
DevSecOps Engineer
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in Ohio.
• Integrate security measures into the software development lifecycle.
• Create practical secure development standards in collaboration with engineering teams.
• Assist developers in identifying and addressing application security vulnerabilities.
• Offer technical guidance on secure coding practices and prevalent vulnerability classes.
• Facilitate security assessments for applications, services, APIs, and significant architectural modifications.
• Design and implement automated security testing within CI/CD pipelines.
• Execute SAST, SCA, secret scanning, container image scanning, IaC scanning, and dependency vulnerability detection.
• Develop security gates for build and deployment processes.
• Correlate and eliminate duplicate vulnerability signals across Dependabot, Vanta, and Tenable.
• Assess applications and APIs for potential security weaknesses.
• Establish secure API authentication and authorization patterns.
• Assist in threat modeling and addressing application security findings.
• Review Terraform, CloudFormation, Kubernetes manifests, and infrastructure configurations for security risks.
• Create automated controls, secure infrastructure patterns, guardrails, and security automation.
• Support container image security, workload configuration, secrets management, and runtime security.
• Aid in the planned transition from Heroku to Render.com.
• Design synthetic or de-identified data seeding for DAST in staging without revealing PHI.
• Engage in architecture and design reviews.
• Collaborate with Cloud Security, Security Operations, and engineering teams to enhance security visibility and resolve issues.
• Monitor security findings, remediation timelines, vulnerability trends, security coverage, and secure development adoption.
• Replace manual reviews with automated preventative controls.
• Over 3 years of experience in DevOps, DevSecOps, application security, platform engineering, software engineering, or security engineering.
• Familiarity with modern CI/CD systems and software delivery methodologies.
• Experience with contemporary application hosting platforms.
• Proficient in application security, API security, GitHub Advanced Security/CodeQL, dependency and vulnerability alert triage, CI/CD pipelines, Infrastructure-as-Code, secrets management, and software supply chain security.
• Skilled in scripting or programming with Python, Go, JavaScript, PowerShell, or Bash.
• Experience with Git-based development workflows and direct collaboration with developers and engineering teams.
• Proven application of the skills and qualifications mentioned.
• Capability to work at a computer for prolonged periods.
• Strong communication skills, both verbal and written, with engineering and security stakeholders.
• Ability to manage and access sensitive security and system data in accordance with organizational data handling protocols.
• Willingness to address critical security or deployment issues outside regular working hours when necessary.
• Education is not specified as a requirement; hands-on experience will be assessed.
• Licensure or certification is not mandatory.
• Preferred: Experience with Terraform, Kubernetes, or container orchestration.
• Preferred: Familiarity with Rails security tools such as Brakeman, bundler-audit, or Dependabot.
• Preferred: Implementation experience with SAST, SCA, secrets scanning, or IaC security tools.
• Preferred: Knowledge of OWASP Top 10, cloud-native security services, and threat modeling.
• Preferred: Experience in identity, authentication, authorization, secrets management, and regulated environments.
• Ruby experience is a significant advantage.
• Full-time employment.
• Standard business hours.
• Flexible scheduling for security-critical deployment reviews or urgent remediation timelines.
• Equal employment opportunity and an inclusive work environment.
Horizon3.ai
CLOUD MANTA GmbH
Stefanini LATAM
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.