Senior DevSecOps Engineer
Summary
Senior DevSecOps Engineer embeds security into CI/CD pipelines, performs SAST/DAST/SCA scans, and secures Azure deployments for a construction software company.
- Experience: Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices.
- Cloud Expertise: Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others.
- Security Tools & Practices: Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
- Secure Development Lifecycle: In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development.
- Vulnerability Management: Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
- Compliance Knowledge: Familiarity with security and compliance frameworks such as OWASP, NIST, CIS,
- SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
- Collaboration & Communication: Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.
- Security Certifications: Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
- Threat Modeling: Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
- Experience with Microservices & APIs: Strong understanding of microservices architecture and API security practices.
- Security Tools: Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.
- DevSecOps Integration: Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
- Application Security Expertise: Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling.
- Azure Cloud Security: Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more.
- Static and Dynamic Application Security Testing: Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments.
- Secrets Management: Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments.
- Software Composition Analysis (SCA): Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies.
- Automation and Infrastructure as Code: Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments.
- Security Policies & Compliance: Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure.
- Collaboration & Mentorship: Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools.
- Occasional travel to our office may be requested up to once or twice a year
- Flexibility to work Remotely
- Medical, dental, and vision coverage with company-paid and employee-paid options
- Paid holidays, sick days, and personal time off
- Employee Resource Groups (ERGs) that foster connection and inclusion
- On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
- Dog-friendly campus and WiFi-accessible courtyards
- 401(k) with a 5% company match
- Coverage for employee professional development and wellness
- And more!