Source description
About the role
Job Summary We are seeking a seasoned Senior DevOps / DevSecOps Security Engineer with 8–10+ years of experience to lead vulnerability remediation initiatives— specifically on BitSight-identified security issues —across SaaS and public cloud environments. The ideal candidate will be highly hands-on, with deep experience in vulnerability analysis, remediation guidance, and security engineering within CI/CD and cloud operations contexts. This role will work closely with Engineering, DevOps, and Security teams to drive actionable remediation, embed security into infrastructure and development pipelines, and enhance overall security posture. Key Responsibilities Security Vulnerability Remediation & Management Lead hands-on remediation of vulnerabilities identified by BitSight and other security assessment tools. Triage, verify, and resolve security findings across cloud services, containers, microservices, and SaaS products. Prioritize vulnerabilities based on risk, exploitability, and business impact with clear mitigation plans. Collaborate with DevOps, engineering, and product teams to ensure timely remediation and secure deployments. DevSecOps Integration Embed security controls, automated checks, and scanning throughout the CI/CD pipelines (DevOps + DevSecOps). Integrate BitSight outputs into internal vulnerability workflows and dashboards. Automate security test execution in build and release workflows. Cloud & Infrastructure Security Design, implement, and secure environments in AWS, Azure, or GCP. Harden cloud infrastructure and services, ensuring compliance with security best practices and organizational standards. Tooling, Automation & Reporting Build automation for vulnerability detection, verification, and remediation. Maintain security tooling, vulnerability scanners, and reporting frameworks. Provide regular leadership reporting (metrics, trends, risk dashboards). Cross-functional Collaboration Work with engineering teams to implement secure design principles and support secure coding. Guide remediation approaches, safe configuration changes, and risk reduction strategies. Partner with Product and Security teams to embed security into the development lifecycle. Required Skills & Expertise Technical Skills 8–10+ years in DevOps, DevSecOps, Security Engineering, or related roles. Strong experience with BitSight vulnerability identification and remediation workflows (or similar SaaS security rating/scan platforms). Deep hands-on experience with vulnerability management and remediation in cloud & SaaS environments. Expertise with CI/CD automation (Jenkins, GitHub Actions, GitLab CI, Azure DevOps, etc.). Experience with cloud security: AWS/Azure/GCP (IAM, networking, logging, security services). Infrastructure as Code (IaC) security: Terraform, CloudFormation. Scripting and automation skills: Python, Bash, PowerShell, etc. Strong grasp of vulnerability assessment and scanning tools (SAST, DAST, SCA, container security scanners). Solid understanding of security frameworks and best practices (OWASP, NIST, CIS). Qualifications & Certifications (Preferred) Bachelor's degree in CS, IT, Cybersecurity, or equivalent. Security certifications such as: CISSP, CISM AWS Certified Security Specialty GIAC/GSEC Certified DevSecOps Professional (if available)
More at MokshTech