Senior DevSecOps Engineer Work Schedule Standard (Mon-Fri) Environmental Conditions Office Job Description Job Description We are seeking a Senior DevSecOps Engineer (8-12 years of experience) with demonstrated technical leadership experience to lead security automation and tooling integration across projects .
This role will focus on embedding security controls into the software delivery lifecycles specifically SBOM generation and quality improvement, secret scanning, and SAST integration -and automating security report generation and publishing into platforms such as Dependency-Track and DefectDojo . You will work closely with engineering, DevOps, and security stakeholders to drive adoption of secure-by-default practices, influence technical direction, and ensure scalable, repeatable, and measurable security automation through CI/CD pipelines. You will also help raise the overall maturity of the program through mentorship, standards, and continuously improving documentation.
Key Responsibilities
- Provide technical leadership for DevSecOps initiatives across MSD projects, including driving best practices, standardization, and adoption across teams.
- Integrate and operationalize security tooling within MSD projects, including: SBOM generation and validation Secret scanning SAST (Static Application Security Testing)
- Improve the quantity (coverage) and quality of generated SBOMs by defining standards, validation gates, and measurable KPIs (e.g., completeness, dependency accuracy, license metadata, component version resolution).
- Design and maintain CI/CD automation to generate security reports and automatically publish results to: Dependency-Track (SBOM ingestion / component risk analysis) DefectDojo (centralized vulnerability management / reporting)
- Build and maintain "security as code" patterns (pipeline templates, reusable scripts, standardized configs) to enable broad adoption across multiple repositories/teams.
- Mentor engineers and partners with development teams to improve remediation workflows by tuning rulesets, improving signal-to-noise, and ensuring findings are actionable.
- Establish secure and scalable practices for credential handling in pipelines (least privilege, secret management patterns, rotation support).
- Lead or contribute to cross-functional working groups with Security, DevOps, and Engineering to align on standards, prioritization, and measurable outcomes.
- Create, maintain, and continuously improve documentation (runbooks, onboarding guides, troubleshooting, reference architecture) to support platform adoption.
- Provide operational support for security tooling integrations, including triage of pipeline failures, report ingestion issues, and tooling upgrades.
- Contribute to continuous improvement of DevSecOps strategy, governance, and compliance alignment through automation and measurable outcomes.
Required Skills
- 8-12 years of experience in DevOps / DevSecOps / Security Engineering / Platform Engineering roles with strong CI/CD ownership.
- Demonstrated technical leadership experience (e.g., leading initiatives, mentoring engineers, defining standards, driving cross-team adoption).
- Strong hands-on experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, GitLab CI).
- Practical expertise in: SBOM generation and management (e.g., CycloneDX or SPDX concepts, dependency discovery, artifact association)
- Secret scanning integrations and tuning SAST integration, configuration, and triage workflows
- Experience automating generation, transformation, and publishing of security results (APIs, JSON handling, pipelines-as-code, scripting).
- Experience integrating with or operating vulnerability/SBOM platforms such as Dependency-Track and DefectDojo (or equivalent tools).
- Strong scripting skills (Python, PowerShell, Bash, etc.) for automation and tooling glue.
- Strong troubleshooting skills across build systems, SCM workflows, containers/artifacts, and security tooling outputs.
- Ability to write clear technical documentation and drive adoption across teams.
Desirable Skills
- Experience improving SBOM quality metrics and implementing policy gates (completeness checks, schema validation, build provenance, license metadata enrichment).
- Familiarity with SCA/vulnerability workflows and risk triage at scale (severity normalization, deduplication, SLA reporting).
- Experience with container security and artifact scanning (images, binaries, registries), plus SBOM provenance linkage.
- Knowledge of secure software supply chain practices (SLSA concepts, signing/attestation, provenance, dependency pinning).
- Experience working in regulated or security-focused environments with strong auditability requirements.
- Exposure to internal developer platform patterns (golden pipelines, reusable actions, templates, centralized governance).
Experience Level Senior Level