Education: Bachelor's degree or related field
Experience: 7+ years
"I can succeed as a Senior DevSecOps Engineer at Capital Group."
As a Senior DevSecOps Engineer within the Application Security team, you'll support, secure, manage and deploy solutions that secure the software delivery lifecycle for enterprise applications. This is a highly technical role, so you will need a strong understanding of automation, CI/CD infrastructure, software development, and cloud services.
Knowledge of information security and application security tools is highly desirable.
The DevSecOps engineer supports the security of continuous integration and continuous deployment (CI/CD) initiatives and is an integrated team member working with software developers, system engineers, cybersecurity engineers and systems administrators. The role is security-focused and helps CI/CD pipelines deliver secure software in a scalable manner while showing developer empathy and engineering excellence such as obsession with security tool output quality, false positive removal, using data / metrics to improve tools that integrate into the CI/CD pipeline.
This role is hybrid (in-office 3 days/week) in New York NY.
- Simplify automation that applies security inter-workings with CI/CD pipelines. - Work to consistently learn and share advanced skills and practices that promote team excellence. - Build relationships with developers, stakeholders and scrum master's to incorporate security principles into engineering design and deployments. - Supervise testing and validation in application security controls across projects. - Oversee implementation of defensive practices and countermeasures across infrastructure and applications. - Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads. - Serve as a point of contact for security-based escalations and remain tightly involved through resolution. - Build services and tools to enable developers and engineers to easily use security components produced by Application Security team members. - Support the ability to "shift left" and incorporate security early on and throughout the development lifecycle. - Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging. - Leverage Vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors as well as workarounds. - Join forces and provision security principles in architecture, infrastructure and code. - Regularly research and learn new tactics, techniques and procedures (TTPs) in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary through the CI/CD pipeline. - Enrich DevOps architecture with security standards and best practices. - Partner with teams to define key performance indicators (KPIs) and metrics across business units.
- Bachelor's degree in Computer Science or related field and/or at least 7+ years' experience in information technology, information security administration or security operations. - Experience with agile workflows, including Scrum and Kanban. - Hands-on experience of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes). - Understanding DevSecOps tooling, including Terraform, Ansible, and CI/CD Pipelines. - Experience with operations and security across Amazon Web Services (AWS). - Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface while performing rapid, continuous implementation. - Proficient in designing, building, and deploying complex engineering solutions - Expert Programming knowledge in Python.
Other Languages a bonus. - Interested in Agentic software development, including developing agentic Skills to accelerate feature requests and improve the quality of solutions delivered. - Excellence in communicating business risk and remediation requirements from assessments.
Charlotte Base Salary Range: $136,749-$218,798 Southern California Base Salary Range: $159,354-$254,966
Search Senior DevSecOps Engineer jobs near Irvine → Browse all live jobs
This posting was published by Capital Group on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.