Senior DevSecOps Engineer
TLDR
This role requires defining and executing the DevSecOps strategy to integrate security throughout CI/CD pipelines and maintain secure multi-cloud operations.
- Define DevSecOps strategy and Influence architecture and platform decisions
- Design and implement secure CI/CD pipelines with integrated security controls
- Embed security practices into SDLC (shift-left approach)
- Integrate and operationalize controls aligned with FedRAMP and cloud security best practices
- Apply secure coding practices aligned with OWASP Top 10 to reduce application vulnerabilities
- Automate security testing (SAST, DAST, SCA, container scanning, IaC scanning)
- Define and enforce secure coding standards and best practices
- Secure cloud environments (AWS / Azure / GCP) following FedRAMP security controls (NIST 800-53) where applicable
- Implement identity and access management (IAM), secrets management, and network security controls
- Harden Kubernetes clusters and containerized workloads
- Build and maintain security automation frameworks
- Develop scripts and tools (Python, Go, Bash) to improve security posture
- Monitor vulnerabilities and drive remediation efforts
- Identify and remediate vulnerabilities mapped to OWASP Top 10 categories
- 7+ years of experience in relevant roles
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field
- Hands-on experience with SAST, DAST, SCA, IaC, and container supply chain security
- Strong understanding of DevOps, DevSecOps, and Security Engineering principles
- Familiarity with compliance frameworks such as FIPS, CIS, FedRAMP, and NIST
- Strong experience with CI/CD tools (Jenkins, GitHub Actions, GitLab CI, etc.)
- Hands-on experience with cloud platforms (AWS, Azure, or GCP)
- Deep understanding of containerization (Docker) and orchestration (Kubernetes)
- Experience with Infrastructure as Code tools (Terraform, CloudFormation, etc.)
- Strong knowledge of application and infrastructure security principles
- Proficiency in scripting or programming languages (Python, Go, Bash, etc.)
-
Good understanding of AI models like Claude, Gemini and any other GPT models
-
Working knowledge of AI Agents, MCP, LangChain, LangGraph and securing them
Good to have
Saviynt builds an AI-powered identity platform that helps organizations manage access to their applications and data securely. Targeting businesses looking for robust identity governance and access management solutions, Saviynt differentiates itself by combining transparency with innovative security measures, ensuring clients can trust their vital security architecture.
- Founded
- Founded 2010
- Employees
- 500+ employees
- Industry
- Internet Software & Services
- Total raised
- $40M raised