Staff DevSecOps Engineer | Bankrate

Bankrate

United States

Hybrid

USD 150,000 - 225,000

Full time

2 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health Insurance
Life Insurance
Disability Insurance
401(k) with match
Flexible PTO

Job summary

Bankrate is seeking a senior DevSecOps Engineer to own our security posture across cloud and CI/CD. You will implement policy-as-code, automate evidence generation, and drive secure-by-default development. The role emphasizes automation, AI-assisted remediation, and scalable security across multi-cloud environments.

You will work on integration of SAST/SCA, secret scanning, and SBOM generation, with a focus on reducing toil and accelerating product delivery while maintaining audit readiness.

Qualifications

  • 5+ years in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus.
  • Deep hands-on cloud security experience on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: building pipeline security controls into developer workflows.
  • Hands-on vulnerability management at scale with automation.
  • Working knowledge of SOC 2 and evidence controls in engineering environments.
  • Fluency with modern cloud security tooling (CSPM, SAST, secret scanning, compliance automation, SIEM).
  • Strong coding/scripting ability to build automation and tooling at scale.
  • Experience standing up or maturing an in-house security function.
  • Multi-cloud exposure and securing an internal developer platform.
  • Security monitoring and detection/alerting design.
  • Experience applying AI/LLM tooling to security operations.

Responsibilities

  • Own the engineering side of our compliance program (SOC 2 Type 2).
  • Operate our compliance automation platform with integrations and evidence pipelines.
  • Productize compliance through policy-as-code and automated evidence generation.
  • Own cloud security posture management and runtime security tooling.
  • Triage and remediate findings against SLAs with automation.
  • Build auto-remediation workflows including AI-assisted pipelines.
  • Build and maintain CI/CD security gates (SAST/SCA, secret scanning, SBOM).
  • Encode security controls into infrastructure- and policy-as-code.
  • Help close prototype-to-production gap with secure-by-default systems.
  • Make secure-by-default the norm through internal tooling to automate controls.
  • Build reusable modules and AI-driven tooling for security automation.
  • Partner with corporate security and GRC functions to mature in-house security.

Skills

Security engineering
DevSecOps
Automation
AI/LLM in security
Vulnerability management
SOC 2 knowledge
Cloud security
Scripting/coding

Tools

Terraform
SAST/SCA
Secret scanning
SBOM generation
Prisma Cloud
Wiz
Snyk
Drata
Vanta

Job description

This role is not open to visa sponsorship or transfer of visa sponsorship including those on H1-B, F-1, OPT, STEM-OPT, or TN visa, nor is it available to work corp-to-corp.

  • This role is open to remote or hybrid candidates (East Coast preference), with hybrid being central to our New York, NY or Charlotte area offices. Must be able to work Eastern Standard Time hours.

For the Bankrate website click here. Curious how Bankrate fits into Red Ventures? Click here.

Platform Engineering builds the foundations our product teams ship on — deployment, infrastructure, and security. We're hiring a DevSecOps Engineer to be the technical owner of our security posture and a force multiplier for every engineer at the company. This is a build-the-function role, not a ticket-taking role. You'll treat security as code, bake it into the development lifecycle, and automate the toil away so teams can ship fast and safely. You'll have unusually broad ownership and unusually high impact.

What You’ll Do
  • Own the engineering side of our compliance program (SOC 2 Type 2): implementing controls, collecting evidence, and keeping us audit-ready.
  • Operate our compliance automation platform — integrations, evidence pipelines, and mapping controls to real implementation.
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails so passing audits doesn't slow product delivery.
  • Own cloud security posture management and runtime security tooling: posture monitoring, container and IaC scanning, and runtime coverage across our environment.
  • Triage and remediate findings against demanding SLAs, and design the automation and alerting that keeps pace with volume manual effort can't.
  • Build auto-remediation workflows — including AI-assisted pipelines — that detect, file, and (where safe) fix findings with minimal human intervention.
  • Build and maintain CI/CD security gates: SAST/SCA, secret scanning, SBOM generation, dependency management, and container/IaC scanning — implemented as reusable pipeline components and enforced through automated policy.
  • Encode security and compliance controls into infrastructure-as-code and policy-as-code so the easy path is the secure path.
  • Help close the prototype-to-production gap: turn fast-moving prototypes into production-grade, secure-by-default systems with automated guardrails.
  • Make secure-by-default the norm through our internal tooling, so the right controls are applied automatically rather than relying on engineers to remember.
  • Build the automation the team runs on — reusable modules, pipeline components, and AI/agentic tooling that turn manual security work into self-service capability.
  • Partner with corporate security and GRC functions while building and maturing our in-house security capability, so the team can make sound security decisions quickly and independently
What We’re Looking For
  • 5+ years in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus (Staff level: 8+ years and a track record of building security functions or programs).
  • Deep hands-on cloud security experience (compute, networking, IAM, key management, logging) on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: building pipeline security controls (SAST/SCA, secret scanning, dependency and container scanning) into developer workflows.
  • Hands-on vulnerability management at scale: triage, prioritization, SLA-driven remediation, and the automation to make it sustainable.
  • Working knowledge of SOC 2 (or comparable frameworks) and what it takes to implement and evidence controls in a real engineering environment.
  • Fluency with the categories of modern cloud security tooling — CSPM, ASPM/SAST and secret scanning, compliance automation, and SIEM (e.g., tools such as Wiz, Prisma Cloud, Snyk, Drata, Vanta, or equivalents).
  • Strong coding/scripting ability to build automation, not just configure tools — you write the pipelines, modules, and tooling that scale security across many services.
  • Experience standing up or maturing an in-house security function.
  • Multi-cloud exposure and experience securing an internal developer platform.
  • Security monitoring and detection/alerting design.
  • Experience applying AI/LLM tooling to security operations — auto-remediation, evidence generation, agentic workflows.
Compensation

