We’re seeking a Senior DevSecOps Engineer to lead and scale secure development and delivery practices within a collaborative R&D environment. This role blends technical leadership, hands‑on engineering, and cross‑functional partnership to drive secure, reliable, and efficient software and firmware delivery.
What You’ll Do
- Lead a DevSecOps function supporting secure cloud environments and CI/CD pipelines
- Embed security into the development lifecycle (SAST, DAST, SCA, SBOM, threat modeling)
- Partner with engineering teams to improve workflows, testing, and release strategies
- Automate infrastructure using IaC and configuration management tools
- Oversee vulnerability management, incident response, and remediation efforts
- Implement monitoring/logging to ensure performance and reliability of pipelines
- Manage binary repositories and support software supply chain security
- Drive continuous improvement through metrics, tooling, and process optimization
- Mentor team members and help build a strong DevSecOps culture
- Evaluate and implement new tools; collaborate with vendors and internal stakeholders
What You Bring
- BS in Computer Science, Engineering, or related field
- ~5+ years in engineering, including 2+ years in DevSecOps/security-focused DevOps
- Technical leadership experience
- Strong background in CI/CD, cloud platforms (e.g., AWS), and containerization (Docker)
- Experience integrating security tools (SAST, DAST, SCA, SBOM) into pipelines
- Proficiency in scripting (Python, Bash, or PowerShell)
- Experience with IaC, build tools, and monitoring/logging solutions
- Solid understanding of cybersecurity principles and secure development practices
- Strong problem-solving, communication, and collaboration skills
Nice to Have
- Experience with Agile/DevOps/DevSecOps environments
- Familiarity with Git-based toolchains and pipeline automation
- Knowledge of software supply chain security, SBOM standards, and compliance frameworks
- Cybersecurity certifications (e.g., CISSP, Security+, AWS Security)
- Experience with vulnerability management in regulated environments
#J-18808-Ljbffr