DevSecOps Security Engineer
Jobgether United States · $191K–$259K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
Architect and automate security workflows across CI/CD pipelines to ensure continuous compliance and vulnerability management. Partner with development teams to integrate security tooling and establish technical standards for secure cloud and container environments.
What they look for
Requirements
Requires 8+ years of experience in security engineering with hands-on expertise in DevSecOps pipelines and continuous ATO environments. Candidates must possess strong knowledge of AWS security services, Infrastructure as Code, and relevant NIST compliance frameworks.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Security Engineer based in the United States.
This is a senior-level security engineering role focused on building secure, automated cloud environments for mission-critical programs. You will own the security dimension of DevSecOps pipelines operating under a continuous Authorization to Operate (cATO) model. The role combines cloud security, compliance automation, vulnerability management, Infrastructure as Code, and CI/CD engineering. You’ll work closely with development and platform teams to embed security into automated workflows and continuously strengthen the organization’s security posture. You’ll also help mentor engineers and establish technical standards for secure AWS and container environments. This is a fully remote opportunity with limited travel and significant autonomy.
\n
Accountabilities:
- Architect and automate security workflows across CI/CD and compliance operations, reducing manual effort in vulnerability analysis, security inventory audits, and continuous monitoring.
- Integrate and monitor security tooling within automated pipelines, including scan ingestion, finding triage, evidence generation, and security reporting.
- Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapped to NIST 800-53 and NIST 800-171.
- Develop automated inventory reconciliation, delta analysis, and configuration drift detection across cloud accounts to maintain an accurate and auditable security posture.
- Establish and implement security standards for AWS Cloud and container environments, including logging, monitoring, audit correlation, and secure configuration practices.
- Support Infrastructure as Code security by developing and scanning Terraform and CloudFormation configurations for security and compliance requirements.
- Use Generative AI engineering tools such as Claude, Gemini, and Copilot to accelerate security automation, compliance reporting, and IaC scanning workflows.
- Partner with development and platform teams to resolve complex security, configuration, and performance challenges while promoting a strong DevSecOps culture.
- Mentor junior and mid-level engineers, share modern security practices, and help drive technical consensus across the team.
- Lead the creation and maintenance of technical documentation, processes, procedures, and engineering standards.
Requirements
- 8+ years of relevant experience, ideally supported by a bachelor's degree in a related discipline or an equivalent combination of education and professional experience.
- Direct, hands-on experience managing the security component of a DevSecOps pipeline within a continuous ATO (cATO) environment, including automated security gates, control evidence, and continuous authorization activities.
- Strong experience automating compliance workflows such as vulnerability scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.
- Hands-on knowledge of AWS security services, particularly AWS GovCloud tools such as Security Hub, Inspector, GuardDuty, and Config, as well as security platforms such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.
- Strong Infrastructure as Code security experience with Terraform and/or CloudFormation.
- Knowledge of NIST 800-53 and/or NIST 800-171, including control implementation and evidence mapping, with familiarity with FedRAMP and IAM.
- Strong scripting and automation capabilities using Python, Bash, or similar languages, together with Linux/Unix administration experience; RHEL or CentOS knowledge is advantageous.
- Active Security+ certification or an equivalent DoD 8570/8140 baseline certification.
- Experience with continuous monitoring automation, proactive compliance management, security audits, and large-scale evidence collection is highly desirable.
- Strong critical thinking and problem-solving skills, with the ability to develop practical solutions to complex security and compliance challenges.
- Excellent communication and collaboration skills, with the ability to explain technical security concepts clearly to both engineering teams and program stakeholders.
- Demonstrated ability or strong interest in mentoring engineers, influencing technical decisions, and serving as a technical anchor for a team.
- A continuous-learning mindset and commitment to engineering excellence, process improvement, and modern security practices.
- Experience with security product development, DevSecOps tooling, or security analytics platforms such as Databricks is a plus.
- U.S. citizenship is required, and candidates must be able to satisfy the applicable background/public-trust requirements.
Benefits
- Competitive compensation: Expected salary range of $191,250–$258,750, depending on experience, location, and contractual requirements.
- Fully remote work: Work from any U.S. location with a full-flex work model designed to support autonomy and work-life balance.
- Comprehensive healthcare: Medical plan options, including plans with Health Savings Accounts, plus dental and vision coverage.
- Retirement benefits: 401(k) plan with a competitive company match and pre-tax/post-tax contribution options.
- Paid time off: Vacation, sick and personal leave, holidays, and additional leave programs designed to support rest and personal needs.
- Family support: Paid parental and family leave, including up to 160 hours of paid family leave in a rolling 12-month period for eligible employees.
- Additional protection: Disability, life, accidental death and dismemberment, critical illness, personal accident, and other insurance options.
- Professional development: Paid advanced certifications, higher education opportunities, and dedicated technical development programs.
- Career mobility: Access to internal career support and opportunities to advance across a broad range of technology and mission-focused roles.
- Meaningful technical work: Exposure to complex, mission-critical cloud, cybersecurity, AI, and infrastructure technologies.
- Work schedule: 40 hours per week with less than 10% travel expected.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Lead Cybersecurity & Application Security Engineer
Weekday AI Hyderabad, Telangana, India
-
Cyber Security Engineer
Zensar Pune, Maharashtra, India
-
Italian Speaking Cybersecurity Customer Experts - Work In Athens, Greece
Mercier Consultancy Group Belgium
-
Cybersecurity Incident Commander - CIRT
Thrive Mabalacat, Pampanga, Philippines
-
Cybersecurity Expert
Consort Group Porto, Porto, Portugal · €43K–€52K/yr
-
Senior Consultant - Cybersecurity
UL Solutions Bangalore, Karnataka, India