Lead InfoSec Engineer, DevSecOps

S&P Global

New York (NY)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior DevSecOps Engineer to embed automated security controls into CI/CD pipelines across build, test, and release stages. You will design risk-based security gates, integrate SAST/DAST/SCA, and enable secure-by-default development in AWS and Azure.

You will build scalable DevSecOps tooling, champion developer-first security, and drive cloud-native security architecture for containerized workloads and IaC.

Qualifications

  • 8+ years of experience in software engineering, DevOps, or DevSecOps.
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies like Docker, Kubernetes, or OpenShift and infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi.
  • Strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms.
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles.
  • Proven ability to build and maintain internal tooling with scripting languages such as Python, Go, or similar for automation and platform development.
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders.
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority.
  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies.

Responsibilities

  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development.
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms.
  • Champion developer-first security experiences by designing "paved road" security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining strong security posture.
  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks.
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness.
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping.
  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall DevSecOps maturity across the organization.
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level.

Job description

Responsibilities
  • Embed automated security controls into CI/CD pipelines across build, test, and release stages, designing risk-based security gates and integrating comprehensive security testing (SAST, DAST, SCA, container scanning) to enable secure-by-default development
  • Build and maintain internal DevSecOps tooling and platform extensions that scale across enterprise engineering teams, including reusable pipeline libraries, security plugins, and automation frameworks integrated into shared developer platforms
  • Champion developer-first security experiences by designing "paved road" security patterns, self-service tooling, and standardized integrations that reduce friction while maintaining strong security posture
  • Drive cloud-native security architecture across AWS and Azure environments, implementing security controls for Kubernetes, containerized workloads, and infrastructure-as-code using modern security frameworks
  • Evaluate and integrate best-of-breed security tools aligned to application, pipeline, container, and cloud security needs, driving standardization and consolidation to reduce complexity while improving effectiveness
  • Support continuous compliance and governance by translating regulatory requirements into automated engineering controls, enabling audit readiness through automated evidence collection and control mapping
  • Provide technical leadership and mentorship to engineering teams as an embedded security subject matter expert, influencing design decisions and raising overall DevSecOps maturity across the organization
  • Lead vulnerability management and remediation across application, pipeline, and cloud environments while participating in threat modeling and architecture reviews to ensure security is embedded at the design level
Requirements
  • 8+ years of experience in software engineering, DevOps, or DevSecOps roles within enterprise or regulated environments with strong hands-on experience securing CI/CD pipelines and modern application stacks
  • Practical expertise with cloud platforms such as AWS, Azure, or Google Cloud, including containerization technologies (such as Docker, Kubernetes, or OpenShift) and infrastructure-as-code tools like Terraform, CloudFormation, or Pulumi
  • Strong understanding of application security concepts including OWASP Top 10, secure coding practices, and experience with security testing tools such as SAST, DAST, and SCA platforms
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity or equivalent practical experience in DevSecOps or security engineering roles
  • Proven ability to build and maintain internal tooling with experience in scripting languages such as Python, Go, or similar for automation and platform development
  • Excellent technical communication skills with the ability to clearly articulate security risks and solutions to engineering teams and business stakeholders
  • Strong collaboration and influence capabilities with demonstrated success working embedded within engineering teams and driving security adoption without direct authority
  • Experience with modern development practices including CI/CD pipeline design, version control systems like Git, and agile development methodologies
Core Competencies

Demonstrates expertise in embedding automated security controls within CI/CD pipelines and driving cloud-native security architecture across AWS and Azure environments. Proficient in application security concepts and building internal DevSecOps tooling to enhance security practices across engineering teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer – Information Security
DevSecOps Engineer – Information Security

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Vytalize Health • Kansas (OH)

On-site
USD 120,000 - 160,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
DevSecOps Application Security Engineer
DevSecOps Application Security Engineer

ALLTECH CONSULTING SVC INC • West Hartford (CT)

On-site
USD 90,000 - 120,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Sandy (UT)

On-site
USD 110,000 - 170,000
Senior Information Protection Advisor – Product Security, DevSecOps
Senior Information Protection Advisor – Product Security, DevSecOps

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Washington

On-site
USD 140,000 - 210,000
DevSecOps Lead
DevSecOps Lead

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 230,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

Hybrid
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance