DevSecOps Engineer
As a DevSecOps Engineer, this professional will lead the integration of security into software development, continuous integration, continuous delivery (CI/CD), and cloud operations.
They will design and maintain secure CI/CD pipelines, automate security controls ("shifting security left"), manage cloud infrastructure, and ensure system scalability, high availability, and compliance.
The DevSecOps Engineer will also mentor team members on secure coding and infrastructure practices, leading cross-functional alignment between engineering, security, and operations teams.
Responsibilities:
- Lead the design, implementation, and maintenance of secure CI/CD pipelines, automating security scanning (SAST, DAST, SCA) alongside build, test, and deployment processes.
- Architect, manage, and harden scalable, highly available, and compliant cloud infrastructure.
- Implement and manage container security and orchestration technologies (e.g., Docker, Kubernetes) to optimize deployment and runtime safety.
- Stay up to date with emerging industry trends, security standards, and best practices in DevSecOps, cloud security, and vulnerability management.
- Provide guidance, training, and mentorship to team members on secure development lifecycle (SDLC) practices and Infrastructure as Code (IaC) security.
Requirements:
- Bachelor’s degree in Computer Science, Cyber Security, Engineering, related field, or relevant equivalent experience.
- 7+ years of experience in DevOps, DevSecOps, or Infrastructure Engineering with a strong security focus.
- Extensive experience integrating automated security gates into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins).
- Expertise in scripting and automation languages (e.g., Python, Bash, Go).
- Expertise with major cloud platforms (AWS, Azure, or GCP) and cloud security tooling (e.g., IAM, Security Hub, GuardDuty).
- In-depth knowledge of infrastructure as code tools.
- Excellent communication, incident handling, and cross-team collaboration skills.
Shift-Left Security Integration:
- Implement automated static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and secrets detection into existing build pipelines to catch vulnerabilities early.
- Secrets & Identity Management: Design, deploy, and manage enterprise secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) and enforce strict Least Privilege Access via IAM policies and Zero Trust architecture.
- Vulnerability Management & Remediation: Establish continuous vulnerability assessment processes across cloud instances, container registries, and software dependencies; collaborate with development teams to triage and patch vulnerabilities based on risk priority.
- Security Monitoring & Incident Response Automation: Partner with Security Operations (SecOps) to build automated threat monitoring, anomaly detection, audit logging, and response capabilities across...
- Rate: Not Specified
- Location: Lansing, US-MI
- Type: Permanent
- Industry: Engineering
- Recruiter: STC Health LLC
- Contact: Not Specified
- Email: to view click here
- Reference: R0046892
- Posted: 2026-10-07 10:17:47 -
- View all Jobs from STC Health LLC
More Jobs from STC Health LLC
- ConvergeProsperity - Product Forward Deployed Engineer, Insurance Growth Suite (Manager) - Innovatio
- Organization Workforce & Change Consultant
- Patient Care Coordinator – Administrative
- Assistant General Manager
- Parts Counter Sales
- Armed Driver Guard
- Armed Non Driving Vault Teller PM
- Operations Supervisor
- Armed Driver Guard
- Armed Driver Guard
- Armed Driver Guard
- Part Time Cash Management Services Teller
- Coin Teller
- 2nd Shift Vault Teller- Colo Springs
- Warehouse/Driver Associate
- Payroll Analyst
- Licensed Practical Nurse (LPN) - Float Pool
- Athletic Trainer, Certified - Per Diem (PRN) Float Pool
- Certified Medical Assistant/CMA - Per Diem (PRN) Float Pool
- Operator