Confirmed on the employer's own hiring board on Oct 6, 2026. First seen by Alion on Oct 6, 2026.
Description
Curious about what it’s like to work at Cognyte?
At Cognyte, you’ll collaborate with expert colleagues around the globe to solve problems most people will never even know exist!
You’ll be part of building unique solutions shaped by real investigative methodologies, enabling our customers to identify, investigate, visualize and prevent criminal, terror and security threats worldwide.
These solutions are used by law enforcement, national security, and national and military intelligence agencies in almost 100 countries to turn massive, diverse data into clear, actionable intelligence for a safer world.
As a DevSecOps Engineer, you will work closely with architecture, development, and operations teams to make security a shared responsibility across all stages of software development and deployment.
Your primary responsibility will be implementing on-prem security best practices, testing, and automation tools into CI/CD pipelines and production environments using industry-standard tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and other security mechanisms.
As a Cognyter you will:
- Security Integration into DevOps: Collaborate with development, architecture and operations teams to integrate security practices throughout the software development lifecycle, from source code to production deployment.
- CI/CD & Supply Chain Security: Implement and manage automated security controls across CI/CD pipelines, dependencies, container images, artifacts and registries, including vulnerability scanning, SBOM generation and artifact validation.
- Security Testing: Implement and operate SAST, DAST, SCA and container security tools, analyze findings, prioritize vulnerabilities and drive remediation with development teams.
- Cloud-Native & Kubernetes Security: Strengthen Kubernetes and OpenShift environments through RBAC, secrets management, admission policies, workload security, network policies and security best practices.
- Automation & Process Improvement: Continuously improve and automate security processes, controls and guardrails while minimizing manual intervention and improving developer experience.
- Lead: Take ownership of DevSecOps security activities, coordinating with relevant development and operations teams to ensure effective implementation, execution and continuous improvement.
- Recommend Architecture and Technologies: Identify security gaps and recommend appropriate architectures, technologies, tools and controls to strengthen secure and scalable software delivery, including disconnected and air-gapped environments.
Requirements
For that mission you will need:
- 4+ years of experience in DevSecOps, application security, platform security or a similar role integrating security into CI/CD and software delivery processes.
- Proven hands-on experience implementing security tools such as SAST, DAST, SCA, container scanning and vulnerability management solutions.
- Strong knowledge of software supply-chain security, including dependencies, SBOM, container images, trusted registries, artifact signing or verification and secure artifact promotion.
- Hands-on experience with CI/CD technologies and scripting such as Jenkins, Git, Python, Bash and Groovy.
- Strong experience with Kubernetes and on-prem cloud-native platforms, including Helm, Kustomize, RBAC, secrets, networking, cluster troubleshooting and workload security.
- Experience implementing security solutions in air-gapped or disconnected environments.
- Familiarity with Infrastructure as Code and automation tools such as Terraform and Ansible.
- Knowledge of CIS benchmarks, Linux hardening, Kubernetes security practices and secure configuration management.
- Experience with secrets management, certificates, PKI and secure credential handling.
- In-depth knowledge of application and infrastructure vulnerabilities, including OWASP Top 10 and common mitigation practices.
- Experience with security tools such as SonarQube, Checkmarx, Coverity, OWASP ZAP, Trivy, Grype or equivalent solutions.
- Familiarity with policy-as-code technologies such as Kyverno, OPA/Gatekeeper or equivalent.
- Experience with vulnerability prioritization, remediation tracking, security exceptions and risk management.
- Familiarity with on-premises cloud platforms such as OpenShift or Tanzu.
- Hands-on experience using AI-based tools to improve security analysis, automation or engineering productivity.
- Strong communication and problem-solving skills with the ability to collaborate effectively across development, architecture, security and operations teams.
- A proactive approach to driving security ownership and a security-first engineering culture.
Nice to have:
- Certifications in security or DevOps tools (e.g., Certified Kubernetes Administrator (CKA), Certified DevSecOps Professional, AWS Certified Security Specialty).
- Experience in threat modeling and risk assessment for secure software development.
- Familiarity with containerization and container security (e.g., Docker, Kubernetes).
- Public cloud platforms (AWS, Azure, GCP) and their security configurations.

