×
Register Here to Apply for Jobs or Post Jobs. X

Senior DevSecOps Engineer

Job in Sugar Land, Fort Bend County, Texas, 77479, USA
Listing for: HCSS
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below

We are HCSS. For the last 40 years, we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer.

We have earned Best Companies to Work for in Texas honors for 18consecutive years and have been named a USA Today Top Workplace. HCSS has also been recognized by Built In as a Best Place to Work in Greater Houston and by Construction Executive for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence.

WHO WE NEED:

As a Senior Dev Ops Engineer specializing in Dev Sec Ops  and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level Dev Ops engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development teams deliver secure software at scale.

Qualifications:
  • Experience: Minimum of 5 years of experience in application security, Dev Sec Ops , or a related field, with a deep focus on secure software development and security testing practices.
  • Cloud Expertise: Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure Dev Ops, and others.
  • Security Tools & Practices: Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., Hashi Corp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
  • Secure Development Lifecycle: In-depth understanding of the secure development lifecycle (SDLC) and Dev Sec Ops  best practices, with experience embedding security into every phase of software development.
  • Vulnerability Management: Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
  • Compliance Knowledge: Familiarity with security and compliance frameworks such as OWASP, NIST, CIS,
  • SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Collaboration & Communication: Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.
Preferred Qualifications:
  • Security

    Certifications:

    Certified in cloud security (e.g., Microsoft Certified:
    Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
  • Threat Modeling
    :
    Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
  • Experience with Microservices & APIs
    :
    Strong understanding of microservices architecture and API security practices.
  • Security Tools:Experience with tools such as Sonar Qube, Veracode, Checkmarx, Snyk, Black Duck, Mend, Git Hub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.
Role Responsibilities:
  • Dev Sec Ops  Integration: Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
  • Application Security Expertise: Lead efforts in identifying, prioritizing, and mitigating security risks and…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary