Senior DevSecOps Engineer @Heavy Construction Systems Specialists, LLC
Devops
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Senior DevSecOps Engineer @Heavy Construction Systems Specialists, LLC

1mth ago - Heavy Construction Systems Specialists, LLC is hiring a remote Senior DevSecOps Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

As a Senior DevOps Engineer specializing in DevSecOps and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including:

  • SAST
  • DAST
  • SCA
  • Secrets scanning
  • API security
  • Secure coding practices
  • Threat modeling
  • Vulnerability triage
  • Risk-based remediation
  • Security integration within CI/CD pipelines

The successful candidate will serve as a technical leader and trusted advisor who helps development teams deliver secure software at scale.

Qualifications

  • Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices.
  • Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others.
  • Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
  • In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development.
  • Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
  • Familiarity with security and compliance frameworks such as OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.

Requirements

  • Security Certifications: Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
  • Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
  • Strong understanding of microservices architecture and API security practices.
  • Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.

Role Responsibilities

  • Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
  • Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling.
  • Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more.
  • Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments.
  • Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments.
  • Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies.
  • Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments.
  • Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure.
  • Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools.

Travel Requirements

  • Occasional travel to our office may be requested up to once or twice a year.

Benefits

  • Flexibility to work Remotely
  • Medical, dental, and vision coverage with company-paid and employee-paid options
  • Paid holidays, sick days, and personal time off
  • Employee Resource Groups (ERGs) that foster connection and inclusion
  • On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
  • Dog-friendly campus and WiFi-accessible courtyards
  • 401(k) with a 5% company match
  • Coverage for employee professional development and wellness
  • And more!
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior DevSecOps Engineer @Heavy Construction Systems Specialists, LLC
Devops
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,920+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later