Total Cash Compensation Range: $150,000 – $225,000 per year

Actual compensation varies based on location, experience, and qualifications.

Benefits
  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program
  • Flexible Paid Time Off (PTO): We believe time to rest and recharge is essential. That’s why we offer a generous and flexible PTO policy. Full-time employees accrue 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.
Who We Are

Bankrate is where Americans go to get the best price on life's most important financial decisions. By combining proprietary data, advanced technology, and deep market coverage, Bankrate helps consumers compare options and make confident financial choices across mortgages, credit cards, savings, and more. As a rate provider to the Federal Reserve and the benchmark relied upon by major publishers and policymakers nationwide, Bankrate's rate data is the national standard. This commitment to precision is reflected across all its products. In mortgages, proprietary auction technology puts lenders in real-time competition on price alone, consistently delivering rates in the lowest 10% in the country. For deposits, the platform features exclusively top-tier rates in the top 10% nationally, while its credit card coverage encompasses more than 90% of the market by volume. Founded by a journalist, Bankrate remains dedicated to its founding mission of transparency, honest information, and real competition — helping to make the American dream more affordable for everyone.

Red Ventures is an equal opportunity employer that does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or any other basis protected by law. Employment at Red Ventures is based solely on a person's merit and qualifications.

We are committed to providing equal employment opportunities to qualified individuals with disabilities. This includes providing reasonable accommodation where appropriate. Should you require a reasonable accommodation to apply or participate in the job application or interview process, please contact accommodation@redventures.com.

If you are based in California, we encourage you to read this important information for California residents linked here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer | Bankrate
Staff DevSecOps Engineer | Bankrate

Socket.dev • United States

Hybrid
USD 150,000 - 225,000
Health Insurance Coverage (medical, 3)
Life Insurance
Disability Insurance
+4
Senior Software Engineer
Senior Software Engineer

Bankrate • United States

Hybrid
USD 100,000 - 195,000
Health Insurance Coverage (medical, .)
Life Insurance
Disability Insurance
+2
Forward Deployed Engineer | Bankrate
Forward Deployed Engineer | Bankrate

Bankrate • United States

Hybrid
USD 100,000 - 195,000
Health Insurance Coverage (medical, d
Life Insurance
Disability Insurance
+6
Staff Engineer | Bankrate
Staff Engineer | Bankrate

Bankrate • United States

Hybrid
USD 130,000 - 210,000
Health Insurance Coverage
Life Insurance
Short and Long-Term Disability Insurance
+4
Forward Deployed Engineer | Bankrate
Forward Deployed Engineer | Bankrate

Red Ventures • United States

Hybrid
USD 100,000 - 195,000
Health Insurance Coverage (medical, d​
Life Insurance
Disability Insurance
+6
Staff Engineer | Bankrate
Staff Engineer | Bankrate

Red Ventures • United States

Hybrid
USD 130,000 - 210,000
Health Insurance
Life Insurance
Disability Insurance
+2
Senior AI Product Manager | Bankrate
Senior AI Product Manager | Bankrate

Bankrate • United States

Hybrid
USD 155,000 - 220,000
Health Insurance Coverage (medical, is
Engineering Manager | Bankrate
Engineering Manager | Bankrate

Bankrate • United States

On-site
USD 160,000 - 210,000
Health Insurance Coverage
Life Insurance
Disability Insurance
+5
Information Security Engineer | Corporate Technology
Information Security Engineer | Corporate Technology

Red Ventures • Town of Charlotte (NY)

On-site
CAD 138,000 - 207,000
Health Insurance
Life Insurance
Disability Insurance
+6
Engineering Manager
Engineering Manager

Red Ventures • New York (NY)

Hybrid
USD 160,000 - 210,000