Confirmed on the employer's own hiring board on Oct 11, 2026. First seen by Alion on Oct 11, 2026. Justworks scores B on the Alion truth index.
Join our team as a Senior DevSecOps Engineer, a foundational role where you'll shape how secure software is built. You'll work closely with our Developer Experience and SRE teams, as well as the Security organization. Your responsibilities will include owning security automation across our CI/CD pipelines, building security into our templates, hardening our software supply chain, and coordinating vulnerability exposure remediation. You'll also partner with the Security team on cloud security posture and support the rollout of penetration testing. This role offers a range of benefits, including paid volunteer work, parental leave, work from home opportunities, and extensive learning and development opportunities.
Missions
- Assumer la responsabilité de l'automatisation de la sécurité dans les pipelines CI/CD, y compris l'intégration des outils de sécurité tels que SAST, SCA, la détection des secrets et l'analyse des conteneurs.
- Collaborer avec l'équipe de sécurité pour renforcer la chaîne d'approvisionnement logicielle, y compris la gestion des dépendances, la signature des artefacts et la génération de SBOM.
- Coordonner la remédiation des vulnérabilités exposées dans l'ensemble de l'ingénierie, y compris les vulnérabilités du code, les changements de configuration de l'infrastructure et les mises à jour.
Profil recherché
- So you build guardrails instead: pipelines that catch vulnerabilities before a human ever has to, golden paths with security baked in, and automation that turns "did we patch that?" from a meeting into a dashboard- You believe the secure path should be the easy path. You've spent your career where security and engineering meet, and you've learned that scanners nobody reads and gates nobody can pass don't make software safer, they make engineers route around you
- You're comfortable in a CI/CD pipeline, an AWS account, and a Kubernetes cluster. You can read application code well enough to tell a real injection risk from scanner noise, and you'd rather fix the template that generated the bug than file 40 tickets about it
- As a Senior DevSecOps Engineer, how results are achieved is paramount for your success and ultimately result in our success as an organization. In this role, your foundational knowledge, skills, abilities and personal attributes are anchored in the following competencies:
- Good judgement - the exercise of critical thinking, analyzing and assessing problems and implications, identifying patterns, making connections of underlying issues, understanding risks and developing mitigation strategies, and taking ownership of the outcome
- Resourcefulness - taking a can-do approach, even in the face of obstacles and constraints by assessing what’s in front of you and effectively and efficiently optimizing what you have, whether it's working on something new or thinking about how to do something better
- Teamwork and communication - putting our collective best together through documentation, collaboration, relationship-building, listening, empathy, recruiting, and evangelism.Influence and leadership - fostering a community of knowledge-sharing, collaboration, mentorship, and forward-thinking
- Skills and knowledge - the capacity to actively learn and apply specific domain knowledge, know-how, and best practices to continually enhance and improve
- 5+ years of professional experience in software engineering, infrastructure, or security engineering
- Hands-on experience integrating security tooling into CI/CD pipelines (GitHub Actions strongly preferred): SAST, SCA, secrets detection, container scanning
- 3+ years focused on application security, security automation, or DevSecOps practice
- Demonstrated ability to reduce security friction for engineers, with examples of controls teams adopted willingly
- Proficiency in at least one programming language (Go, Python, or Ruby preferred); you build tooling, not just configure it
- Strong written communication; you document as you build
- Proficiency with AWS and its security services (IAM, GuardDuty, Security Hub, CloudTrail); you understand cloud identity well enough to design least-privilege access, not just audit it
- Experience with Kubernetes and infrastructure-as-code (Terraform preferred), including policy-as-code enforcement

