Engineer

Concord, NC, US • Posted 2 hours ago • Updated 2 hours ago
Contract Independent
On-site
Compensation information provided in the description
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Information Assurance
  • Impact Analysis
  • Information Architecture
  • Security Policy
  • Concurrent Computing
  • High Availability
  • Operational Excellence
  • Command-line Interface
  • Regression Testing
  • Routing
  • Regulatory Compliance
  • Training
  • Issue Tracking
  • SLA
  • Lifecycle Management
  • