×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps Engineer

Job in Columbus, Franklin County, Ohio, 43224, USA
Listing for: Socket.dev
Full Time position
Listed on 2026-09-20
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection, Systems Engineer
Salary/Wage Range or Industry Benchmark: 110000 - 160000 USD Yearly USD 110000.00 160000.00 YEAR
Job Description & How to Apply Below

Description

About

At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives.

Position Summary

We are seeking a Dev Sec Ops  Engineer to integrate security into the organization's software development and delivery processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards.

This role partners closely with Software Engineering, Platform Engineering, Dev Ops, and Security teams to build security controls directly into CI/CD pipelines, development workflows, infrastructure-as-code, container environments, and application delivery processes. Rather than operating as a final security checkpoint, the Dev Sec Ops  Engineer helps engineering teams identify and address security issues earlier in the development lifecycle while building scalable security automation that allows teams to move quickly without sacrificing security.

Key Responsibilities Secure Software Development
  • Integrate security controls into the software development lifecycle.
  • Partner with engineering teams to establish practical secure development standards.
  • Help developers identify and remediate application security vulnerabilities.
  • Provide technical guidance on secure coding practices and common vulnerability classes.
  • Support security reviews for new applications, services, APIs, and major architectural changes.
CI/CD Security
  • Design and implement automated security testing within CI/CD pipelines.
  • Implement and manage capabilities such as:
  • Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA)
  • Secret scanning
  • Container image scanning
  • Infrastructure-as-Code scanning
  • Dependency and package vulnerability detection
  • Develop appropriate security gates for build and deployment pipelines.
  • Reduce alert fatigue by correlating and de-duplicating vulnerability signals across Dependabot, Vanta, and Tenable, escalating only when standard remediation timelines are at risk of being missed.
  • Work with engineering teams to ensure security controls minimize unnecessary friction.
Application and API Security
  • Evaluate applications and APIs for common security weaknesses.
  • Help establish secure API authentication and authorization patterns.
  • Support threat modeling for applications and new engineering initiatives.
  • Assist engineering teams with remediation of application security findings.
  • Identify systemic security issues that can be addressed through reusable controls or engineering patterns.
Infrastructure-as-Code and Automation
  • Review Terraform, Cloud Formation, Kubernetes manifests, and similar infrastructure definitions for security risks.
  • Develop automated controls that detect insecure infrastructure configurations before deployment.
  • Create reusable secure infrastructure patterns and guardrails.
  • Build security automation using scripting, APIs, and cloud-native services.
Container and Kubernetes Security
  • Help establish security standards for containers and Kubernetes environments.
  • Support container image security, workload configuration, secrets management, and runtime security.
  • Identify insecure deployment patterns and help engineering teams adopt safer alternatives.
  • Support the security review of the planned migration from Heroku to , including secrets handling, network posture, and changes to the deployment model.
  • Design a synthetic or de-identified data seeding strategy to enable…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary