DevSecOps Engineer

ContractOn-siteMidLimited info disclosed
37 views0 applications

Description

Overview The DevSecOps Engineer will play a critical role in securing our cloud platforms, applications, and supporting infrastructure by continuously identifying, prioritizing, and remediating security vulnerabilities. Reporting into the Security Team Lead, this position requires a hands-on technical professional who can directly implement security remediations and configuration changes within cloud and application environments, rather than solely coordinating tasks with other teams. In this role, you will partner closely with application, Operations, and Platform Architecture teams to design, implement, and maintain robust security controls across AWS GovCloud and AWS Commercial environments. You will apply deep technical expertise and industry best practices to address emerging cybersecurity threats, develop innovative security solutions, and ensure our platforms remain compliant and resilient. The DevSecOps Engineer will manage and execute all aspects of vulnerability management, including scanning, analysis, and remediation. Using tools such as Nessus and Fortify, you will investigate security findings, perform corrective actions directly in cloud and application ecosystems, and drive issues through to full resolution. This role is central to strengthening the security posture of the organization and embedding security throughout the development and operational lifecycle. Education Requirements A Bachelor’s Degree in Computer Science, Engineering, Math, or a related field is required. Candidates with equivalent professional experience and certifications may also be considered. Clearance Requirements This role requires an active Public Trust clearance, or the ability to obtain and maintain one. U.S. citizenship is necessary for eligibility. Work Arrangement This is a remote position. Responsibilities Conduct continuous vulnerability assessments using industry-standard tools (SAST, DAST, SCA, container scanning, IaC scanning). Collaborate with engineering and infrastructure teams to remediate vulnerabilities and implement secure-by-default configurations. Establish and enforce secure coding guidelines and hardening standards. Support incident response activities, including root-cause analysis and containment. Partner with SRE and Platform teams to architect secure infrastructure, ensuring adherence to compliance frameworks (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain documentation related to security controls, processes, and vulnerability management workflows. Required Qualifications Experience with vulnerability scanning tools (e.g., Snyk, Tenable, Qualys, SonarQube, Trivy). 5+ years AWS cloud platforms and their native security service 5+ years Linux administration and automation Experience automating workflows using scripting languages such as Python, Bash, or PowerShell. Experience and working knowledge of NIST 800-53 security and privacy controls Knowledge of network security concepts, encryption, secret management, and identity frameworks. Desired Skills Certifications such as AWS Security Specialty, GIAC, CEH, or CSSLP. Experience with IaC security scanning tools like Checkov, tfsec, or OPA/Conftest. Familiarity with SIEM/log analytics platforms such as Splunk, ELK, or Sentinel. Experience with secure architecture design, threat modeling, and incident response. Knowledge of AWS GovCloud environment specifics and compliance requirements. Why Apply Join a forward-thinking organization committed to security excellence and innovation. This role offers the opportunity to work on impactful projects across regulated and sensitive environments, leveraging cutting-edge cloud security practices. Collaborate with talented teams dedicated to embedding security into every aspect of development and operations. If you’re passionate about cybersecurity, automation, and cloud architecture, apply now to make a meaningful difference.