DevSecOps Engineer / Cyber Engineer
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, Systems Engineer
Employment Type: Full-time
Status: Immediate
About the RoleSignal Hill Technologies is seeking a Dev Sec Ops Engineer / Cyber Engineer to embed security throughout the software development and delivery lifecycle for our government and commercial clients. This is both a hands‑on engineering role and a technical advisory role — you'll build security directly into CI/CD pipelines, assess the applications and infrastructure moving through them, and help our teams ship secure, resilient systems faster.
You’ll work across the hardware‑to‑application stack: reviewing code and pipeline configurations, running and triaging security scans, and partnering with engineering teams so that security is a built‑in property of what we ship - not a gate at the end.
About Signal Hill TechnologiesFounded and led by veteran cyber operators, Signal Hill Technologies delivers advanced cybersecurity solutions to DoD, Intelligence Community, financial services, and critical infrastructure clients, with many years of experience defending both US Government and commercial clients against sophisticated, well‑funded, motivated adversaries. We are relentless about real results and operationally proven expertise. Our mission is to provide the best technical solutions and hands‑on support to address each customer's unique cyber risks.
PositionResponsibilities
- Develop secure software testing and validation procedures for applications moving through the CI/CD pipeline (e.g., Jenkins, Git Hub Actions).
- Integrate and tune SAST/DAST tooling within build and release pipelines; reconcile scan output and validate findings as true positives.
- Perform secure code review and program testing to identify flaws and mitigate vulnerabilities prior to release, applying standards such as OWASP ASVS and the Dev Sec Ops Maturity Model (DSOMM).
- Perform risk analysis — threat, vulnerability, and probability of occurrence — whenever an application or system undergoes a major change.
- Address security implications across the software acceptance phase, including completion criteria, risk acceptance and documentation, and independent testing methods.
- Prepare security assessment and authorization documentation and communicate findings and secure‑coding guidance clearly to both technical and non‑technical stakeholders.
- Consult with engineering and development staff to evaluate the interface between hardware, software, and infrastructure, and to identify security issues around steady‑state operation and end‑of‑life management.
- Support the development and refinement of Dev Sec Ops processes, pipeline security gates, and reporting standards.
- Public Trust eligible (U.S. citizenship or green card required and ability to pass a background investigation).
- Minimum of 6 years of relevant cybersecurity/Dev Sec Ops engineering experience, including at least 2 years of hands‑on application security experience.
- Proficiency in Dev Sec Ops concepts, including CI/CD pipelines, Jenkins and/or Git Hub Actions, and SAST/DAST integration and automation.
- Scripting proficiency in Python and/or Power Shell.
- Experience with systems integration, including APIs, API security, and databases.
- Strong collaborative and interpersonal skills, with the ability to clearly communicate technical findings and secure‑coding guidance to both technical and non‑technical audiences.
- Working knowledge of cybersecurity and privacy principles, risk management processes, and common system/application vulnerabilities (e.g., injection, buffer overflow, cross‑site scripting).
- Hands‑on experience with code analysis and vulnerability scanning tools (e.g., Burp Suite Professional or similar SAST/DAST tooling).
- Bachelor's degree in Computer Science, Cybersecurity Engineering, Computer Engineering, Systems Engineering, Computer Information Systems, or a related field.
- Cloud security engineering experience in AWS and/or Azure, including IAM policy and configuration.
- Familiarity with infrastructure automation and configuration management tooling (e.g., Ansible, Terraform).
- Familiarity with the Risk Management Framework and related security/privacy controls (NIST SP 800-37,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).