AppSec & DevSecOps Lead — Secure Cloud Delivery

Imprivata

Waltham (MA)

Hybrid

USD 163,000 - 173,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Imprivata is seeking an AppSec and DevSecOps Lead to operationalize secure software delivery across product lines, engineering teams, and infrastructure. You will embed security throughout the lifecycle—from design and coding through testing, deployment, operations, and retirement—and support cloud-native as well as on‑premises, hybrid environments.

You will lead security-by-design initiatives, integrate SAST/DAST/SCA, and drive secure automation, SBOMs, and provenance across CI/CD pipelines.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
  • Seven or more years in DevOps, cloud, software, application, or infrastructure security, including three or more years of hands‑on DevSecOps or security engineering experience.
  • Experience integrating security into CI/CD and development workflows across cloud‑native and traditional environments.
  • Proficiency with AWS, Azure, or Google Cloud; infrastructure as code; containers; Kubernetes; Git; and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins.
  • Experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, and software supply‑chain controls such as SBOMs, SLSA, Sigstore, artifact signing, or provenance.
  • Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or comparable languages.
  • Working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, secure network design, and policy‑as‑code.
  • Experience securing SaaS, on‑premises, hybrid, virtualized, customer‑managed, mobile, endpoint, API, microservice, serverless, or service‑mesh environments.
  • Experience securing products in healthcare, financial services, government, or other regulated industries, including identity, privileged‑access, authentication, or zero‑trust solutions.
  • Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability‑management, or GRC platforms.
  • Familiarity with STRIDE, PASTA, attack trees, or other threat‑modeling methods, and relevant certifications such as CISSP, CCSP, CSSLP, AWS, Azure, Google Cloud, or Kubernetes security certifications.
  • Ability to explain technical risk to technical and non‑technical stakeholders, influence teams, and drive adoption without relying solely on authority.

Responsibilities

  • Drive and operationalize DevSecOps across products, cloud deployments, data centers, and traditional software, partnering with Engineering, Product, Platform, Quality, DevOps, SecOps, and GRC to drive adoption and ownership.
  • Establish security‑by‑design, secure‑by‑default, policy‑as‑code, reusable standards, reference architectures, and minimum security requirements.
  • Embed SAST, DAST, SCA, secrets, container, IaC, API, and license scanning into CI/CD, with measurable, risk‑based security gates tailored to products and deployment models.
  • Secure Git workflows, build systems, runners, identities, repositories, signing systems, credentials, release artifacts, SBOMs, provenance, and other software supply‑chain controls.
  • Apply secure‑by‑default controls to cloud, networks, identity, platforms, containers, databases, APIs, serverless services, and service communications.
  • Use infrastructure‑as‑code, policy‑as-code, and automation to address drift, excessive privileges, exposed services, and insecure network paths, while partnering on secrets, encryption, segmentation, logging, monitoring, resilience, testing, and remediation.
  • Address security for authentication, authorization, privileged access, sessions, tenant isolation, APIs, federation, mobile, endpoints, healthcare data, new services, acquisitions, and major releases.
  • Secure agentic AI and MCP servers, clients, code, and workflows through threat modeling, least privilege, authentication, authorization, tool validation, secure APIs, prompt‑injection protection, data‑loss prevention, sandboxing, isolation, monitoring, and human approval.
  • Operationalize findings from code, dependency, container, cloud, penetration testing, bug reports, and other tools by improving ownership, prioritization, remediation, exceptions, reporting, and monitoring with SecOps.
  • Support response to compromised credentials, malicious code, exposed secrets, supply‑chain attacks, unauthorized deployments, and cloud compromise, including exercises and post‑incident reviews.
  • Support NIST SSDF, NIST CSF, CIS Controls, OWASP, ISO 27001, SOC 2, and healthcare requirements; maintain control evidence; and use metrics, incidents, audits, assessments, and engineering feedback to drive continuous improvement.
  • Other duties as assigned and required.

Skills

AWS
Azure
Google Cloud
Infrastructure as Code
Containers
Kubernetes
Git
CI/CD
Python
Go
JavaScript
Java
Bash
IAM

Education

Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience

Tools

GitHub Actions
GitLab
Jenkins
SAST/DAST tools

Job description

Imprivata is seeking an AppSec and DevSecOps Lead to operationalize secure software delivery across product lines, engineering teams, and infrastructure. You will embed security throughout the lifecycle—from design and coding through testing, deployment, operations, and retirement—and support cloud-native as well as on‑premises, hybrid environments.

You will lead security-by-design initiatives, integrate SAST/DAST/SCA, and drive secure automation, SBOMs, and provenance across CI/CD pipelines.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AppSec & DevSecOps Lead: Build Secure, Scalable Software
AppSec & DevSecOps Lead: Build Secure, Scalable Software

RXinsider LTD. • Waltham (MA)

Hybrid
USD 163,000 - 173,000
Senior DevSecOps & AppSec Leader
Senior DevSecOps & AppSec Leader

Imprivata • Saint Petersburg (FL)

Hybrid
USD 184,000 - 228,000
Senior DevSecOps & Application Security Leader
Senior DevSecOps & Application Security Leader

RXinsider LTD. • Waltham (MA)

Hybrid
USD 170,000 - 230,000
Senior DevSecOps & Application Security Leader
Senior DevSecOps & Application Security Leader

Imprivata • Waltham (MA)

Hybrid
USD 184,000 - 228,000
Sr. Manager, DevSecOps and Application Security
Sr. Manager, DevSecOps and Application Security

RXinsider LTD. • Waltham (MA)

Hybrid
USD 170,000 - 230,000
AppSec and DevSecOps Lead
AppSec and DevSecOps Lead

Imprivata • Waltham (MA)

Hybrid
USD 163,000 - 173,000
AppSec Architect & DevSecOps Leader
AppSec Architect & DevSecOps Leader

ACV Auctions • Buffalo (NY), Northern (KY)

Hybrid
USD 110,000 - 170,000
Health plans
Disability & Life Insurance
Dental & Vision
+3
AppSec and DevSecOps Lead
AppSec and DevSecOps Lead

RXinsider LTD. • Waltham (MA)

Hybrid
USD 163,000 - 173,000
AppSec Lead: Secure DevOps & Cloud Engineering
AppSec Lead: Secure DevOps & Cloud Engineering

Beyond Finance • United States

Remote
USD 140,000 - 165,000
Health, dental, and vision benefits
PTO, holidays, and parental leave
401(k) matching
Senior AppSec Engineer – DevSecOps & Cloud Security Lead
Senior AppSec Engineer – DevSecOps & Cloud Security Lead

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000