
Search by job, company or skills
Description
Principal DevSecOps Engineer (Security Operations)Syneos Health is a leading fully integrated biopharmaceutical solutions organization built to accelerate customer success. We translate unique clinical, medical affairs and commercial insights into outcomes to address modern market realities.
Every day we perform better because of how we work together, as one team, each the best at what we do. We bring a wide range of talented experts together across a wide range of business-critical services that support our business. Every role within Corporate is vital to furthering our vision of Shortening the Distance from Lab to Life.
Discover what our 29,000 employees, across 110 countries already know.
WORK HERE MATTERS EVERYWHERE
Why Syneos Health
Job Responsibilities
Overview
We are seeking a skilledDevSecOpsEngineer to strengthen our software delivery pipelines withsecurity bestpractices, automation, and continuous improvement. The ideal candidate will bridge the gap between development, security, and operations teams, ensuring that our infrastructure and applications are secure, scalable, and efficiently deployed.
You'llbe instrumental in building security guardrails that enable developers to move fast whilemaintainingrobust security posture, creating golden paths that make secure choices the easy choices.
Key Responsibilities
1. Security Integration & Automation
Embed security practices into CI/CD pipelines (e.g., Azure DevOps, GitHub Actions).
Automate static and dynamic code analysis (SAST/DAST), dependency scanning, and container image scanning.
Implement and manage vulnerability scanning tools (e.g.,SonarQube,Snyk).
Generate andmaintainSoftware Bill of Materials (SBOM) for applications and container images usingJFrog.
ManageJFrogfor secure artifact repository management, binary promotion, and access control.
Build developer security tooling including IDE plugins, pre-commit hooks, and local scanning capabilities.
Ensure secure configurations across cloud environments and container platforms.
2. Cloud & Infrastructure Security
ApplyDevSecOpsprinciples to cloud infrastructure (AWS, Azure, or GCP).
Utilize Wiz for cloud security posture management (CSPM), vulnerability management, and compliance monitoring across multi-cloud environments.
Implement Infrastructure as Code (IaC) security scanning using Terraform.
Enforce policy-as-code using frameworks like Open Policy Agent (OPA),Kyverno, Sentinel.
Manage secrets andcredentials securelywith tools like AWS SecretsManager, orAzure Key Vault, or OCI Vault.
Design and implement network security controls includingmicrosegmentation, network policies, and zero-trust principles.
Implement runtime security and threat detection using container runtime protection tools.
Monitor and respond to security incidents in CI/CD and production environments.
3. Platform Engineering & Architecture
Build andmaintainsecure platform abstractions (golden paths) that enable developers to deploy securely by default.
Design and implement security reference architectures for common patterns (microservices, serverless, data pipelines, API gateways).
Implement service mesh security features includingmTLS, traffic encryption, and policy enforcement.
Secure API gateways with authentication, authorization, rate limiting, and threat protection.
Manage supply chain security including artifact signing, registry security, and SLSA framework implementation.
Build security observability through metrics, dashboards, and security-focused SLIs/SLOs.
4. Collaboration & Process Improvement
Partner with development and operations teams toidentifyand mitigate security risks early in the SDLC.
Participate in code reviews and architecture discussions to ensure security-by-design.
Support development teams in remediating vulnerabilities and implementing secure coding practices.
Build and lead security champions program to elevate security awareness across engineering teams.
Advocate for security automation and continuous improvement, translating security requirements into practical, developer-friendly solutions.
Mentor teams on secure development practices and modern security tooling.
5. Compliance & Governance
Ensure alignment with security and compliance standards (ISO 27001, SOC 2, HIPAA, GDPR, PCI-DSS, etc.).
Contribute tothreat modeling, risk assessments, and security architecture reviews.
Maintain audit trails and compliance documentation fordeploymentpipelines.
Implement and enforce security policies across the software delivery lifecycle.
Qualifications
Required
Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
3+ years of experience in DevOps, Cloud Engineering, Security Engineering, or Platform Engineering.
Strong scripting and automation skills (Python, Bash, PowerShell, Go).
Hands-on experience with CI/CD tools (GitHub Actions, Azure DevOps).
Proficiencyin containerization (Docker, Kubernetes) and related security tools.
Experience with cloud platforms (AWS, Azure, or Oracle) andIaCframeworks (Terraform).
Solid understanding of security principles, threat modeling, and the OWASP Top 10.
Preferred
Certifications such as:
AWS Certified Security Specialty / DevOps Engineer
Azure Security Engineer / DevOps Expert
Certified Kubernetes Security Specialist (CKS)
CISSP, GIAC GSEC, or CertifiedDevSecOpsProfessional
Experience with Wiz or similar cloud-native application protection platforms.
Experience withJFrogplatform for artifact management and software composition analysis.
Experience with policy-as-code frameworks (OPA,Kyverno, Sentinel).
Knowledge of supply chain security (SLSA framework, SBOM generation).
Experience with monitoring and logging tools (Prometheus, Grafana, Datadog).
Understanding of microservicesarchitecture, service mesh, and API security.
Familiarity with runtime security.
Experience with incident response, SIEM platforms, or SOC processes.
Background in secure SDLC methodologies and threat modeling frameworks
Get to know Syneos Health
Over the past 5 years, we have worked with 94% of all Novel FDA Approved Drugs, 95% of EMA Authorized Products and over 200 Studies across 73,000 Sites and 675,000+ Trial patients.
No matter what your role is, you'll take the initiative and challenge the status quo with us in a highly competitive and ever-changing environment. Learn more about Syneos Health.
Additional Information
Tasks, duties, and responsibilities as listed in this job description are not exhaustive. The Company, at its sole discretion and with no prior notice, may assign other tasks, duties, and job responsibilities. Equivalent experience, skills, and/or education will also be considered so qualifications of incumbents may differ from those listed in the Job Description. The Company, at its sole discretion, will determine what constitutes as equivalent to the qualifications described above. Further, nothing contained herein should be construed to create an employment contract. Occasionally, required skills/experiences for jobs are expressed in brief terms. Any language contained herein is intended to fully comply with all obligations imposed by the legislation of each country in which it operates, including the implementation of the EU Equality Directive, in relation to the recruitment and employment of its employees. The Company is committed to compliance with the Americans with Disabilities Act, including the provision of reasonable accommodations, when appropriate, to assist employees or applicants to perform the essential functions of the job.
Summary
We are seeking a skilledDevSecOpsEngineer to strengthen our software delivery pipelines withsecurity bestpractices, automation, and continuous improvement. The ideal candidate will bridge the gap between development, security, and operations teams, ensuring that our infrastructure and applications are secure, scalable, and efficiently deployed. You'llbe instrumental in building security guardrails that enable developers to move fast whilemaintainingrobust security posture, creating golden paths that make secure choices the easy choices.INC Research/inVentiv Health has become Syneos Health, the only fully integrated end-to-end clinical and commercial solution organization. We are purpose-built for biopharmaceutical acceleration, creating better, smarter, faster ways to help clients navigate an increasingly complex marketplace. Our new business addresses today’s market realities through clinical and commercial sharing expertise and data and insights to meet the needs of emerging and large global biopharmaceutical companies.
Job ID: 138147707