DevSecOps Security Assessment Engineer
1 week ago
SOFT's client located in Remotely is looking for a Security Assessment Engineer - DevSecOps for a long term contract assignment.
PLEASE NOTE THE FOLLOWING BEFORE APPLYING:
WE ARE NOT ACCEPTING ANY 3RD PARTY SOLICITATIONS FOR THIS OR ANY OF OUR JOB POSTINGS OR REQUISITIONS. ANY SUCH INQUIRIES WILL NOT BE CONSIDERED OR RESPONDED TO.
WE CAN ONLY WORK WITH DIRECT APPLICANTS WHO ARE AUTHORIZED TO WORK IN THE US WITHOUT SPONSORSHIP
We are seeking a skilled Security Assessment Engineer to join our team. The ideal candidate will be instrumental in supporting the adoption of DevSecOps principles and automating assessment services to ensure continuous authorization to operate within our organization. This is a unique position that must be able to flex between security engineering, security control automation, development, and assessor roles in a NIST based risk management environment.
Key Responsibilities:
• Support DevSecOps initiatives by developing and implementing test-driven security within a CI/CD pipeline
• Create automation to support the NIST Risk Management Framework (SP800-37, SP800-53/53a).
• Develop and track Plan of Action and Milestones (POA&Ms) to address identified security vulnerabilities and compliance gaps.
• Able to document clear and repeatable process and train others to be able to perform automated assessment reviews.
• Develop and implement security assessment automation tools to support DevSecOps practices.
• Collaborate with development teams to integrate security assurance into the CI/CD pipeline.
• Conduct security assessments and risk analyses on new and existing software.
• Provide Subject Matter Expertise in the creation of security policies, standards.
• Develop and document procedures specific to the role.
• Work closely with compliance teams to ensure continuous monitoring and authorization.
• Assist in developing security training and awareness for technical staff.
• Stay current with evolving security landscape, industry trends, tools, and best practices.
Required Qualifications:
• Bachelor’s degree in Computer Science, Information Security, or a related field (preferred)
• Proven experience with security assessment tools and methodologies.
• Experience with wide range of programming languages, automation tools and scripting languages (e.g., Python, Ruby, Go, Bash/Shell, JavaScript/Node.js, Groovy, YAML/JSON, PowerShell, Java, Terraform).
• Understanding languages in the context of various DevSecOps tools and platforms like Docker, Kubernetes, Ansible, Chef, Puppet, Jenkins, GitLab CI, and cloud service providers (AWS, Azure, GCP).
• Experience with Policy as Code and Compliance as Code
• Knowledge of compliance frameworks and continuous authorization processes. Prefer NIST SP800-37, SP800-53/53a.
• Excellent communication skills and the ability to work collaboratively.
• Operational vulnerability analysis.
• Deep understanding of Dev/Sec/Ops processes and testing.
Preferred Qualifications:
• Certifications such as GCSA, CISSP, CEH, or OSCP.
• Experience in a policy and assurance or quasi-governmental environment.
• Familiarity with cloud service providers and associated security challenges.
The candidate must possess skills that include experience with:
Test design, performance testing, test architecture, configuration management, troubleshooting,
excellent verbal and written and communication skills both horizontally and vertically, performing manual testing with agility and interaction, be proficient in continuous delivery, Agile, and DevOps.
-
DevSecOps Security Assessment Engineer
1 week ago
new york city, United States SOFT Inc. Full timeSOFT's client located in Remotely is looking for a Security Assessment Engineer - DevSecOps for a long term contract assignment.PLEASE NOTE THE FOLLOWING BEFORE APPLYING: WE ARE NOT ACCEPTING ANY 3RD PARTY SOLICITATIONS FOR THIS OR ANY OF OUR JOB POSTINGS OR REQUISITIONS. ANY SUCH INQUIRIES WILL NOT BE CONSIDERED OR RESPONDED TO. WE CAN ONLY WORK WITH DIRECT...
-
DevSecOps Security Assessment Engineer
1 week ago
New York, United States SOFT Inc. Full timeSOFT's client located in Remotely is looking for a Security Assessment Engineer - DevSecOps for a long term contract assignment.PLEASE NOTE THE FOLLOWING BEFORE APPLYING: WE ARE NOT ACCEPTING ANY 3RD PARTY SOLICITATIONS FOR THIS OR ANY OF OUR JOB POSTINGS OR REQUISITIONS. ANY SUCH INQUIRIES WILL NOT BE CONSIDERED OR RESPONDED TO. WE CAN ONLY WORK WITH DIRECT...
-
DevSecOps Engineer
1 month ago
New York, New York, United States Minutes to Seconds Pty Ltd Full timeAbout the JobAt Minutes to Seconds, we're dedicated to matching talented individuals with tailored job opportunities that foster success. Our expertise lies in pairing people with the right job roles, creating a perfect fit that drives business growth and individual development. We've partnered with top-notch individuals and businesses in Australia to...
-
DevSecOps Engineer
3 weeks ago
New Haven, United States Talent Groups Full time**Our client is only able to work with W2 candidates at this time (US Citizen or Green Card Perm Residents)**Hybrid Details: Onsite as neededDuration: 12 months to startJob DescriptionThe DevSecOps Engineer, will oversee a variety of platform and product deployments. The DevSecOps Engineer will collaborate with developers, scrum teams and information...
-
DevSecOps Engineer
4 weeks ago
New Orleans, Louisiana, United States iSeatz Full timeJob SummaryiSeatz is seeking a highly skilled DevSecOps Engineer to join our team. As a DevSecOps Engineer, you will play a critical role in bridging the gap between development, operations, and security to ensure the rapid, safe, and secure delivery of code.Key Responsibilities Integrate security into CI/CD pipelines to ensure secure deployment practices...
