
Senior DevSecOps Engineer
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in New York.
• Establish, uphold, and enforce best practices for DevSecOps throughout the software development lifecycle (SDLC).
• Assess, integrate, and sustain DevSecOps tools and technologies to enhance automated CI/CD pipelines.
• Guide Agile teams by facilitating daily stand-ups, sprint planning sessions, reviews, retrospectives, and other Agile ceremonies.
• Ensure that security remains a top priority during the design, implementation, and delivery of all development projects.
• Collaborate with various teams, including software developers, security engineers, and IT operations, to guarantee seamless integration of security practices within workflows.
• Promote team collaboration and communication, cultivating a culture of innovation, accountability, and continuous improvement.
• Offer mentorship to development team members regarding DevSecOps practices, tools, and Agile methodologies.
• Create reports and provide updates to leadership on project status, risks, and the security measures that have been implemented.
• Bachelor's degree with nine (9) years or more of experience; Master's degree with seven (7) years or more of experience; or a Ph.D. or JD.
• An active Secret-level security clearance and Security+ certification are required.
• A minimum of 8 years of experience in software development, DevOps, or IT operations.
• At least 3 years of leadership experience in an Agile environment, demonstrating a successful history of leading cross-functional teams.
• Strong knowledge of Agile methodologies such as Scrum, Kanban, and SAFe.
• Expertise in creating and managing CI/CD pipelines using tools like Jenkins, GitLab CI/CD, or similar.
• Practical experience with infrastructure as code (IaC) tools such as Terraform.
• Significant hands-on experience with Kubernetes, container technologies (e.g., Docker), and managing workloads on these platforms.
• A comprehensive understanding of CI/CD pipeline stages (e.g., build, test, security scan, deployment) and best practices for automation.
• Knowledge and experience working in secure environments, specifically Impact Level 6 (IL6) or similarly controlled environments, with a solid grasp of DoD or equivalent compliance frameworks.
• Proficiency in tools for security automation.
• Familiarity with image scanning tools (e.g., Anchore).
• Experience with static code analysis tools (e.g., SonarQube).
• Knowledge of software signing tools (e.g., Cosign) for image and binary integrity verification.
• Practical experience with container hardening and vulnerability remediation.
• Build and manage Kubernetes clusters in development, testing, and production environments.
• Proficiency with cloud platforms such as AWS, and container orchestration tools like Kubernetes or Docker.
• In-depth understanding of secure software development practices and frameworks, including threat modeling, security automation, and vulnerability management.
• Experience with version control systems such as Git and artifact repositories like Artifactory or Nexus, with four (4) years or more of experience.
• Flexible work arrangements
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.