Senior DevSecOps Engineer; AppSec focus
Listed on 2026-05-24
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, Data Security
Job Description
One of our top financial customers is seeking a Senior Dev Sec Ops Engineer (Application Security Focus) to build and integrate application security solutions across the SDLC. This role is centered around Dev Sec Ops , CI/CD pipeline security, and tool orchestration.
As a senior member of the Cyber Engineering Team, you will be responsible for the stand up and integration of SAST/DAST/security tooling, building custom integrations, and creating a centralized, contextualized view of vulnerabilities across tools and environments for the enterprise. The role requires strong ownership in bridging security findings to developer remediation and shaping scalable Dev Sec Ops workflows.
Key Responsibilities- Supporting evaluation and implementation of DAST/Web App security tools (POCs, onboarding)
- Enhancing security-focused CI/CD pipelines (SAST, DAST, secrets scanning)
- Building orchestration across tools, pipelines, and environments to improve visibility and prioritization of vulnerabilities
- Collaborating closely with security and engineering teams to refine workflows and security processes
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.
If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy:
- 7+ years development experience, including 3+ years in Application Security / Dev Sec Ops
- Strong backend/full stack engineering (non-UI, hands-on builder mindset)
- Deep experience with CI/CD pipelines and secure SDLC practices
- Hands-on integration of: SAST, DAST / web app scanning, and Secrets detection
- Ability to correlate, contextualize, and operationalize vulnerabilities across tools
- Must have experience with the below technologies listed in the ‘Core Tech Stack’ section and direct engineering ownership of the key technical responsibilities outlined in the “Engineering + Security Practices” section.
- Languages:
Python (preferred), Type Script, Java - Cloud & Containers: AWS, Kubernetes, Docker (Docker file, Docker Compose)
- IaC:
Terraform - CI/CD & SCM:
Git Hub, Git Hub Actions, Git Hub Workflows, Git Ops - APIs: REST / HTTP service development
- Data: SQL & No
SQL - Focus:
Pipeline integration, tool orchestration, vulnerability aggregation
- Translate security requirements into Dev Ops implementations
- Build custom integrations and orchestration layers
- Experience with testing for resiliency/security
- Strong debugging/troubleshooting across app + pipeline + security tooling
- Solid App Sec best practices and cross-team collaboration - Experience evaluating/implementing DAST tools (POCs, vendor selection), highly preferred
- Experience working in a highly regulated environment, finance and government highly preferred.
- Building end-to-end vulnerability aggregation/reporting platforms
- Experience in multi-pipeline / complex Dev Ops environments
- Experience mentoring engineers or contributing to engineering standards/frameworks
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).