Senior DevSecOps/Application Security Engineer
Listed on 2026-05-26
-
IT/Tech
Cybersecurity, Data Security, Security Manager
Description
Onsite in Fenton Cary, NC
We are seeking a Senior Dev Sec Ops / Application Security Engineer to join a modern Information Security organization supporting rapidly evolving development environments. This role sits at the intersection of application security, developer enablement, and automation, with a strong mandate to embed security directly into how software and AI-driven solutions are built, tested, and deployed.
As a senior technical contributor, you will focus on securing code, development pipelines, and AI-enabled applications while helping establish governance and standardized security controls across teams that are increasingly writing and deploying their own code. This is a hands‑on role for someone who can both build and advise—balancing strong security controls with developer efficiency and delivery velocity.
This is a full‑time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a W2 basis.
Salary: $122,000 - $145,000/ yr. w2 + benefits
Responsibilities- Embed security controls into application development workflows
, CI/CD pipelines, and code repositories - Support and guide developers on secure coding practices and secure build processes
- Drive automation and policy-as-code to enforce security requirements consistently
- Secure modern, AI-enabled applications and assess risks introduced by AI in development workflows
- Improve security prioritization and efficiency through automation and intelligent tooling
- Design and implement secure CI/CD pipelines with automated controls such as:
- Static and Dynamic Application Security Testing (SAST/DAST)
- Software Composition Analysis (SCA)
- Secrets scanning and code integrity checks
- Infrastructure-as-Code (IaC) and container image scanning
- Secure code repositories by enforcing:
- Branch protections and access controls
- Commit signing, code integrity, and version control governance
- Prevent insecure code usage or data exposure (e.g., sensitive data pushed to public repositories)
- Implement and maintain policy-as-code frameworks to enforce security standards automatically
- Secure the software supply chain, including:
- Dependency validation
- SBOM generation
- Validation of third‑party and purchased software
- Establish standardized security guardrails as more teams begin building and deploying code
- Ensure data is encrypted at rest and handled securely across development environments
- Partner with identity and data protection teams to strengthen:
- Identity and access controls (IAM)
- Data Loss Prevention (DLP) practices within development workflows
- Evaluate risks introduced by AI in software development and application design
- Help define and implement controls for secure AI‑driven applications
- Leverage AI to enhance security monitoring, prioritization, or automation
- Interest in candidates who can write code and potentially build secure prompting or automation solutions
- 7+ years of experience in Dev Sec Ops , application security, security engineering, or platform engineering
- Experience with cloud‑native and modern development environments, including containers and infrastructure‑as‑code
- Strong scripting or automation experience (e.g., Python, Power Shell, Bash)
- Proven ability to translate security requirements into scalable, automated technical controls
- Practical experience with repository platforms such as Git Hub, Git Lab, Azure Dev Ops, or Bitbucket and related security governance.
- Deep experience with containers (Docker), Kubernetes, and IaC tools including Terraform, ARM, and AWS Cloud Formation.
- Strong understanding of software supply chain security, dependency management, and SBOM practices.
- Experience implementing policy-as-code using Azure Policy, AWS Config, OPA, or similar tools.
- Proficiency with scripting and automation such as Python, Power Shell, and Bash and Dev Ops tooling like Jenkins, Git Hub Actions, and Azure Pipelines.
- Strong understanding of SDLC and operationalizing controls in engineering environments.
Strong hands‑on experience securing:
- Code repositories (e.g., Git Hub, Git Lab, Azure Dev Ops)
- CI/CD pipelines and developer platforms
- Approximately 5% travel.
Bachelor’s degree in Computer Science, Engineering, Information Security, or a related field (or equivalent practical experience)
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).