Create Alert
Email me similar jobs

DevSecOps Engineer — Tooling Implementation & Integration

Position: DevSecOps Engineer Tooling Implementation & Integration
Type :- Remote


Position Overview

This is a hands-on build role at the center of a DevSecOps program. The engineer will deploy and operate DefectDojo Pro inside a FedRAMP-authorized AWS environment as the single source of truth for vulnerability findings.

The role involves integrating seven detection sources:

  • Trivy

  • Semgrep

  • Qualys

  • Tenable

  • AWS Inspector

  • CrowdStrike

  • Dependabot

while retiring a legacy multi-hop pipeline (GHAS Splunk Email Jira).

The engineer will own all integration code, CI/CD wiring, and automation that moves findings from detection through evaluation to ticketing and reporting.

This position requires deep AWS expertise, strong Python development skills, Kubernetes operational fluency, and experience with security tooling in regulated environments.


Key Responsibilities
  • Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS environment, including:

    • IdP/SSO integration

    • Security hardening

    • Boundary-compliant configuration

  • Build and maintain scanner integrations:

    • API connectors

    • Webhook pipelines

    • CI jobs feeding findings from all detection sources into the aggregation platform

  • Integrate container scanning into:

    • GitHub CI pipelines

    • Amazon ECR registry workflows (Trivy)

    • Runtime container scanning for EKS/ECS workloads

  • Build a runtime reconciliation loop matching scanned images to deployed workloads.

  • Implement KEV/EPSS enrichment and internet-reachability tagging.

  • Build FedRAMP JSON export services (VDT/AVI/MRH schemas).

  • Implement link-only bidirectional Jira synchronization while keeping vulnerability metadata inside the ATO boundary.

  • Configure PagerDuty alerting for emergency-patch scenarios (12-hour to 2-day SLAs).

  • Decommission the legacy GHAS Splunk Email findings chain and migrate active workflows without losing audit continuity.

  • Write infrastructure-as-code, deployment automation, and operational documentation for all components.


Required Skills
  • 6+ years of experience in DevOps, DevSecOps, or Platform Engineering with significant security tooling exposure.

  • Strong AWS experience with:

    • Amazon EKS/ECS

    • Amazon ECR

    • Amazon EC2

    • AWS Lambda

    • IAM

    • VPC Networking

  • Strong Python (or similar language) for API integrations and data pipelines.

  • Experience with:

    • REST APIs

    • Webhooks

    • JSON schema development

  • Hands-on experience with GitHub Actions CI/CD.

  • Experience integrating security scanning into build and container registry workflows.

  • Kubernetes operational expertise including:

    • Deployments

    • Admission controllers/concepts

    • Workload visibility

    • Runtime security tooling

  • Infrastructure-as-Code experience (Terraform preferred).


Preferred (Bonus) Skills
  • Experience with DefectDojo (especially DefectDojo Pro) or similar ASPM/vulnerability management platforms.

  • Experience with:

    • Trivy

    • Grype

    • AWS Inspector

    • CrowdStrike Falcon Cloud Security

    • Semgrep

    • Qualys APIs

    • Tenable APIs

  • Experience operating security tooling within a FedRAMP or other regulated environment.

  • Understanding of:

    • ATO scope

    • Hardening baselines

    • Change control

  • Familiarity with SBOM formats (CycloneDX).

  • Familiarity with VEX, KEV, and EPSS data sources.


DevSecOps Engineer — Tooling Implementation & Integration

Apply Now
Back to search page