DevSecOps Engineer
Listed on 2026-01-02
-
IT/Tech
Cybersecurity, Systems Engineer
Who We Are:
At Avnet, relationships matter. We are a global, FORTUNE ® 500 technology distributor and solutions company that delivers design, supply chain and logistics expertise to customers at every stage of a product’s lifecycle. Our employees have a front row seat to the latest innovations shaping the world we live in and the future we share. We’re driven to help our customers around the world succeed and we do so by earning the trust of some of the biggest names in technology.
Working at Avnet means being a part of a global team. We work collaboratively and with integrity, doing business the right way. For more than a century, we have partnered together to help our customers, suppliers and teammates realize the transformative possibilities of technology. Experience what’s next at Avnet!
* Applicants for this position must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment visa at this time*
We are seeking a highly autonomous and hands‑on Dev Sec Ops / Application Security Engineer to champion security integration across our global application ecosystem. This role sits at the intersection of application security, software engineering, and cloud automation.
You will be responsible for assisting in the design, implementation, and scaling of security controls throughout the Software Development Lifecycle (SDLC), primarily focusing on securing Azure‑native services and driving cultural change toward secure‑by‑default practices among global development and architecture teams.
Principal Responsibilities:- Pipeline Security Automation: Design, implement, and centrally manage advanced security tooling (SAST, DAST, SCA, Secrets Management) directly within high‑volume Git Hub Actions and Git Lab CI/CD pipelines.
- Azure Cloud Security Engineering: Engineer and enforce security controls for our Azure‑native services (e.g., AKS, Azure Functions, App Services), with a strong emphasis on Managed Identities, Azure Policy, Defender for Cloud, and securing the networking perimeter (e.g., App Gateway WAF).
- Secure Design & Governance: Lead threat modeling sessions and security design reviews for net‑new, large‑scale applications. Design and operationalize security guardrails aligned with enterprise standards (OWASP API Security, NIST, PCI‑DSS).
- Vulnerability Remediation &
Coaching:
Drive the end‑to‑end vulnerability lifecycle, from discovery (e.g., coordinating with Red Teams/Bug Bounty) to defining clear, actionable security‑focused remediation guidance for development teams. - IaC Security: Embed security checks and best practices into our Infrastructure‑as‑Code workflows, primarily using Terraform or Bicep.
- Identity & Access Management: Define and implement robust access controls and key management strategies utilizing Azure Key Vault and cloud‑native identity solutions.
- Other duties as assigned
- Cloud Depth: Hands‑on experience securing production workloads in the Microsoft Azure ecosystem. Deep familiarity with key services like AKS, Azure Functions, App Services, and Azure Firewall/WAF.
- CI/CD Mastery: Demonstrated expertise automating security controls (scanning, gating, posture checks) within Git Hub Actions and/or Git Lab CI/CD.
- Security Knowledge: Strong, actionable knowledge of the OWASP Top 10/API Security and aligning practices to standards like NIST 800‑53.
- Automation: Proficiency in Python, Power Shell, or Bash for creating security automation, custom checks, and tool integration.
- Tooling: Working experience with modern enterprise security tools (e.g., Snyk, Checkmarx, Prisma Cloud, Git Hub Advanced Security, or ASPM platforms).
- Container Security: Practical experience with container runtime security and posture management (e.g., Defender for Containers, Falco).
- Typically, 8+ years with bachelor's or equivalent.
- Bachelor's degree or equivalent experience from which comparable knowledge and job skills can be obtained.
- Generous Paid Time Off
- 401K and Pension Plan
- Paid Holidays
- Family Support (Paid Leave, Surrogacy, Adoption)
- Medical, Dental, Vision, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).