, secrets, and deployment artifacts are continuously assessed before promotion to production.

Main Responsibilities:

  • Define and implement secure DevSecOps architectures and CI/CD security controls (SAST, SCA, secrets, containers, SBOM, quality gates).

  • Integrate and manage security tools (GitHub Advanced Security, SonarQube, JFrog) within development workflows.

  • Establish secure artifact management and controlled promotion across environments.

  • Manage vulnerabilities end-to-end: analysis, prioritization, remediation support, and reporting.

  • Configure GitHub security features and enforce repository and PR governance standards.

  • Maintain code quality and security policies using SonarQube.

  • Secure artifact repositories and dependencies using JFrog Artifactory and Xray.

  • Define branching strategies and enforce secure release and deployment controls.

  • Ensure traceability, auditability, and proper governance across the delivery lifecycle.

  • Support and enable development teams through guidance, training, and practical secure implementations.

Key Requirements:

  • Proven experience in DevSecOps, application security, or DevOps engineering.

  • Strong hands-on experience with CI/CD pipelines and secure delivery practices.

  • Experience with: GitHub Enterprise & GitHub Advanced Security, SonarQube configuration and governance, JFrog Artifactory and Xray.

  • Strong understanding of vulnerability management and secure artifact lifecycle.

  • Experience working directly with development teams in remediation efforts.

  • Knowledge of Git workflows, release management, and deployment governance.

  • Experience in regulated or large enterprise environments.

Nice to Have:

  • GitHub Advanced Security certification.

  • JFrog Artifactory / Xray training.

  • SonarQube administration.

  • Secure SDLC or OWASP-based training.

  • Cloud security certifications (Azure, Kubernetes, OpenShift).

  • DevSecOps certifications.

  • Security certifications such as CISSP, CSSLP, GIAC, or similar.

Other Details:

Note: Hands-on experience is valued more than certifications. This role requires strong collaboration and stakeholder engagement skills, with the ability to explain security risks clearly to diverse audiences. The ideal candidate will possess a pragmatic decision-making approach, an analytical mindset for risk prioritization, and strong documentation and communication skills. A proactive problem-solving attitude is essential, along with the ability to work within complex enterprise environments.