-
DevSecOps Engineer
2 weeks ago
New Haven, CT, United States Talent Groups Full time**Our client is only able to work with W2 candidates at this time (US Citizen or Green Card Perm Residents)**Hybrid Details: Onsite as neededDuration: 12 months to startJob DescriptionThe DevSecOps Engineer, will oversee a variety of platform and product deployments. The DevSecOps Engineer will collaborate with developers, scrum teams and information...
-
DevSecOps Transformation Lead
4 weeks ago
New York, New York, United States Capco Full timeAbout the Role:We are seeking a highly skilled DevSecOps Transformation Lead to join our team at Capco. As a Principal Consultant for DevSecOps Excellence, you will play a key role in driving the development of a comprehensive DevSecOps strategy, focusing on automation, operational soundness, and alignment with best practices.Key Responsibilities:Lead the...
-
Security Engineer
3 weeks ago
New York, United States Motion Recruitment Full timeOur client is looking for a Security Engineer to lead their security initiatives and protect sensitive company data. The role involves developing security tools, automating workflows, responding to incidents, and collaborating with engineering teams to ensure data security and governance. Ideal candidates will have, hands-on experience in DevOps/DevSecOps...
-
Jersey City, New Jersey, United States The Dignify Solutions LLC Full timeJob Title: Cloud Security Engineer with DevSecOpsCompany: The Dignify Solutions LLCJob Summary:We are seeking a highly skilled Cloud Security Engineer with expertise in DevSecOps to join our team. The ideal candidate will have a strong background in cloud security, threat detection, and DevSecOps practices.Key Responsibilities:Develop, implement, and verify...
-
Senior Security Engineer
3 weeks ago
New York, New York, United States Bitcoin Devs Company Full timeJob Title: Senior Security EngineerJob Description:The Senior Security Engineer plays a vital role in ensuring the security and integrity of Bitcoin Devs Company’s platform, systems, and applications. This position is crucial in protecting the organization from potential security threats and vulnerabilities, as well as implementing and maintaining best...
-
DevSecOps Engineering Lead, NA Technology
6 days ago
jersey city, United States Chubb Full timeDo you thrive in fast-paced environments, leading teams to adopt secure and efficient software development practices? Are you passionate about building DevSecOps pipelines that deliver measurable value? If so, we want to hear from you!You might know Chubb as the world’s largest publicly traded P&C insurer, but we also built a market-leading insurtech from...
-
Security Solutions Engineer
4 weeks ago
New York, New York, United States Avant Tech Full timeJob Title: Security Solutions EngineerAt Avant Tech, we're seeking a highly motivated Security Solutions Engineer to join our team. As a key member of our Security team, you will be responsible for engineering automated security solutions that secure and harden internal platforms, reducing friction for developers in their daily development lifecycle.Key...
-
Security Engineer
3 weeks ago
New York, United States Avant Tech Full timeOur client provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management. They enable their clients to achieve their strategic financial objectives by providing...
-
Staff Security Engineer
1 week ago
New York, United States Intuit Inc Full timeOverview We are seeking a highly skilled Staff Security Engineer with over 10 years of overall experience, including 5+ years of coding experience, and a robust background in security reviews, threat modeling, and incident response. This role requires a unique combination of advanced software development skills and deep expertise in security to perform...
-
Cybersecurity Engineer
4 weeks ago
New York, New York, United States Crédit Agricole CIB Full timeJob SummaryThe Security Engineer will be responsible for the IT Security review and assessment of the corporate desktops and servers, infrastructure applications & network in CA-CIB NY. He is also responsible for enforcing the security policy and complying with requirements of external security audits and recommendations.Key ResponsibilitiesPrepare,...
-
Information Security Engineer 3
2 months ago
New York, United States Aloden, Inc. Full timeJob Title: Information Security Engineer 3 (SAAS, Checkmarx, OWASP, Python) Location: New York Summary: We are seeking a highly skilled and experienced Information Security Engineer 3 to join our team. The ideal candidate will have a strong background in SaaS security, vulnerability management, and application security testing. You will play a critical role...
-
Security Specialist
4 weeks ago
New York, New York, United States Motion Recruitment Full timeJob Title: Security SpecialistAbout the Role:We are seeking a highly skilled Security Specialist to lead our security initiatives and protect sensitive company data. The ideal candidate will have hands-on experience in DevOps/DevSecOps tools, strong analytical skills for monitoring logs and managing vulnerabilities, and a strong understanding of security...
-
Cyber Security Engineer
3 weeks ago
New York, United States Saxon Global Full timeFULL TIME POSITION: Title-Cyber Security Engineer/NIST Title Client - Peoples Bank - Location-Hybrid/Midtown, New York City - salary--$ 145K Salary Target -Visa:USC,GC,GC-EAD **We need a senior (7+ Years) Cyber Security Engineer with great experience working with Cyber Security and Information Risk management with Strong understanding and hands on...
-
new york city, United States A-1 Consulting Inc, Atlanta, GA Full timeHi ,Greetings !!!!Please go through the below job description and let me know your interest.Role: Application Security Engineer/Architect Location: NYC, NY(Hybrid)Only : GC / USC*We are looking for a motivated, detail-oriented individual with strong technical skills. This role’s primary focus is on working to secure in-house built and software as a service...
-
new york city, United States A-1 Consulting Inc, Atlanta, GA Full timeHi ,Greetings !!!!Please go through the below job description and let me know your interest.Role: Application Security Engineer/Architect Location: NYC, NY(Hybrid)Only : GC / USC*We are looking for a motivated, detail-oriented individual with strong technical skills. This role’s primary focus is on working to secure in-house built and software as a service...