DevSecOps Engineer

Silpa Consulting LLC

Houston (TX)

Hybrid

USD 120,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Complex work environments
Opportunities for follow-on engagements
Invest in your development

Job summary

A leading IT consulting firm is seeking a skilled DevSecOps Engineer in Houston, Texas, to enhance cloud security protocols across multiple projects. The role involves building efficient CI/CD pipelines, securing cloud environments, and integrating modern security tools like Terraform and Docker. Ideal candidates will have extensive experience with Azure, AWS, and GCP, along with a robust understanding of security practices. Join us to make a significant impact on our client's software delivery processes.

Qualifications

  • 3 or more years of hands-on experience in DevSecOps or cloud security engineering.
  • Proficient in CI/CD pipeline creation and modification.
  • Hands-on experience with securing infrastructure in Azure, AWS, or GCP.

Responsibilities

  • Design and maintain secure CI/CD pipelines.
  • Integrate security tools into pipeline workflows.
  • Ensure compliance controls within CI/CD processes.
  • Monitor cloud environments for security events.

Skills

DevSecOps
CI/CD tooling
Infrastructure as Code (IaC)
Container security
Scripting in Python

Tools

Terraform
GitHub Actions
Azure DevOps
Docker
Kubernetes

Job description

Submit your application and resume through our online form. We'll review your qualifications and get back to you soon.

Silpa Companies, LLC is a national IT consulting and staffing firm empowering organizations across multiple industries through a blend of AI adoption, Master Data Management, Data and Analytics, Cybersecurity, Cloud Engineering, DevSecOps/GitOps, Fractional C-Suite leadership, Digital Transformation, and M&A advisory for private equity and software ventures.

Role Description

Silpa Companies is seeking a hands-on DevSecOps Engineer for contract, project-based engagements across our cloud engineering, application security, and platform delivery portfolio. You will embed with client engineering teams to build, secure, and automate the pipelines, infrastructure, and delivery workflows that power modern software organizations. This role sits at the intersection of development, operations, and security. You are not a policy writer or an auditor. You are an engineer who builds secure systems, automates security controls into pipelines, and hardens cloud infrastructure across Azure, AWS, and GCP. You are comfortable writing Terraform, tuning a SIEM alert, reviewing a Dockerfile for security misconfigurations, and advising a development team on secrets management in the same week. Versatility and technical depth are what make this role work.

Key Responsibilities
  • Design, build, and maintain secure CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent tooling.
  • Integrate SAST, DAST, SCA, container scanning, and secrets detection tools directly into pipeline workflows.
  • Enforce security gates, policy-as-code checks, and compliance controls as automated pipeline steps.
  • Manage pipeline secrets, service credentials, and environment configurations using vault solutions (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
  • Continuously improve pipeline performance, reliability, and security posture across client delivery environments.
  • Design and implement secure cloud infrastructure across Azure, AWS, and GCP using infrastructure-as-code (Terraform, Bicep, CloudFormation, Pulumi).
  • Harden cloud environments against misconfigurations using tools such as Prisma Cloud, Wiz, Defender for Cloud, or AWS Security Hub.
  • Implement and manage identity and access controls including IAM policies, service accounts, RBAC, and least-privilege enforcement.
  • Configure and maintain network security controls including VPCs, security groups, private endpoints, and zero-trust network access patterns.
  • Monitor cloud environments for security events, anomalies, and compliance drift using SIEM and cloud-native observability platforms.
  • Secure containerized workloads and Kubernetes clusters including pod security policies, network policies, image scanning, and runtime protection.
  • Manage and harden Kubernetes environments across AKS, EKS, and GKE.
  • Enforce image provenance, vulnerability scanning, and supply chain security practices across container registries.
  • Partner with development teams to shift security left and build a culture of secure-by-default engineering.
  • Conduct architecture reviews and threat modeling sessions to identify security risks early in the development lifecycle.
  • Produce clear documentation for pipelines, runbooks, security controls, and infrastructure configurations.
  • Support incident response activities including forensic data collection, environment containment, and post-incident hardening.
  • Assess and harden AI-powered applications and LLM integrations against threats defined in the OWASP LLM Top 10.
  • Integrate AI-specific security scanning and validation controls into CI/CD pipelines for applications that consume LLM APIs or deploy ML models.
  • Evaluate and enforce data privacy and access controls for AI workloads including RAG pipelines, vector databases, fine-tuning datasets, and model endpoints.
  • Support secure deployment of AI services across Azure OpenAI, AWS Bedrock, and Google Vertex AI including network isolation, identity controls, and logging.
What We Are Looking For
  • 3 or more years of hands-on DevSecOps, platform engineering, or cloud security engineering experience.
  • Proficiency with CI/CD tooling and the ability to build and modify pipelines, not just run them.
  • Hands-on experience securing infrastructure and workloads across Azure, AWS, and GCP.
  • Strong IaC skills with Terraform and at least one cloud-native IaC tool (Bicep, CloudFormation, or Pulumi).
  • Experience with container security across Docker and Kubernetes, including cluster hardening and image scanning.
  • Working knowledge of application security tooling including SAST, DAST, SCA, and secrets scanning solutions.
  • Familiarity with AI and LLM security risks including OWASP LLM Top 10, prompt injection, data leakage through model outputs, and supply chain risks in ML pipelines.
  • Familiarity with compliance frameworks (SOC 2, NIST, CIS Benchmarks) as they apply to cloud and pipeline environments.
  • Strong scripting skills in Python, Bash, or PowerShell to automate security and operations workflows.
Eligibility Requirements
  • Authorized to work in the U.S.
  • Candidates located in the Houston, Texas area will be given preference; however, remote practitioners will also be considered.
  • Reliable, secure internet connection and ability to travel to client sites as required by engagement scope.
  • Available to mobilize within a standard engagement window and maintain consistent availability throughout project duration.
Why Join Us?

Silpa Companies places DevSecOps Engineers on engagements where the work is real, the environments are complex, and your contributions directly improve how clients build and ship software. You will work across cloud platforms, pipeline toolchains, and security stacks that span multiple industries and technology maturity levels. No two engagements are the same. Engineers who bring technical depth and a security-first mindset build strong reputations within the Silpa network and are consistently prioritized for follow-on and expanded scope engagements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Full Stack Engineer
Full Stack Engineer

Silpa Consulting LLC • Houston (TX)

Hybrid
USD 90,000 - 120,000
Diverse technology engagements
Opportunities for growth
Flexible work arrangements
Technology Lead
Technology Lead

Silpa Consulting LLC • Houston (TX)

Hybrid
USD 120,000 - 150,000
Competitive compensation
Diverse project opportunities
Supportive project management
Penetration Tester
Penetration Tester

Silpa Consulting LLC • Houston (TX)

Remote
USD 96,000 - 152,000
Flexible contract engagements
Diverse client projects
Opportunity for repeat engagements
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000
vCISO
vCISO

Silpa Consulting LLC • Houston (TX)

Hybrid
USD 120,000 - 180,000
DevOps Engineer, Information Technology
DevOps Engineer, Information Technology

Socket.dev • Plano (TX)

Hybrid
USD 120,000 - 170,000
DevSecOps Engineer - USSF XC3
DevSecOps Engineer - USSF XC3

Silotech Group, Inc • San Antonio (TX)

Hybrid
USD 120,000 - 180,000
Senior DevSecOps Engineer – Secure Cloud & CI/CD (Remote)
Senior DevSecOps Engineer – Secure Cloud & CI/CD (Remote)

Silotech Group, Inc • San Antonio (TX)

Hybrid
USD 120,000 - 180,000
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

LionHires Recruitment • Town of Poland (NY)

On-site
USD 140,000 - 180,000
Health insurance
Sports package
20 vacation days
+3