Lead DevSecOps Engineer

System One

Pittsburgh (Allegheny County)

On-site

USD 130,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

System One is seeking a Lead DevSecOps Engineer in Pittsburgh, PA, responsible for integrating security into CI/CD pipelines and leading DevSecOps practices across teams. The role requires over 7 years of experience in security automation and a strong understanding of tools like Jenkins, Bitbucket, and Ansible.

The ideal candidate will coach teams on security protocols and ensure compliance with best practices, while actively managing the security and reliability of pipelines.

Qualifications

  • 7+ years of hands-on DevSecOps or security automation engineering experience in enterprise environments.
  • Strong knowledge of Jenkins and Bitbucket with a focus on troubleshooting and security.
  • Advanced proficiency in Python for REST API integrations and automation.

Responsibilities

  • Lead security integration into CI/CD pipelines and architect secure cloud environments.
  • Manage Jenkins pipelines for vulnerability remediation automation.
  • Coach offshore engineers on PNC-specific DevSecOps practices.

Skills

DevSecOps
Python
Jenkins
Ansible
Terraform
Bitbucket
CyberArk

Tools

Docker
OpenShift
SecurityCenter
Tanium
Archer GRC

Job description

Job Title: Lead DevSecOps Engineer

Location: Pittsburgh, PA

Responsibilities
  • Lead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design engineering approach across cloud and application platforms.
  • Build and lead the DevSecOps engineering practice across all three execution crews: Platform & Infra, Application/Data/Middleware, and Container & TRC.
  • Own the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements.
  • Coach offshore engineers on PNC-specific practices including Bitbucket branching standards, Jenkins pipeline security gates, PAC enforcement, and container security policies.
  • Manage the security and reliability of Jenkins pipelines used for vulnerability remediation automation, including implementing and maintaining security gates and reusable pipeline components.
  • Own Bitbucket repository structure, branching standards, and manage workflow configurations to enforce quality and security standards.
  • Implement and maintain client PAC policy rules governing vulnerability automation, ensuring compliance with security policies before execution.
  • Develop Ansible playbooks and Terraform modules for infrastructure remediations, ensuring automated compliance evidence generation for audits.
  • Own operations and health of vulnerability tools (Archer, Tanium, Sysdig, SecurityCenter, Imperva), maintaining integrations and ensuring correct alert processing and scan coverage.
  • Manage secrets via CyberArk, ensuring least-privilege access and integrating secrets management within pipelines.
  • Build and maintain a unified vulnerability SLA dashboard in Archer with real-time vulnerability data, along with automated weekly SLA reports.
  • Drive shift-left security practices within client application teams by embedding PAC checks and container security scans in the development pipeline.
  • Identify automation improvements to increase efficiency and contribute operational insights to improve AI/ML triage engines.
Requirements
  • 7+ years of hands-on DevSecOps or security automation engineering experience in enterprise environments.
  • Deep experience with Jenkins: shared libraries, pipeline-as-code, credential management, plugin administration, troubleshooting.
  • Proficiency with Bitbucket: branch permissions, PR workflows, webhook automation, Jenkins integration.
  • Strong knowledge of Artifactory: dependency management, artifact promotion, repository configuration, security scanning.
  • Advanced Python skills: REST API integrations, automation scripting, data pipeline code.
  • Expertise in Ansible: playbook creation for OS and middleware remediations on Linux and Windows.
  • Experience with Terraform: module writing, state management, change governance.
  • Familiarity with policy-as-code tools like OPA/Conftest and runtime enforcement.
  • REST API integrations with Archer GRC, ServiceNow, Jira.
  • Container operations: Docker, OpenShift/OCP, image management, container security.
  • Practical experience with vulnerability platforms: Archer GRC, Tanium, SecurityCenter.
  • Secrets management expertise, specifically CyberArk.
  • Understanding of banking/financial services environment, including CAB process, change windows, deployment governance, and audit requirements.
Preferred Qualifications
  • Familiarity with Converge, Micron framework, CaaS/OCP configurations, or BTI retail/lending mnemonic structures.
  • Sysdig operational experience for container vulnerability scanning and alert management.
  • Tanium endpoint detection and vulnerability data extraction.
  • AI/ML pipeline experience, including LangChain or similar AI agent integration.
  • Production-level Jira administration and Confluence documentation.
Equal Opportunity Employer Statement

System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead DevSecOps Engineer
Lead DevSecOps Engineer

System One • Dallas (TX)

On-site
USD 120,000 - 150,000
Health insurance
401(k) plan
Dental and vision coverage
Lead DevSecOps Engineer
Lead DevSecOps Engineer

System One • Strongsville (OH)

On-site
USD 100,000 - 130,000
Health insurance
401(k) plan
Dental and vision benefits
Automation Lead
Automation Lead

System One • Dallas (TX)

On-site
USD 100,000 - 130,000
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

Dark Wolf • Arlington (VA)

Hybrid
USD 155,000 - 185,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
Senior Technical Engineer
Senior Technical Engineer

Randstad USA • Malvern

On-site
USD 81,000 - 90,000
Vulnerability Management Systems Engineer
Vulnerability Management Systems Engineer

Federal Home Loan Bank Pittsburgh • Pittsburgh

On-site
USD 90,000 - 120,000
Senior DevOps Engineer TS/SCI (or eligible)
Senior DevOps Engineer TS/SCI (or eligible)

Vibrint • Reston (VA)

On-site
USD 140,000 - 190,000