Senior DevSecOps Engineer
Job Title: Senior DevSecOps Engineer
Location: Boston, MA
Employment Type: Full-Time
Experience: 10+ Years (Overall IT), 3-7+ Years in Security/DevSecOps
Job Summary
We are seeking a Senior DevSecOps / Application Security Engineer to embed security across the software development lifecycle (SDLC) and cloud-native environments . This role will focus on integrating security into CI/CD pipelines , cloud infrastructure , containers/Kubernetes , and automation frameworks , ensuring scalable, compliant, and secure delivery of applications.
The ideal candidate has strong hands-on experience in application security, cloud security, DevSecOps practices, and security automation , and thrives in a highly collaborative engineering environment.
Key Responsibilities
Secure SDLC & Application Security
-
Embed security controls across all phases of the SDLC .
-
Perform threat modeling, secure code reviews, and risk assessments .
-
Implement and manage SAST, DAST, and SCA tools , and guide development teams on remediation.
-
Enforce secure coding standards and promote a security-first engineering culture.
CI/CD Pipeline Security
-
Design, build, and maintain secure CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, and Azure DevOps .
-
Automate security scanning, policy enforcement, and compliance checks within pipelines.
-
Integrate secrets management and environment hardening into CI/CD workflows.
Cloud & Infrastructure Security
-
Review and secure Infrastructure as Code (IaC) using Terraform, CloudFormation, ARM, or Pulumi .
-
Enforce cloud security best practices across AWS, Azure, and/or GCP .
-
Deploy and manage cloud-native security services such as AWS GuardDuty, Azure Defender, and GCP Security Command Center (SCC) .
Container & Kubernetes Security
-
Build and manage secure container images and implement vulnerability scanning using tools like Trivy, Aqua, Clair, or Prisma Cloud .
-
Enforce Kubernetes security controls , including RBAC, network policies, and pod security standards.
-
Monitor Kubernetes clusters and remediate security vulnerabilities.
Security Automation & Tooling
-
Develop automation scripts and workflows using Python, Bash, Go, or PowerShell .
-
Integrate SIEM/SOAR platforms with CI/CD and cloud environments.
-
Automate vulnerability management and remediation processes.
Compliance & Governance
-
Support compliance initiatives aligned with NIST, ISO 27001, SOC 2, PCI-DSS , and internal security policies.
-
Implement policy-as-code using tools such as OPA, Conftest, and cloud policy engines .
-
Produce audit-ready documentation, metrics, and security reports.
Monitoring & Incident Response
-
Integrate security telemetry into CI/CD pipelines and cloud platforms.
-
Respond to and triage security incidents related to applications, pipelines, and cloud workloads.
-
Conduct root-cause analysis and implement preventive security controls.
Required Skills & Qualifications
-
10+ years of overall IT experience, with 3-7+ years in Cybersecurity, DevSecOps, or Cloud Security roles
-
Strong scripting and programming skills ( Python, Go, Bash, or PowerShell )
-
Hands-on experience securing CI/CD pipelines
-
Deep understanding of OWASP Top 10, CWE, CVEs
-
Strong experience with container and Kubernetes security
-
Knowledge of microservices, APIs, and distributed systems
-
Solid understanding of cloud networking, IAM, secrets management, and encryption
-
Experience with AWS, Azure, or GCP security services
Nice-to-Have Skills
-
Experience with SIEM/SOAR platforms
-
Exposure to multi-cloud security environments
-
Prior experience supporting regulated or compliance-heavy environments
Soft Skills
-
Strong collaboration and communication skills
-
Ability to influence engineering teams on security best practices
-
Proactive mindset with strong problem-solving abilities
Recommended Jobs
Wealth Management Banker
Job Description What is the opportunity? Wealth Management Banker - Support RBC USWM field and management in growing the cash and lending business through serving as the key contact for financ…
🚨Physician Assistant (PA)- High Paying Locum Tenens Emergency Medicine🚨
&##128205; Location: Springfield, Massachusetts &##128197; Start Date: ASAP – Coverage Starting in June &##129658; Position Type: 1099 Locum Tenens &##128269; Position Overview: We’re see…
Senior Product Manager, Partner Experience
Xometry (NASDAQ: XMTR) powers the industries of today and tomorrow by connecting the people with big ideas to the manufacturers who can bring them to life. Xometry’s digital marketplace gives manufac…
Hardware Engineer
Job Description This position is for an experienced principal hardware engineer to provide development engineering support for Oracle server platforms and electrical testing of next generation …
Radiologist - Remote and 50K Sign On
?Independent group seeking a Remote Radiologist to provide Teleradiology services. Growing Private group with a 100% remote role! Contact: Raymond Stiles(843-574-8233)[email protected] …
Supervisor
Interested in guiding staff as they help people with disabilities and older adults to maintain quality of life? Join Springwell as a SCO/One Care Supervisor. The compensation for this role is $65,0…
Protective Services Supervisor - Signing Bonus
Job Description Job Description Job Category : Exempt [X ] Non-exempt [ ] Updated: Jan 2026 LifePath JOB POSTING TITLE: PROTECTIVE SERVICES SUPERVISOR [$1500 SIGN ON BONUS] GE…
Outside Sales Representative
Overview: Do you have a passion for making a difference for small business in your community? Are you looking for a career with unlimited income potential ? Is company culture important to you? …
Chess Instructor | Winter
Area: Rockland, MA Do you love chess? Do you enjoy working with kids? Chess Wizards is seeking enthusiastic, reliable instructors to join our after-school enrichment program! If you can make…