×
Register Here to Apply for Jobs or Post Jobs. X

DevSecOps Engineer

Job in Denver, Denver County, Colorado, 80285, USA
Listing for: New Charter Technologies, Llc
Full Time position
Listed on 2026-06-06
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Data Security, Security Manager
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
** We believe talent deserves a human touch. Your application will be read by an actual person who’s excited to discover the real you.
**** About the Role
** We are looking for an Dev Sec Ops  Engineer to join our product engineering team. You will serve as the named security function for a team building internal tooling for a portfolio of managed service provider companies, with a roadmap toward a public-facing SaaS product. This role sits inside engineering and works closely with developers and information security day to day.

The team you are joining is experienced and moves quickly. The right person for this role is comfortable operating as a peer to strong engineers, contributing practical security judgment and ensuring overall security of our solutions. As our product matures toward public availability, you will help ensure our security posture scales with it.

You should be comfortable operating in an exploratory, innovation-oriented environment where not everything will become production software. Right-sizing your security posture to the actual risk is a core expectation of this role.
** Key Responsibilities
**** Embedded Security Partnership*
* • Serve as the primary security resource for engineering teams in direct close coordination with information security teams, advising on design decisions, authentication patterns, and API security as features are built rather than after the fact
• Conduct lightweight, developer-friendly threat modeling for new features and services, right-sized to the actual audience and risk profile (internal vs. public-facing)
• Lead collaboration between engineering and information security teams through architecture and code reviews with actionable, specific guidance that helps teams ship, not slow down
• Responsible for remediation and enforcement of security standards as set forth by the information security team
• Define and maintain a tiered security standard that distinguishes expectations for internal tooling vs. production SaaS vs. public-facing products
• Engage constructively with the enterprise security organization, translating between compliance and governance language and the engineering team's operational reality
** Tooling & Automation*
* • Responsible for adherence to Git Hub Advanced Security (GHAS) configuration and security standards through ongoing tuning across code scanning, secret scanning, Dependabot, and security campaigns within Git Hub Enterprise
• Integrate security tooling into CI/CD pipelines as policy-as-code feedback loops, not manual gates
• Develop and maintain Git Hub Actions workflows with reusable, security-enforcing components
• Drive remediation velocity metrics and coverage reporting across engineering teams
** Cloudflare & Azure Security*
* • Collaborate with information security teams to assess and secure workloads across both Cloudflare and Azure, including Cloudflare Workers, Access policies, WAF, and Zero Trust for public-facing infrastructure, and Azure security controls (Managed Identities, Key Vault, Defender, IAM) for internal and opco-facing services
• Apply platform-appropriate security controls as our architecture spans both environments, calibrating to the risk profile of each workload
• Evaluate and harden authentication flows, API security patterns, and service-to-service trust boundaries across Cloudflare and Azure environments
• Contribute to container and cloud workload security as infrastructure patterns evolve
** Development Contributions*
* • Contribute to internal security tooling, automation, and integrations using Python and/or Go
• Build security utilities such as vulnerability aggregation pipelines, policy enforcement tooling, or developer-facing security dashboards
• Collaborate with information security and engineering teams on secure service design patterns, OAuth 2.0/OIDC flows, and API security controls
** Compliance & Risk*
* • Support SOC 2 readiness as the product matures toward public customers, mapping application security controls to Trust Services Criteria
• Triage and prioritize vulnerability findings based on actual business risk rather than CVSS scores alone, distinguishing real issues from noise in a…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary