Senior InfoSec Engineer (SecDevOps) / New York

DigitalXNode

New York (NY)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Restaurant d'entreprise
Indemnités de stage/alternance

Job summary

DigitalXNode is seeking a highly skilled Senior InfoSec Engineer (SecDevOps) to strengthen security across development, cloud, and infrastructure environments. This role bridges Security, Development, and Operations to embed security throughout the software lifecycle and cloud deployment processes.

You will design and maintain secure CI/CD pipelines, perform risk assessments, support compliance initiatives, and lead security initiatives for AWS/Azure, containers, IAM, and encryption.

Qualifications

  • Extensive experience implementing SecDevOps in cloud-native environments.
  • Proven ability to design secure SDLC and CI/CD pipelines.
  • Experience with risk assessments and threat modeling.
  • Strong communication and cross-team collaboration.

Responsibilities

  • Design, implement, and maintain secure CI/CD pipelines.
  • Integrate security controls across the Software Development Life Cycle (SDLC).
  • Collaborate with development, infrastructure, and cloud engineering teams to embed security into development workflows.
  • Perform vulnerability assessments, risk analyses, and security reviews across applications, infrastructure, and cloud environments.
  • Lead cloud and infrastructure security initiatives across AWS, Azure, and hybrid setups.
  • Develop security governance, policies, and documentation.

Skills

DevSecOps
CI/CD security
Threat modeling
Cloud security
Security architecture
IAM & encryption
Kubernetes security
Secure coding
Vulnerability management
Risk assessment

Education

Bachelor's degree in Computer Science or related field
Master's degree in Cybersecurity (advantage)

Tools

AWS
Azure
Kubernetes
Terraform
CI/CD tools
IAM tooling

Job description

We are seeking a highly skilled Senior InfoSec Engineer (SecDevOps) to strengthen the security posture of our development, cloud, and infrastructure environments. This role serves as a critical bridge between Security, Development, and Operations teams, ensuring that security is embedded throughout the software development lifecycle and cloud deployment processes.

The ideal candidate will possess strong expertise in cybersecurity, DevOps practices, cloud security, risk management, and automation. You will be responsible for implementing secure-by-design principles, enhancing CI/CD security, identifying and mitigating security risks, and promoting security best practices across engineering teams.

As a subject matter expert (SME), you will assess cybersecurity risks, evaluate security controls, support compliance initiatives, and contribute to the development of secure software delivery frameworks. This role requires hands‑on technical experience combined with strategic thinking to support secure digital transformation and cloud‑native application development.

Key Responsibilities
DevSecOps & Secure Development
  • Design, implement, and maintain secure CI/CD pipelines that support rapid and secure software delivery.
  • Integrate security controls throughout the Software Development Life Cycle (SDLC).
  • Collaborate with development, infrastructure, and cloud engineering teams to embed security into development workflows.
  • Implement security automation within build, deployment, and release processes.
  • Promote secure coding practices and software security standards across engineering teams.
Security Assessment & Risk Management
  • Conduct vulnerability assessments, risk analyses, and security reviews across applications, infrastructure, and cloud environments.
  • Identify security weaknesses and recommend remediation strategies.
  • Evaluate cybersecurity risks against established security frameworks, standards, and organizational policies.
  • Perform threat modeling and security architecture reviews for new applications and infrastructure initiatives.
  • Monitor risk exposure and provide recommendations aligned with business risk tolerance levels.
Cloud & Infrastructure Security
  • Secure cloud environments across AWS, Azure, and hybrid infrastructures.
  • Implement identity and access management (IAM), network security, encryption, and cloud governance controls.
  • Review and enhance cloud security configurations and deployment architectures.
  • Support container and Kubernetes security initiatives.
  • Collaborate on security requirements for third‑party vendors, integrations, and outsourced technology solutions.
Security Automation & Monitoring
  • Automate security testing, compliance checks, and vulnerability scanning processes.
  • Implement and maintain security monitoring and alerting solutions.
  • Support incident detection, response, and remediation activities.
  • Improve security operations through automation and workflow optimization.
  • Develop security dashboards, reporting mechanisms, and compliance monitoring processes.
Compliance, Governance & Documentation
  • Develop and maintain security policies, standards, procedures, and operational documentation.
  • Support compliance initiatives related to industry standards and regulatory requirements.
  • Document security findings, risk assessments, and remediation plans.
  • Participate in internal and external security audits.
  • Advocate for continuous security improvement across the organization.
Security Awareness & Leadership
  • Provide security awareness training and guidance to engineering and business teams.
  • Mentor developers and operations teams on secure development and deployment practices.
  • Stay informed on emerging cybersecurity threats, vulnerabilities, and security technologies.
  • Act as a security advisor for business initiatives and technology projects.
  • Escalate critical security concerns and risks to leadership when necessary.
Required Skills
Security & DevSecOps Expertise
  • Strong experience implementing DevSecOps principles and secure software delivery practices.
  • Deep understanding of application security, infrastructure security, and cloud security concepts.
  • Experience securing CI/CD pipelines and development environments.
  • Knowledge of secure coding standards, software security testing, and vulnerability management.
  • Experience with threat modeling, risk assessments, and security architecture reviews.
Cloud & Infrastructure Security
  • Strong understanding of AWS, Azure, or multi-cloud security practices.
  • Experience securing Kubernetes, Docker, and containerized environments.
  • Knowledge of identity and access management (IAM), secrets management, and cloud governance.
  • Familiarity with Infrastructure as Code (Terraform, CloudFormation, ARM Templates) security practices.
  • Understanding of network security, encryption, and cloud‑native security controls.
Professional Skills
  • Strong analytical and problem‑solving capabilities.
  • Excellent communication and stakeholder management skills.
  • Ability to balance security requirements with business objectives.
  • Strong documentation and reporting abilities.
  • Experience working with cross‑functional technical teams.
  • Ability to lead security initiatives and influence engineering practices.
Education
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Software Engineering, or a related field.
  • Master's degree in Cybersecurity, Information Assurance, or related disciplines is an advantage.
  • Equivalent combination of education and practical experience may be considered.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps
DevSecOps

CareerUS Solutions • United States

On-site
USD 110,000 - 170,000
DevSecOps Engineer
DevSecOps Engineer

Talentify • Lewisville (TX)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Chris Baily • New York (NY)

On-site
USD 150,000 - 190,000
On-site in NYC
Competitive salary
Senior DevSecOps Architect
Senior DevSecOps Architect

Compunnel, Inc. • Lansing (MI)

On-site
USD 160,000 - 230,000
Senior DevSecOps Engineer – Cloud Infrastructure Security
Senior DevSecOps Engineer – Cloud Infrastructure Security

Partnerverse • Saint Cloud (MN)

On-site
USD 140,000 - 190,000
DevSecOps Engineer
DevSecOps Engineer

Hospital for Special Surgery • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 175,000
DevSecOps Engineer
DevSecOps Engineer

Yugal Tech Academy • United States

On-site
USD 100,000 - 130,000
DevSecOps Lead/Architect
DevSecOps Lead/Architect

UsefulBI • Alameda (CA)

On-site
USD 180,000 - 240,000
Onsite work 4 days/week
Exposure to regulatory compliance
DevSecOps Engineer
DevSecOps Engineer

Phizenix Inc. • Reston (VA)

On-site
USD 120,000 - 180,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000