Senior DevSecOps Engineer

HCSS

Sugar Land (TX)

On-site

USD 120,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work
Medical insurance
Dental insurance
Vision coverage
Holidays
ERGs
On-site amenities
401(k) 5% match

Job summary

HCSS, based in Sugar Land, TX, is seeking a Senior DevOps Engineer with a strong focus on DevSecOps and application security. You will improve, secure, and standardize software delivery across development teams, embedding security into CI/CD pipelines and SDLC practices.

You will lead SAST/DAST/SCA initiatives, manage secrets and cloud security in Azure, and collaborate with engineering, security, and operations to deliver secure software at scale.

Qualifications

  • Minimum of 5 years in application security, DevSecOps, or related field with focus on secure software delivery.
  • Experience securing applications in Azure environments using Azure-native tools.
  • Expertise in SAST/DAST/SCA and secrets management integrated into CI/CD.

Responsibilities

  • Embed security into the full SDLC and CI/CD pipelines.
  • Lead efforts to identify, prioritize, and remediate security risks and vulnerabilities.
  • Utilize Azure cloud services to ensure secure deployments and configurations.
  • Lead SAST/DAST testing to identify and remediate code and runtime vulnerabilities.
  • Manage secrets and software composition analyses to comply with security policies.
  • Develop IaC automation with Terraform for secure cloud environments.
  • Create and enforce security policies aligning with OWASP/NIST/CIS.

Skills

5+ years experience
DevSecOps
Application security
Cloud security
Threat modeling
Communication

Tools

SAST
DAST
SCA
Secrets management
Azure Key Vault
CI/CD security

Job description

We are HCSS. For the last 40 years, we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer. We have earned Best Companies to Work for in Texas honors for 18consecutive years and have been named a USA Today Top Workplace. HCSS has also been recognized by Built In as a Best Place to Work in Greater Houston and by Construction Executive for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence.

WHO WE NEED:

As a Senior DevOps Engineer specializing in DevSecOps and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development teams deliver secure software at scale.

Qualifications:
  • Experience: Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices.
  • Cloud Expertise: Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others.
  • Security Tools & Practices: Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
  • Secure Development Lifecycle: In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development.
  • Vulnerability Management: Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
  • Compliance Knowledge: Familiarity with security and compliance frameworks such as OWASP, NIST, CIS,
  • SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Collaboration & Communication: Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.
Preferred Qualifications:
  • Security Certifications: Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
  • Threat Modeling: Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
  • Experience with Microservices & APIs: Strong understanding of microservices architecture and API security practices.
  • Security Tools:Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.
Role Responsibilities:
  • DevSecOps Integration: Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
  • Application Security Expertise: Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling.
  • Azure Cloud Security: Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more.
  • Static and Dynamic Application Security Testing: Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments.
  • Secrets Management: Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments.
  • Software Composition Analysis (SCA): Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies.
  • Automation and Infrastructure as Code: Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments.
  • Security Policies & Compliance: Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure.
  • Collaboration & Mentorship: Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools.
Travel Requirements:
  • Occasional travel to our office may be requested up to once or twice a year
BENEFITS & PERKS:

Part of our mission is to provide a great life for our employees. We believe that when our people are happy, they do their best work. Some of the benefits and perks we offer include:

  • Flexibility to work Remotely
  • Medical, dental, and vision coverage with company-paid and employee-paid options
  • Paid holidays, sick days, and personal time off
  • Employee Resource Groups (ERGs) that foster connection and inclusion
  • On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
  • Dog-friendly campus and WiFi-accessible courtyards
  • 401(k) with a 5% company match
  • Coverage for employee professional development and wellness
  • And more!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Developer
Senior Software Developer

HCSS • Sugar Land (TX)

Remote
USD 110,000 - 160,000
Remote work
Medical coverage
Holidays & PTO
+2
Senior DevOps Engineer
Senior DevOps Engineer

Texas Mutual Insurance Company • Austin (TX)

Hybrid
USD 136,000 - 169,000
Annual bonus
401(k) with 100% match up to 6%
Student loan repayment matching
+2
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Virtuous Management • Phoenix (AZ)

On-site
USD 120,000 - 180,000
Bonusly
401(k) with company match
Unlimited PTO
+2
Senior Manager, People Services
Senior Manager, People Services

HCSS • Sugar Land (TX)

Hybrid
USD 90,000 - 120,000
Flexible hybrid schedule
Medical, dental, and vision coverage
401(k) with a 5% company match
+2
Senior Analyst, Corporate FP&A
Senior Analyst, Corporate FP&A

HCSS • Sugar Land (TX)

Hybrid
USD 110,000 - 160,000
Remote work flexibility
Medical, dental, vision coverage
Paid holidays & PTO
+4
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Lynx Software Technologies, Inc. • Denver (CO)

On-site
USD 120,000 - 160,000
Low-cost Medical / Dental / Vision
401K with generous employer match
Paid Time Off + Holidays
+3
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Software Engineer (Full Stack / Backend Focus)
Software Engineer (Full Stack / Backend Focus)

Staffed4U • Virginia (MN)

On-site
USD 150,000 - 190,000
Five weeks PTO annually
11 floating holidays
Employer-paid 401(k) with Vanguard
DevSecOps Engineer
DevSecOps Engineer

LionHires Recruitment • Town of Poland (NY)

On-site
USD 140,000 - 180,000
Health insurance
Sports package
20 vacation days
+3
Application Security Engineer-68257
Application Security Engineer-68257

Worky • Dallas (TX)

On-site
USD 120,000 - 180,000