- Hands-on experience in DevSecOps, Application Security, or Security-focused DevOps Engineering
- Experience implementing and supporting Secure Software Development Lifecycle (Secure SDLC) practices
- Strong knowledge of CI/CD pipeline security and integrating security controls into development workflows
- Experience with Azure DevOps and automated pipeline development
- Experience building and implementing security automation, including vulnerability scanning and security testing
- Knowledge of application security principles, including secure coding practices, secrets management, encryption, authentication, and secure integrations
- Experience with vulnerability management and remediation processes
- Understanding of modern software development practices and application architectures
- Experience partnering with application developers, DevOps engineers, and security teams
- Ability to establish security standards, guardrails, and governance processes that are practical and scalable
- Experience implementing shift-left security strategies that move security validation earlier in the development lifecycle
- Strong understanding of security scanning tools and integrating them into automated development pipelines
- Excellent communication skills with the ability to influence engineering teams and drive security best practices
Desired Skills:
- Experience with Application Security Engineering programs and maturing security practices within an organization
- Background in software development with hands-on coding experience
- Experience in Security Operations (SecOps)
- Experience with GitHub, including GitHub Secret Protection
- Experience with Snyk or similar application security and code scanning platforms
- Knowledge of cloud security within Microsoft Azure environments
- Experience in AWS environments with the ability to transition to Azure-based ecosystems
- Experience automating remediation workflows and security exception management
- Familiarity with security frameworks and industry best practices (OWASP, NIST, secure development standards)
- Experience defining application security policies, standards, and governance models
- Knowledge of APIs, certificates, identity and access management, and service account security
- Experience leveraging AI-powered developer tools (Claude, OpenAI, Copilot, etc.) for code review, vulnerability detection, and secure development practices
- Experience helping organizations build and mature application security programs from the ground up
- Experience balancing security requirements with development velocity and operational efficiency
Description of Role/Responsibilities:
Our client is seeking a DevSecOps / Application Security Engineer to help build and mature application security practices across a growing development organization. This role will focus on integrating security into the software development lifecycle, implementing automated security testing within CI/CD pipelines, and establishing practical security standards that support, rather than hinder, development teams. The ideal candidate will bring a blend of application security, DevOps, and software development experience, with hands-on expertise in Azure DevOps, secure SDLC practices, vulnerability management, and security automation. This is an opportunity to play a key role in shaping a shift-left security strategy and building scalable security capabilities from the ground up.
Beacon Hill is an equal opportunity employer and individuals with disabilities and/or protected veterans are encouraged to apply.
California residents: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Completion of this form is voluntary and will not affect your opportunity for employment, or the terms or conditions of your employment. This form will be used for reporting purposes only and will be kept separate from all other records.
Benefits Information:
Beacon Hill offers a robust benefit package including, but not limited to, medical, dental, vision, and federal and state leave programs as required by applicable agency regulations to those that meet eligibility. Upon successfully being hired, details will be provided related to our benefit offerings.
#J-18808-Ljbffr