DevSecOps Engineer – Information Security

Jobtailor

Town of Florida (NY)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in New York is seeking a senior security leader to develop enterprise information security policies and oversee DevSecOps practices across cloud platforms.

You will own CNAPP platforms, drive vulnerability management, integrate security into CI/CD pipelines, and guide incident response while partnering with engineering to preserve developer velocity.

Qualifications

  • BS/BA in Information Technology or related field.
  • Minimum 8 years’ experience in systems administration and security.
  • Experience with CNAPP platforms and cloud security.
  • Hands-on security integration into CI/CD pipelines at scale.

Responsibilities

  • Develops, recommends, and implements enterprise information security policies and standards.
  • Lead the design and integration of DevSecOps, Application Security and Vulnerability Management capabilities.
  • Drive secure-by-design practices across CI/CD pipelines and cloud platforms.
  • Partner with engineering teams to embed automated security controls.
  • Lead the design and implementation of DevSecOps solutions (GitHub, GitLab, Jenkins).
  • Define secure SDLC practices including automated testing and threat modeling.
  • Own CNAPP platforms to improve cloud security posture.
  • Drive vulnerability management strategy and risk-based prioritization.
  • Integrate AppSec tools (SAST, DAST, SCA, container scanning) into pipelines.
  • Establish guardrails for AI-generated code security and data protection.
  • Collaborate to reduce vulnerability backlog and MTTR.
  • Define KPIs and reporting for security posture and risk reduction.
  • Serve as technical advisor for complex security challenges.
  • Lead system and network architecture support for security technologies.
  • Develop risk assessment methodologies and incident response plans.
  • Provide escalation support and present security updates to management.
  • Champion security as a subject matter expert among peers and leadership.

Skills

DevSecOps
Application Security
Cloud Security
CNAPP
Vulnerability Management
Threat Modeling
Secure SDLC
CI/CD Security
AI Security

Education

BS/BA in Information Technology or related field

Tools

Jfrog Artifactory
Xray
Curation
Wiz
Prisma Cloud
Snyk
Checkmarx
Veracode
SonarQube

Job description

Job Responsibilities
  • Develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies.
  • Lead the design and integration of DevSecOps, Application Security and Vulnerability Management capabilities across our enterprise.
  • Drive secure‑by‑design practices across CI/CD pipelines, cloud‑native platforms, and modern development workflows—including AI‑assisted coding environments.
  • Partner closely with application engineering, cloud, and platform teams to embed scalable, automated security controls that reduce risk while enabling developer velocity.
  • Lead the design and implementation of DevSecOps solutions integrated into CI/CD pipelines (GitHub, GitLab, Jenkins).
  • Define and implement secure SDLC practices, including automated testing, threat modeling, and secure coding standards.
  • Own and optimize CNAPP platforms (e.g., Wiz, Prisma Cloud) to improve cloud security posture and workload protection.
  • Drive vulnerability management strategy, including risk‑based prioritization and integration into developer workflows.
  • Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline adoption.
  • Establish guardrails for AI‑generated code security, including validation of outputs and mitigation of risks such as insecure code patterns and data exposure.
  • Embed security controls into AI‑enabled applications and APIs, addressing emerging risks (e.g., prompt injection, model misuse).
  • Partner with engineering teams to reduce vulnerability backlog and MTTR.
  • Define KPIs and reporting for security posture, pipeline coverage, and risk reduction.
  • Serve as a technical advisor and escalation point for complex security and integration challenges.
  • Lead system and network architecture support for information and network security technologies.
  • Lead development and execution of risk assessment methodologies.
  • Develop security incident response plans and strategies.
  • Provide trouble resolution and serve as point of technical escalation on complex problems.
  • Create presentations and seek IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the enterprise.
  • Act as a subject matter expert among peers, manager, and senior management.
Requirements
  • Requires BS/BA in Information Technology or related field of study.
  • Minimum of 8 years’ experience in systems administration and security aspects of information systems.
  • Experience with access management and network security technologies.
  • Proficient in network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people expertise.
  • Experience with multiple technical and business disciplines required.
  • Experience in DevSecOps (Harness pipelines), Application Security, Cloud Security, or related fields.
  • Experience with Jfrog Artifactory, Xray, and Curation.
  • Hands‑on experience integrating security into CI/CD pipelines at scale.
  • Experience with CNAPP platforms (e.g., Wiz, Prisma Cloud).
  • Strong knowledge of Application Security (SAST, DAST, SCA, API security) & Cloud Security (AWS, Azure, or GCP).
  • Experience with containers and Kubernetes security.
  • Experience with vulnerability management and risk prioritization.
  • Experience securing AI/LLM‑enabled applications or AI‑assisted development workflows.
  • Familiarity with AI security risks (e.g., OWASP Top 10 for LLMs, prompt injection, data leakage).
  • Experience with tools such as Snyk, Checkmarx, Veracode, SonarQube.
  • Strong understanding of DevOps and Agile practices.
  • Security certifications (e.g., CISSP, CCSP, CSSLP) preferred.
Core Competencies

Demonstrates expertise in developing and implementing enterprise information security policies, integrating DevSecOps practices into CI/CD pipelines, and managing cloud security posture through CNAPP platforms. Proficient in vulnerability management, application security, and risk assessment methodologies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI DevSecOps Engineer
Senior AI DevSecOps Engineer

Jobtailor • Kansas

On-site
USD 120,000 - 180,000
Lead InfoSec Engineer, DevSecOps
Lead InfoSec Engineer, DevSecOps

S&P Global • New York (NY)

On-site
USD 140,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

electro soft • Arlington (VA)

On-site
USD 140,000 - 190,000
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

ALLTECH CONSULTING SVC INC • West Hartford (CT)

On-site
USD 90,000 - 120,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Vytalize Health • Kansas (OH)

On-site
USD 120,000 - 160,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps Engineer
DevSecOps Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 90,000 - 130,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
DevSecOps Engineer
DevSecOps Engineer

Socket.dev • Arlington (VA)

On-site
USD 120,000 - 150,000