DevSecOps Engineer
The job description
Tech stack. GitHub Actions or Jenkins, SAST/DAST/SCA integrated in CI, container scanning (Trivy, Grype), Terraform security scanning, Cosign and SLSA, Python or Go, SBOM tooling
About the role
You will wire security directly into the software delivery pipeline of a technology company so that every commit, build, and deploy is checked automatically without slowing developers down. The team treats the CI/CD system as both a product requiring its own security and a platform for enforcing security everywhere else. You will build scanner integrations, secure the build infrastructure, and make the paved road the safe road. This role matters because developers only follow secure practices that fit naturally into their workflow, and you build the guardrails that keep shipping velocity and safety advancing together instead of trading against each other.
What you will achieve
- Embed SAST, SCA, and secret scanning into every CI pipeline, delivering actionable results to developers in under 10 minutes from commit.
- Block deployments of container images carrying critical vulnerabilities, driving vulnerable deploys to zero across all services.
- Secure the CI/CD platform itself: hardened ephemeral runners, OIDC-based cloud authentication, and signed build provenance for every artifact produced.
- Reduce security finding noise 50 percent by tuning scanners to the actual codebase and suppressing unactionable rule categories with documented rationale.
- Ship pipeline security templates and starter workflows that new repositories adopt with a single configuration change.
What you will bring
Must-haves
- 2 to 5 years in DevOps, platform engineering, or security engineering with deep, hands-on CI/CD experience.
- Practical skill with GitHub Actions, Jenkins, GitLab CI, or an equivalent pipeline system operated at organizational scale.
- Experience integrating SAST, DAST, SCA, and container scanners into fully automated delivery pipelines.
- Infrastructure as code knowledge with Terraform, including policy-as-code scanning of planned changes.
- Understanding of software supply chain security: SBOM generation, artifact signing, and build provenance.
- Empathy for developer workflows; you build guardrails that guide engineers rather than gates that block them.
- Debugging tenacity for flaky pipelines, where the fix is often in the integration rather than the tool.
Nice-to-haves
- Experience implementing the SLSA framework or Cosign-based artifact signing in production.
- Familiarity with Kyverno, OPA, or Kubernetes admission control for deployment policy enforcement.
- Contributions to pipeline security tooling or shared organizational templates.
- Knowledge of secrets detection tuning to minimize developer friction.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta