Enable job alerts via email!

DevSecOps Engineer

Aedify Security LLC

United States

Remote

USD 80,000 - 120,000

Full time

10 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a proactive DevSecOps Engineer to enhance software security programs and streamline release engineering practices. This role involves collaborating with client teams to implement secure development processes and integrate security testing tools into pipelines. The ideal candidate will have a strong technical background, experience with security tooling, and the ability to communicate effectively across diverse teams. Join a company that values collaboration and individual growth, where your contributions will directly impact security outcomes and help organizations mature securely at scale.

Qualifications

  • 5+ years in software development and security engineering.
  • Experience with security tooling in agile and DevOps pipelines.
  • Knowledge of third-party software risk management.

Responsibilities

  • Documenting software security mandates and standards.
  • Integrating security tools into development pipelines.
  • Designing trusted release engineering processes.

Skills

Security Management
Application Development
IT Security Engineering
Security Tooling Implementation
Technical Documentation
Threat Modeling
Curiosity for DevSecOps Practices

Education

BSc in Computer Science
Master’s in related field

Tools

Azure DevOps
GitHub Actions
GitLab CI/CD
Jenkins
Terraform
CloudFormation
Veracode
Checkmarx
Snyk
Fortify
SonarQube

Job description

Position Type: Contractor, Full-time (1880 hrs. per year)

Position Location: Fully Remote

General Responsibilities

Aedify is seeking a DevSecOps Engineer to help our clients improve their software security programs, security testing pipelines, third-party software management, and release engineering practices.

The DevSecOps Engineer will work directly with client teams to formalize and operationalize secure development processes, integrate security testing tools into pipelines, and develop sustainable release engineering processes. This role will also help establish a separate, trusted, and compartmentalized release engineering function distinct from R&D software development.

Key responsibilities include:
  1. Documenting and communicating software security mandates, standards, and stakeholder roles across customer organizations.
  2. Integrating and configuring security tools into existing development pipelines (e.g., SAST and SCA tools).
  3. Assisting teams in tool evaluation, setup, and adoption across SDLC stages.
  4. Advising on and defining internal threat modeling practices.
  5. Supporting third-party software governance, including open-source and commercial dependencies, using automation.
  6. Coordinating external reviews and penetration testing with stakeholders.
  7. Designing and implementing trusted release engineering processes that separate release packaging, signing, and artifact promotion from R&D practices.
  8. Defining secure, auditable, and independently operated release workflows with stakeholders.
  9. Establishing controls for release artifact integrity, provenance tracking (e.g., SLSA), and environment isolation.
  10. Researching, prototyping, and recommending industry-aligned DevSecOps and release engineering best practices (e.g., NIST SSDF, SLSA, CNCF).

This position requires a proactive individual with strong technical skills, capable of working hands-on in CI/CD environments and formalizing release governance, while effectively communicating security and operational concepts to diverse audiences.

Qualifications
  • Experience working with Security Management, Application Development, IT, and Security Engineering teams.
  • Proven ability to implement security tooling within agile and DevOps pipelines.
  • Familiarity with GitOps and CI/CD platforms (e.g., Azure DevOps, GitHub Actions, GitLab CI/CD, Jenkins).
  • Hands-on experience with security testing tools (e.g., Veracode, Checkmarx, Snyk, Fortify, SonarQube).
  • Experience defining or improving release engineering processes and artifact workflows.
  • Knowledge of third-party software risk management and SBOM processes.
  • Ability to translate security policies and threat models into pipeline controls.
  • Strong written communication skills for technical documentation and presentations.
  • Independent work ethic with initiative to drive projects forward.
  • Curiosity and ability to research emerging DevSecOps practices.
Experience
  • Knowledge of enterprise platforms like JEE, Node.js, Python, or full-stack environments.
  • Experience with Infrastructure-as-Code tools (Terraform, CloudFormation) and cloud architectures.
  • Understanding of cloud security best practices in AWS, Azure, or GCP.
  • Hands-on experience with Secure SDLC processes and release practices.
  • Familiarity with software supply chain security frameworks (SLSA, in-toto, OCI signing).
Education & Experience
  • BSc in Computer Science, Engineering, or related; Master’s preferred.
  • 5+ years in software development, DevOps, or security engineering.
  • 3+ years in DevSecOps or release engineering initiatives.
About Aedify

At Aedify, we empower organizations to mature securely at scale, nurturing individual growth. We value deep listening and collaboration, working shoulder to shoulder with clients to deliver security outcomes efficiently.

We embrace diversity and equal opportunity, welcoming applicants from all backgrounds to enrich our team. Join us where passion meets purpose, and growth and security are our shared goals. Contact careers@aedify.com for more information.

Seniority level
  • Mid-Senior level
Employment type
  • Contract
Job function
  • Engineering and Information Technology
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

DevSecOps Engineer

Via Logic LLC

Village of Harriman

Remote

USD 67,000 - 123,000

6 days ago
Be an early applicant

DevSecOps Engineer - Austin, TX (Remote within TX)

My3Tech

Texas

Remote

USD 90,000 - 140,000

7 days ago
Be an early applicant

DevSecOps Engineer – remote

Level DI

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

Security Engineer – Containers/DevSecOps (100% Remote)

The Mom Project

Remote

USD 100,000 - 125,000

9 days ago

DevSecOps Engineer - Remote

CentralSquare

Remote

USD 80,000 - 120,000

25 days ago

Cloud DevSecOps Engineer Sr

Dayforce

Remote

USD 90,000 - 150,000

Yesterday
Be an early applicant

DevSecOps Engineer

Accenture Federal Services

Sully Square

Hybrid

USD 108,000 - 215,000

3 days ago
Be an early applicant

C++ Software Engineer (DevSecOps)

Aleron

Virginia

Remote

USD 80,000 - 110,000

9 days ago

Cloud DevSecOps Engineer Sr

Dayforce US, Inc.

Minnesota

Remote

USD 90,000 - 150,000

3 days ago
Be an early applicant