DevSecOps Engineer
Core
Embed application security controls into CI/CD pipelines, investigate and remediate security findings, and conduct threat modeling to secure applications and APIs.
Role type
DevSecOps Engineer (Application Security)
Builds
Secure CI/CD pipelines, automated security controls, and developer tooling for application and API platforms
Domain
Software Engineering / Application Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Application security (SDLC), CI/CD integrations, code review, threat modeling, OWASP Top 10, SAMM, ASVS, FIRST principles, programming (Java, C++, Python, JavaScript), LLMs and agentic coding platforms
Preferred skills
Mentoring security teams, raising security awareness, familiarity with monolithic and microservice architectures
Technologies
CI/CD pipelines, LLMs, AI, agentic coding platforms (Github Co-pilot, Gemini, Claude Code), Java, C++, Python, JavaScript
Responsibilities
Embed security controls in CI/CD pipelines, investigate and remediate security findings, conduct targeted code reviews, implement security automations, perform threat modeling, participate in defining security best practices
Seniority
Mid-level to Senior, hands-on IC