DevSecOps Engineer - Information Security
Listed on 2026-07-17
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing: Infrastructure & Operations
Dev Sec Ops Engineer – Information Security
Location:
Associates must be in-office 1–2 days per week, with alternate locations considered for candidates within commuting distance. This position is not eligible for current or future visa sponsorship.
Job Level: Non‑Management Exempt
Workshift: 1st Shift (United States of America)
Job Family: IFT > IT Security & Compliance
- Lead the design and implementation of Dev Sec Ops solutions integrated into CI/CD pipelines (Git Hub, Git Lab, Jenkins)
- Define and implement secure SDLC practices, including automated testing, threat modeling, and secure coding standards
- Own and optimize CNAPP platforms (e.g., Wiz, Prisma Cloud) to improve cloud security posture and workload protection
- Drive vulnerability management strategy, including risk‑based prioritization and integration into developer workflows
- Integrate and tune App Sec tools (SAST, DAST, SCA, container scanning) for scalable pipeline adoption
- Establish guardrails for AI‑generated code security, including validation of outputs and mitigation of risks such as insecure code patterns and data exposure
- Embed security controls into AI‑enabled applications and APIs, addressing emerging risks (e.g., prompt injection, model misuse)
- Partner with engineering teams to reduce vulnerability backlog and MTTR
- Define KPIs and reporting for security posture, pipeline coverage, and risk reduction
- Serve as a technical advisor and escalation point for complex security and integration challenges
- Lead system and network architecture support for information and network security technologies
- Lead development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations
- Lead the development of requirements, system architecture, and software design of security products and services
- Develop security incident response plans and strategies
- Provide trouble resolution and serve as point of technical escalation on complex problems
- Create presentations and seek IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise
- Minimum: BS/BA in information technology or related field and at least 8 years of experience in systems administration and security aspects of information systems, access management, network security technologies, computer networking, telecommunications, systems development and management, hardware, software, data, and people. Equivalent education and experience may be substituted.
- Preferred:
Experience in Dev Sec Ops (e.g., Harness pipelines), Application Security, Cloud Security, or related fields - Hands‑on experience integrating security into CI/CD pipelines at scale
- Experience with Jfrog Artifactory, Xray, and Curation
- Experience with CNAPP platforms such as Wiz or Prisma Cloud
- Strong knowledge of Application Security (SAST, DAST, SCA, API security) and Cloud Security (AWS, Azure, or GCP)
- Experience with containers & Kubernetes security
- Experience in vulnerability management and risk prioritization
- Experience securing AI/LLM‑enabled applications or AI‑assisted development workflows
- Familiarity with AI security risks (e.g., OWASP Top
10 for LLMs, prompt injection, data leakage) - Experience with tools such as Snyk, Checkmarx, Veracode, Sonar Qube
- Strong understanding of Dev Ops and Agile practices
- Security certifications such as CISSP, CCSP, CSSLP (preferred)
Elevance Health is an Equal Employment Opportunity employer, and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).