HumanBit Logo

DevSecOps Engineer | Scrabble & Jigsaw

Posted on January 17, 2026

Job Description

<meta charset="UTF-8" /> <p><b>DevSecOps Engineer Job</b></p> <p><b>Description</b></p> <p>We&#39;re looking for an experienced&nbsp;<b>DevSecOps Engineer</b>&nbsp;with&nbsp;<b>7+ years of experience</b>&nbsp;to join</p> <p>our team. In this role, you&#39;ll be instrumental in integrating security best practices throughout our</p> <p>entire software development lifecycle (SDLC). You&#39;ll bridge the gap between development,</p> <p>security, and operations, ensuring our applications and infrastructure are secure from the</p> <p>get-go.</p> <p><b>Responsibilities:</b></p> <p>&bull;&nbsp;<b>Design and Implement Security Automation:</b>&nbsp;Architect and deploy automated</p> <p>security tools within our CI/CD pipelines to perform static application security testing</p> <p>(SAST), dynamic application security testing (DAST), and container security scanning.</p> <p>&bull;&nbsp;<b>Secure Cloud Infrastructure:</b>&nbsp;Work with cloud services (AWS, Azure, GCP) to</p> <p>ensure our infrastructure is configured securely, adhering to best practices like the</p> <p>principle of least privilege and network segmentation.</p> <p>&bull;&nbsp;<b>Threat Modeling and Risk Assessment:</b>&nbsp;Conduct regular threat modeling exercises</p> <p>to identify potential security vulnerabilities and work with development teams to</p> <p>mitigate risks.</p> <p>&bull;&nbsp;<b>Incident Response and Monitoring:</b>&nbsp;Develop and maintain security monitoring and</p> <p>alerting systems to detect and respond to security incidents.</p> <p>&bull;&nbsp;<b>Security Policy and Compliance:</b>&nbsp;Define and enforce security policies, standards,</p> <p>and procedures to ensure compliance with industry regulations and internal</p> <p>requirements.</p> <p>&bull;&nbsp;<b>Collaboration and Training:</b>&nbsp;Collaborate with development, QA, and operations</p> <p>teams to embed security culture. Provide training and guidance on secure coding</p> <p>practices and security tools.</p> <p>&bull;&nbsp;<b>Customer Security Assessments:</b>&nbsp;Support responses to customer information</p> <p>security questionnaires, ensuring accurate representation of our security controls and</p> <p>practices.</p> <p>&bull;&nbsp;<b>SOC 2 and Compliance Programs</b>: Lead or assist in maintaining the company&rsquo;s</p> <p>SOC 2 certification and other compliance programs, including gathering evidence,</p> <p>coordinating with auditors, and driving continuous improvement of controls.</p> <p><b>Required Skills and Qualifications:</b></p> <p>&bull;&nbsp;<b>Experience:</b>&nbsp;7-10years of professional experience in a DevSecOps, DevOps, or a</p> <p>security-focused role.</p> <p>&bull;&nbsp;<b>CI/CD Tools:</b>&nbsp;Proficient with CI/CD tools like&nbsp;<b>Jenkins, GitLab CI, or CircleCI</b>.</p> <p>&bull;&nbsp;<b>Scripting:</b>&nbsp;Strong scripting skills in languages such as&nbsp;<b>Python, Bash, or PowerShell</b></p> <p>for automation.</p> <p>&bull;&nbsp;<b>Cloud Platforms:</b>&nbsp;Hands-on experience with at least one major cloud provider (<b>AWS,</b></p> <p><b>Azure, or GCP</b>) and familiarity with infrastructure as code tools like&nbsp;<b>Terraform,</b></p> <p><b>Pulumi or CloudFormation</b>.</p> <p>&bull;&nbsp;<b>Security Tools:</b>&nbsp;Expertise with security tools for&nbsp;<b>SAST (e.g., SonarQube, Fortify),</b></p> <p><b>DAST (e.g., Burp Suite, OWASP ZAP), and container security (e.g., Clair, Trivy)</b>.</p> <p>&bull;&nbsp;<b>Containerization and Orchestration:</b>&nbsp;Experience with&nbsp;<b>Docker and Kubernetes</b>.</p> <p><b>Soft Skills:</b>&nbsp;Excellent problem-solving, communication, and collaboration skills.</p> <p><b>Preferred Qualifications</b></p> <p>&bull;&nbsp;Relevant certifications such as&nbsp;<b>CISSP, SANS GIAC, or AWS/Azure Security</b></p> <p><b>Specialist</b>.</p> <p>&bull;&nbsp;Experience with a security information and event management (<b>SIEM</b>) system like</p> <p>Splunk or ELK Stack.&bull;&nbsp;Familiarity with compliance frameworks like&nbsp;<b>PCI DSS, HIPAA, or SOC</b></p>
Powered by
HumanBit Logo