DevSecOps Tech Lead

CIBR Warriors

Charlotte (NC)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CIBR Warriors is seeking a DevSecOps Tech Lead in Charlotte, North Carolina, to oversee the security and compliance of the software development lifecycle. In this role, you will develop strategies, implement technologies, and collaborate with cross-functional teams to ensure secure application delivery. Key responsibilities include leading software supply chain security initiatives, managing open-source risk, and mentoring security engineers. A Bachelor's degree and hands-on experience with SCA/SAST tools are essential for this position.

Qualifications

  • Hands-on experience deploying and operating SCA/SAST tools.
  • Experience with additional AppSec tools such as Secret Scanning and DAST.
  • Strong understanding of modern application delivery and development.

Responsibilities

  • Lead the design and execution of enterprise-wide security strategies.
  • Own end-to-end open-source risk management and vulnerability detection.
  • Define and enforce security policies aligned with industry standards.

Skills

Deployment and operation of SCA/SAST tools
Understanding of AppSec tools
Modern application development
Knowledge of security frameworks (NIST, OWASP)

Education

Bachelor's degree in a related field or equivalent experience

Job description

The DevSecOps team is responsible for the solutions and processes that secure our applications and operations. As a DevSecOps Tech Lead, you will play a pivotal role in ensuring the security and compliance of the software development lifecycle (SDLC). You will help develop strategy, implement new technology, maintain technical controls, assess vulnerabilities, and collaborate with developers to ensure that the proper guardrails are in place to enable the continuous and secure delivery of applications.

Core Responsibilities
  • Lead the design and execution of enterprise-wide Software Composition Analysis (SCA) and software supply chain security strategy across all applications and platforms.
  • Own end-to-end open-source risk management, including vulnerability detection, prioritization, and remediation of third-party dependencies.
  • Define and enforce security policies aligned with industry standards such as OWASP and NIST (SSDF), ensuring secure software development practices.
  • Integrate SCA tooling into CI/CD pipelines and developer workflows to enable automated, shift-left security controls.
  • Drive implementation and adoption of Software Bill of Materials (SBOM) standards (e.g., Cyclone,DX, SPDX) for full dependency visibility.
  • Secure the software supply chain by implementing controls for artifact integrity, provenance, and signed builds, aligned with OpenSSF frameworks (e.g., SLSA).
  • Lead response and mitigation efforts for critical supply chain vulnerabilities (e.g., zero-day dependency risks), ensuring rapid impact analysis and remediation.
  • Establish governance over artifact repositories and package registries, enforcing version control, trusted sources, and secure publishing practices.
  • Define and track key security metrics (e.g., vulnerability MTTR, coverage, policy compliance) and present insights to senior leadership.
  • Mentor a team of security engineers while partnering with engineering, DevOps, and product teams to drive scalable, developer-friendly security solutions.
Qualifications
  • Bachelor's degree in a related field or equivalent experience
  • Hands‑on experience deploying and operating SCA/SAST tools, including onboarding, auth setup, and CI/CD integration
  • Experience with additional AppSec tools (Secret Scanning, IAST, DAST, etc.)
  • Strong understanding of modern application development and delivery (IDEs, repos, CI/CD, cloud, containers, serverless)
  • Working knowledge of NIST, OWASP, and MITRE frameworks
  • AppSec, DevSecOps, cloud, or development certifications a plus
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevSecOps Engineer – Information Security
DevSecOps Engineer – Information Security

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Lead InfoSec Engineer, DevSecOps
Lead InfoSec Engineer, DevSecOps

S&P Global • New York (NY)

On-site
USD 140,000 - 180,000
Software Supply Chain Security Specialist
Software Supply Chain Security Specialist

Vanguard • Malvern

On-site
USD 150,000 - 210,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

ALLTECH CONSULTING SVC INC • West Hartford (CT)

On-site
USD 90,000 - 120,000
DevSecOps Engineer (Web Security Focus)
DevSecOps Engineer (Web Security Focus)

shefsolutionsllc • Los Angeles (CA)

On-site
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Washington

On-site
USD 140,000 - 210,000
DevSecOps Engineer
DevSecOps Engineer

Intellect Solutions LLC • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

Yugal Tech Academy • United States

Remote
USD 100,000 - 130,000