Senior DevSecOps Engineer
Summary
Senior DevSecOps Engineer embeds security into CI/CD pipelines, performs SAST/DAST/SCA scans, and secures Azure deployments for a construction software company.
- 8+ years of experience in DevOps, DevSecOps, application security, security engineering, software engineering, platform engineering, or a related technical field.
- Strong hands-on experience with cloud services, preferably Azure, including application hosting, networking, storage, databases, identity, monitoring, access control, and security services.
- 5+ years of experience designing, developing, securing, and maintaining CI/CD pipelines using tools such as Azure DevOps, GitHub Actions, YAML, GitLab CI, Jenkins, or similar platforms.
- Strong experience embedding security tools and controls into CI/CD pipelines, including SAST, DAST, SCA, secrets scanning, dependency scanning, container scanning, and other automated security validation tools
- Deep understanding of secure SDLC, DevSecOps principles, secure software development practices, and modern application security concepts.
- Strong understanding of OWASP Top 10, API security, authentication, authorization, input validation, session management, encryption, secure error handling, secrets handling, and software supply chain risk.
- Experience identifying, triaging, prioritizing, and driving remediation of application security vulnerabilities across new and existing applications.
- Experience with vulnerability management practices, including security scanning tools, risk assessment, remediation tracking, exception handling, and risk acceptance workflows.
- Experience with secrets management solutions such as Azure Key Vault, HashiCorp Vault, or equivalent technologies
- Experience with scripting and automation using PowerShell, Azure CLI, Bash, Python, Go, or similar technologies.
- Ability to read, understand, and reason about application code in one or more modern programming languages such as C#, Java, JavaScript, TypeScript, Python, Go, or similar.
- Familiarity with security and compliance frameworks such as OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
- Strong troubleshooting, analytical, and problem-solving skills
- Excellent communication skills with the ability to explain security concepts, risks, and remediation guidance to both technical and non-technical stakeholders.
- Ability to work independently, manage multiple priorities, and collaborate effectively with cross-functional teams.
- Proactive attitude toward continuous improvement, automation, secure engineering practices, and developer enablement.
- Advanced cloud, DevOps, or security certifications such as AZ-400, Microsoft Certified: Azure Security Engineer, CISSP, CSSLP, CCSP, GWEB, GWAPT, or equivalent.
- Strong hands-on experience with Azure security services such as Azure Key Vault,
- Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID, Azure Monitor, Azure DevOps, and related Azure-native security capabilities.
- Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.
- Experience with threat modeling techniques and frameworks such as STRIDE, attack trees, abuse cases, or similar approaches.
- Strong understanding of microservices architecture and API security practices.
- Experience with OpenAPI/Swagger, OAuth2, OIDC, SAML, JWT, identity federation, and modern authentication and authorization patterns.
- Experience creating developer-facing security documentation, secure coding guidance, reusable pipeline templates, and security training materials.
- Experience building vulnerability dashboards, security KPIs, remediation workflows, and risk acceptance processes.
- Own or support application vulnerability management processes from detection through remediation, exception, or formal risk acceptance.
- Triage findings from security tools, penetration tests, dependency scans, cloud scans, code reviews, and internal assessments.
- Prioritize vulnerabilities based on severity, exploitability, business impact, application criticality, exposure, compensating controls, and compliance requirements.
- Partner with development teams to drive timely remediation of high-risk and recurring vulnerabilities.
- Track and communicate remediation progress, vulnerability trends, SLA performance, and application security posture to technical and non-technical stakeholders.
- Identify recurring vulnerability patterns and drive systemic improvements through automation, education, standards, and reusable security controls.
- Help define vulnerability remediation SLAs, exception processes, risk acceptance criteria, and security reporting standards.
- Design, implement, manage, and secure cloud-based application environments, preferably within Azure.
- Apply Azure security best practices using services such as Azure Key Vault, Microsoft Defender for Cloud, Azure Policy, Azure DevOps, identity and access controls, encryption, logging, and monitoring.
- Implement secure access patterns using RBAC, least privilege, managed identities, secure networking, encryption, and policy-based controls.
- Monitor and troubleshoot cloud services to help ensure secure, reliable, and high-performing application environments.
- Collaborate with stakeholders to design cloud solutions that meet current and future business, security, compliance, and operational needs.
- Support secure configuration and hardening of application hosting environments, databases, networking components, storage, and related platform services.
- Implement, manage, and continuously improve secrets management practices across development, test, staging, and production environments.
- Use solutions such as Azure Key Vault, HashiCorp Vault, or equivalent platforms to protect sensitive information.
- Partner with teams to eliminate hardcoded secrets, improve secret rotation, and enforce secure access patterns.
- Integrate secrets scanning and prevention controls into source code repositories and CI/CD pipelines.
- Define standards for secret storage, access, lifecycle management, auditability, and remediation of exposed secrets.
- Act as a trusted security and DevOps advisor to developers, architects, QA engineers, product teams, and engineering managers.
- Create practical secure coding guidance, reusable examples, internal documentation, reference patterns, and developer-friendly security standards.
- Conduct training, workshops, and coaching on topics such as OWASP Top 10, API security, secure coding, CI/CD security, secrets management, dependency risk, and cloud security.
- Mentor and guide junior DevOps engineers and help raise the overall security maturity of engineering teams.
- Promote a collaborative security culture where security is embedded into engineering practices rather than treated as a blocker.
- Influence teams through partnership, automation, practical guidance, and risk-based decision-making.
- Contribute to application security standards, secure coding policies, cloud security standards, pipeline requirements, and DevSecOps governance.
- Ensure applications, cloud environments, pipelines, and development workflows align with organizational security and compliance requirements.
- Support compliance with frameworks and standards such as OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
- Help define and enforce security policies related to application security, cloud security, vulnerability remediation, secrets management, and CI/CD practices.
- Continuously evaluate the effectiveness of security tooling, automation, standards, and processes.
- Occasional travel to our office may be requested up to once or twice a year
- Flexibility to work Remotely
- Medical, dental, and vision coverage with company-paid and employee-paid options
- Paid holidays, sick days, and personal time off
- Employee Resource Groups (ERGs) that foster connection and inclusion
- On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
- Dog-friendly campus and WiFi-accessible courtyards
- 401(k) with a 5% company match
- Coverage for employee professional development and wellness
- And more!
Skills
- Acceptance Criteria
- API
- Api Security
- Authentication
- Automation
- Azure
- Azure DevOps
- Bash
- Burp Suite
- CI/CD
- Cissp
- CLI
- Cloud
- Cloud Security
- C#
- DAST
- DevOps
- DevSecOps
- Entra ID
- Gdpr
- GitHub
- GitHub Actions
- GitLab
- ISO 27001
- Java
- JavaScript
- Jenkins
- JWT
- Microservices
- Networking
- Nist
- OAuth
- OpenAPI
- OpenID
- OWASP
- Pci Dss
- PowerShell
- Python
- RBAC
- Risk Assessment
- SAML
- SAST
- SDLC
- Secrets Management
- Secure Coding
- SOC 2
- SonarQube
- Swagger
- TypeScript
- Vault
- Wi-Fi
- YAML