Job Summary
We are seeking a seasoned Senior DevOps / DevSecOps Security Engineer with 8–10+ years of experience to lead vulnerability remediation initiatives—specifically on BitSight-identified security issues—across SaaS and public cloud environments. The ideal candidate will be highly hands-on, with deep experience in vulnerability analysis, remediation guidance, and security engineering within CI/CD and cloud operations contexts.
This role will work closely with Engineering, DevOps, and Security teams to drive actionable remediation, embed security into infrastructure and development pipelines, and enhance overall security posture.
Key Responsibilities
Security Vulnerability Remediation & Management
- Lead hands-on remediation of vulnerabilities identified by BitSight and other security assessment tools.
- Triage, verify, and resolve security findings across cloud services, containers, microservices, and SaaS products.
- Prioritize vulnerabilities based on risk, exploitability, and business impact with clear mitigation plans.
- Collaborate with DevOps, engineering, and product teams to ensure timely remediation and secure deployments.
DevSecOps Integration
- Embed security controls, automated checks, and scanning throughout the CI/CD pipelines (DevOps + DevSecOps).
- Integrate BitSight outputs into internal vulnerability workflows and dashboards.
- Automate security test execution in build and release workflows.
Cloud & Infrastructure Security
- Design, implement, and secure environments in AWS, Azure, or GCP.
- Harden cloud infrastructure and services, ensuring compliance with security best practices and organizational standards.
Tooling, Automation & Reporting
- Build automation for vulnerability detection, verification, and remediation.
- Maintain security tooling, vulnerability scanners, and reporting frameworks.
- Provide regular leadership reporting (metrics, trends, risk dashboards).
Cross-functional Collaboration
- Work with engineering teams to implement secure design principles and support secure coding.
- Guide remediation approaches, safe configuration changes, and risk reduction strategies.
- Partner with Product and Security teams to embed security into the development lifecycle.
Required Skills & Expertise
Technical Skills
- 8–10+ years in DevOps, DevSecOps, Security Engineering, or related roles.
- Strong experience with BitSight vulnerability identification and remediation workflows (or similar SaaS security rating/scan platforms).
- Deep hands-on experience with vulnerability management and remediation in cloud & SaaS environments.
- Expertise with CI/CD automation (Jenkins, GitHub Actions, GitLab CI, Azure DevOps, etc.).
- Experience with cloud security: AWS/Azure/GCP (IAM, networking, logging, security services).
- Infrastructure as Code (IaC) security: Terraform, CloudFormation.
- Scripting and automation skills: Python, Bash, PowerShell, etc.
- Strong grasp of vulnerability assessment and scanning tools (SAST, DAST, SCA, container security scanners).
- Solid understanding of security frameworks and best practices (OWASP, NIST, CIS).
Qualifications & Certifications (Preferred)
- Bachelor's degree in CS, IT, Cybersecurity, or equivalent.
- Security certifications such as:
- CISSP, CISM
- AWS Certified Security Specialty
- GIAC/GSEC
- Certified DevSecOps Professional (if available)