QA Engineer / DevSecOps AnalysT with Security Clearance

CEdge Inc.

St. Louis (MO)

Hybrid

USD 90,000 - 130,000

Full time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CEdge Inc. seeks a QA Engineer / DevSecOps Analyst to own the quality and security pipeline across TMS web applications. The role ensures 90-day scans, high-threat remediation within 10 days, and that every deliverable passes quality gates for MoDOT acceptance.

The position requires coordinating with developers, maintaining CI/CD in Azure DevOps, and developing automated test suites for critical modules, all while supporting accessibility testing and security metrics reporting.

Qualifications

  • 3+ years in software QA, test engineering, or application security.
  • Hands-on with SAST tools (SonarQube, Veracode, Checkmarx).
  • CI/CD experience in Azure DevOps, Jenkins, or equivalents.
  • Experience writing and executing test plans, cases, and regression suites for .NET web apps.
  • Ability to classify CVSS vulnerabilities and communicate remediation priorities to developers.
  • Willingness to undergo MoDOT background checks.
  • Familiarity with OWASP Top 10 and secure coding practices.

Responsibilities

  • Schedule, execute, and report 90-day security scans for critical and external-facing TMS web apps.
  • Triage scan results and track High-Threat remediation within 10 business days.
  • Operate and maintain the CI/CD pipeline in Azure DevOps: configure build triggers, tests, and gate controls.
  • Develop and maintain automated test suites for high-risk TMS modules.
  • Execute SOW quality gates: verify unit/integration/system tests and prepare staging packages.
  • Participate in code reviews from security/test-coverage perspective.
  • Track and report security and quality metrics weekly; provide monthly compliance evidence.
  • Ensure mirrored workstation environment matches MoDOT toolchain; coordinate updates within 30 days.
  • Support ADA/Section 508 accessibility testing for all new/modified web apps.

Skills

QA experience
SAST tools
CI/CD pipelines
Test planning
Vulnerability triage
OWASP Top 10
Accessibility testing

Education

CompTIA Security+
GIAC GWEB

Tools

Azure DevOps
Jenkins

Job description

CEdge has an opportunity for a QA Engineer / DevSecOps Analyst (Supporting) , located in Saint Louis, MO (remote/on-site when required). If you are ready to work alongside World Renowned Technology experts, and carry the skills below, this is the opportunity that will inevitably take your career to unbelievable levels! Clearance Required: None; MoDOT MACHS background check required.

POSITION SUMMARY

The QA Engineer / DevSecOps Analyst owns the quality and security pipeline for all TMS maintenance and programming deliverables. The contract imposes hard security scan obligations — 90-day mandatory scans, 10-business-day High-Threat remediation, static scan score maintained at 90 or above — that require a dedicated owner. This individual schedules and executes scans, triages results, coordinates remediation with developers, and ensures every SOW deliverable passes quality gates before staging for MoDOT acceptance. This position is not submitted as an Exhibit E biography but is critical to meeting the contract's measurable security SLAs.

KEY RESPONSIBILITIES
  • Schedule, execute, and report all required 90-day security code scans for critical and external-facing TMS web applications; maintain static scan score ≥ 90 at all times (
  • 2.3.7)
  • Triage scan results: classify vulnerabilities by severity, assign ownership to developers, and track High-Threat remediation to closure within 10 business days (
  • 2.3.7)
  • Operate and maintain the CI/CD pipeline in Azure DevOps: configure build triggers, automated test execution, and gate controls that enforce quality and security standards before merge
  • Develop and maintain automated test suites (unit, integration, regression) for the highest-risk TMS modules; expand coverage during SOW development
  • Execute SOW quality gates: confirm unit, integration, and system test completion; document results with pass/fail criteria; prepare staging packages for MoDOT acceptance
  • Participate in code review from a security and test-coverage perspective; flag testability or security concerns during architecture walkthroughs
  • Track and report security and quality metrics to the Technical Program Manager weekly; produce monthly scan compliance evidence for Program Manager review before invoicing
  • Ensure mirrored workstation environment at CEdge matches MoDOT's security scanning toolchain; coordinate tool updates within 30 days of MoDOT infrastructure change notifications
  • Support ADA/Section 508 accessibility testing for all new and modified web-application deliverables REQUIRED QUALIFICATIONS
  • Minimum 3 years of software QA, test engineering, or application security experience
  • Hands-on experience with static application security testing (SAST) tools (SonarQube, Veracode, Checkmarx, or equivalent)
  • Experience with CI/CD pipeline configuration in Azure DevOps, Jenkins, or equivalent
  • Experience writing and executing test plans, test cases, and regression suites for .NET web applications
  • Ability to classify and triage CVSS-scored vulnerabilities and communicate remediation priorities to developers
  • Ability to pass MoDOT background check PREFERRED QUALIFICATIONS
  • Minimum 1 year of experience similar to MoDOT's technical architecture (.NET, Oracle, Azure DevOps)
  • Experience with OWASP Top 10 and secure coding practices in a .NET context
  • CompTIA Security+, GIAC GWEB, or equivalent security credential
  • Experience with accessibility testing tools for Section 508 compliance (WAVE, axe, NVDA)
  • Missouri residency or St. Louis metro area location
  • Experience managing scan schedules against contractual cadence requirements
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

QA Engineer / DevSecOps Analyst (Supporting) Job id: 010
QA Engineer / DevSecOps Analyst (Supporting) Job id: 010

CEdge Inc • St. Louis (MO)

On-site
USD 80,000 - 100,000
Full Benefits Package
10 Days PTO
10 Paid Holidays
+1
QA Engineer | DevSecOps & Security CI/CD Expert
QA Engineer | DevSecOps & Security CI/CD Expert

CEdge Inc. • St. Louis (MO)

Hybrid
USD 90,000 - 130,000
QA Engineer & DevSecOps Analyst - Security & CI/CD Lead
QA Engineer & DevSecOps Analyst - Security & CI/CD Lead

CEdge Inc • St. Louis (MO)

Hybrid
USD 80,000 - 100,000
Full Benefits Package
10 Days PTO
10 Paid Holidays
+1
Oracle DBA / Spatial Engineer with Security Clearance
Oracle DBA / Spatial Engineer with Security Clearance

CEdge Inc. • St. Louis (MO)

Hybrid
USD 95,000 - 150,000
TEST ENGINEER with Security Clearance
TEST ENGINEER with Security Clearance

CEdge Inc. • St. Louis (MO)

On-site
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

IPolarity LLC • Whippany (NJ)

On-site
USD 146,136,000 - 197,713,000
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000
Application Security (AppSec) Engineer - W2 Only
Application Security (AppSec) Engineer - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 110,000 - 160,000
Cloud Application Software Security Engineer
Cloud Application Software Security Engineer

Experis • St. Louis (MO)

Hybrid
USD 124,000 - 165,000
Remote work possible
Exposure to AWS GovCloud
Federal environment experience
+2
Lansing, MI - IT - DTMB - Agency Services - MDOT - Software Test Analyst 3
Lansing, MI - IT - DTMB - Agency Services - MDOT - Software Test Analyst 3

Global Pharma Tek • Lansing (MI)

On-site
USD 75,000 - 95,000