DevSecOps Engineer - Information Security
Core
Develops, recommends, and implements enterprise information security policies, technical standards, and DevSecOps capabilities to support secure-by-design practices across CI/CD pipelines, cloud-native platforms, and AI-assisted coding environments.
Role type
Senior IC DevSecOps Engineer (Information Security)
Builds
Secure CI/CD pipelines, cloud-native security controls, and AI-enabled application security guardrails
Domain
Healthcare / Information Security & Cloud Infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
DevSecOps, Application Security (SAST, DAST, SCA), Cloud Security (AWS, Azure, GCP), Container & Kubernetes security, Vulnerability management, AI/LLM security, CI/CD pipeline integration, Security architecture design
Preferred skills
Harness pipelines, Jfrog Artifactory, Wiz, Prisma Cloud, Snyk, Checkmarx, Veracode, SonarQube, CISSP, CCSP, CSSLP
Technologies
GitHub, GitLab, Jenkins, Wiz, Prisma Cloud, Snyk, Checkmarx, Veracode, SonarQube, Kubernetes, AWS, Azure, GCP
Responsibilities
Lead design and implementation of DevSecOps solutions in CI/CD pipelines; Define and implement secure SDLC practices; Own and optimize CNAPP platforms; Drive vulnerability management strategy; Integrate and tune AppSec tools; Establish guardrails for AI-generated code security; Partner with engineering teams to reduce vulnerability backlog; Define KPIs and reporting for security posture; Serve as technical advisor for complex security challenges; Lead system and network architecture support for security technologies; Develop security incident response plans.
Seniority
Senior, hands-on IC