Search by job, company or skills

I

Principal DevSecOps Engineer (Security Operations)

3-5 Years
new job description bg glownew job description bg glownew job description bg svg
  • Posted 2 days ago
  • Be among the first 10 applicants
Early Applicant

Job Description

Description

Principal DevSecOps Engineer (Security Operations)

Syneos Health is a leading fully integrated biopharmaceutical solutions organization built to accelerate customer success. We translate unique clinical, medical affairs and commercial insights into outcomes to address modern market realities.

Every day we perform better because of how we work together, as one team, each the best at what we do. We bring a wide range of talented experts together across a wide range of business-critical services that support our business. Every role within Corporate is vital to furthering our vision of Shortening the Distance from Lab to Life.

Discover what our 29,000 employees, across 110 countries already know.

WORK HERE MATTERS EVERYWHERE

Why Syneos Health

  • We are passionate about developing our people, through career development and progression supportive and engaged line management technical and therapeutic area training peer recognition and total rewards program.
  • We are committed to our Total Self culture - where you can authentically be yourself. Our Total Self culture is what unites us globally, and we are dedicated to taking care of our people.
  • We are continuously building the company we all want to work for and our customers want to work with. Why Because when we bring together diversity of thoughts, backgrounds, cultures, and perspectives - we're able to create a place where everyone feels like they belong.

Job Responsibilities

Overview

We are seeking a skilledDevSecOpsEngineer to strengthen our software delivery pipelines withsecurity bestpractices, automation, and continuous improvement. The ideal candidate will bridge the gap between development, security, and operations teams, ensuring that our infrastructure and applications are secure, scalable, and efficiently deployed.

You'llbe instrumental in building security guardrails that enable developers to move fast whilemaintainingrobust security posture, creating golden paths that make secure choices the easy choices.

Key Responsibilities

1. Security Integration & Automation

  • Embed security practices into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions).

  • Automate static and dynamic code analysis (SAST/DAST), dependency scanning, and container image scanning.

  • Implement and manage vulnerability scanning tools (e.g.,SonarQube,Snyk).

  • Generate andmaintainSoftware Bill of Materials (SBOM) for applications and container images usingJFrog.

  • ManageJFrogfor secure artifact repository management, binary promotion, and access control.

  • Build developer security tooling including IDE plugins, pre-commit hooks, and local scanning capabilities.

  • Ensure secure configurations across cloud environments and container platforms.

2. Cloud & Infrastructure Security

  • ApplyDevSecOpsprinciples to cloud infrastructure (AWS, Azure, or GCP).

  • Utilize Wiz for cloud security posture management (CSPM), vulnerability management, and compliance monitoring across multi-cloud environments.

  • Implement Infrastructure as Code (IaC) security scanning using Terraform.

  • Enforce policy-as-code using frameworks like Open Policy Agent (OPA),Kyverno, Sentinel.

  • Manage secrets andcredentials securelywith tools like AWS SecretsManager, orAzure Key Vault, or OCI Vault.

  • Design and implement network security controls includingmicrosegmentation, network policies, and zero-trust principles.

  • Implement runtime security and threat detection using container runtime protection tools.

  • Monitor and respond to security incidents in CI/CD and production environments.

3. Platform Engineering & Architecture

  • Build andmaintainsecure platform abstractions (golden paths) that enable developers to deploy securely by default.

  • Design and implement security reference architectures for common patterns (microservices, serverless, data pipelines, API gateways).

  • Implement service mesh security features includingmTLS, traffic encryption, and policy enforcement.

  • Secure API gateways with authentication, authorization, rate limiting, and threat protection.

  • Manage supply chain security including artifact signing, registry security, and SLSA framework implementation.

  • Build security observability through metrics, dashboards, and security-focused SLIs/SLOs.

4. Collaboration & Process Improvement

  • Partner with development and operations teams toidentifyand mitigate security risks early in the SDLC.

  • Participate in code reviews and architecture discussions to ensure security-by-design.

  • Support development teams in remediating vulnerabilities and implementing secure coding practices.

  • Build and lead security champions program to elevate security awareness across engineering teams.

  • Advocate for security automation and continuous improvement, translating security requirements into practical, developer-friendly solutions.

  • Mentor teams on secure development practices and modern security tooling.

5. Compliance & Governance

  • Ensure alignment with security and compliance standards (ISO 27001, SOC 2, HIPAA, GDPR, PCI-DSS, etc.).

  • Contribute tothreat modeling, risk assessments, and security architecture reviews.

  • Maintain audit trails and compliance documentation fordeploymentpipelines.

  • Implement and enforce security policies across the software delivery lifecycle.

Qualifications

Required

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).

  • 3+ years of experience in DevOps, Cloud Engineering, Security Engineering, or Platform Engineering.

  • Strong scripting and automation skills (Python, Bash, PowerShell, Go).

  • Hands-on experience with CI/CD tools (GitHub Actions, Azure DevOps).

  • Proficiencyin containerization (Docker, Kubernetes) and related security tools.

  • Experience with cloud platforms (AWS, Azure, or Oracle) andIaCframeworks (Terraform).

  • Solid understanding of security principles, threat modeling, and the OWASP Top 10.

Preferred

  • Certifications such as:

  • AWS Certified Security Specialty / DevOps Engineer

  • Azure Security Engineer / DevOps Expert

  • Certified Kubernetes Security Specialist (CKS)

  • CISSP, GIAC GSEC, or CertifiedDevSecOpsProfessional

  • Experience with Wiz or similar cloud-native application protection platforms.

  • Experience withJFrogplatform for artifact management and software composition analysis.

  • Experience with policy-as-code frameworks (OPA,Kyverno, Sentinel).

  • Knowledge of supply chain security (SLSA framework, SBOM generation).

  • Experience with monitoring and logging tools (Prometheus, Grafana, Datadog).

  • Understanding of microservicesarchitecture, service mesh, and API security.

  • Familiarity with runtime security.

  • Experience with incident response, SIEM platforms, or SOC processes.

  • Background in secure SDLC methodologies and threat modeling frameworks

Get to know Syneos Health

Over the past 5 years, we have worked with 94% of all Novel FDA Approved Drugs, 95% of EMA Authorized Products and over 200 Studies across 73,000 Sites and 675,000+ Trial patients.

No matter what your role is, you'll take the initiative and challenge the status quo with us in a highly competitive and ever-changing environment. Learn more about Syneos Health.

Additional Information

Tasks, duties, and responsibilities as listed in this job description are not exhaustive. The Company, at its sole discretion and with no prior notice, may assign other tasks, duties, and job responsibilities. Equivalent experience, skills, and/or education will also be considered so qualifications of incumbents may differ from those listed in the Job Description. The Company, at its sole discretion, will determine what constitutes as equivalent to the qualifications described above. Further, nothing contained herein should be construed to create an employment contract. Occasionally, required skills/experiences for jobs are expressed in brief terms. Any language contained herein is intended to fully comply with all obligations imposed by the legislation of each country in which it operates, including the implementation of the EU Equality Directive, in relation to the recruitment and employment of its employees. The Company is committed to compliance with the Americans with Disabilities Act, including the provision of reasonable accommodations, when appropriate, to assist employees or applicants to perform the essential functions of the job.

Summary

We are seeking a skilledDevSecOpsEngineer to strengthen our software delivery pipelines withsecurity bestpractices, automation, and continuous improvement. The ideal candidate will bridge the gap between development, security, and operations teams, ensuring that our infrastructure and applications are secure, scalable, and efficiently deployed. You'llbe instrumental in building security guardrails that enable developers to move fast whilemaintainingrobust security posture, creating golden paths that make secure choices the easy choices.

More Info

Job Type:
Function:
Employment Type:

About Company

INC Research/inVentiv Health has become Syneos Health, the only fully integrated end-to-end clinical and commercial solution organization. We are purpose-built for biopharmaceutical acceleration, creating better, smarter, faster ways to help clients navigate an increasingly complex marketplace. Our new business addresses today&#8217&#x3B;s market realities through clinical and commercial sharing expertise and data and insights to meet the needs of emerging and large global biopharmaceutical companies.

Job ID: 138147733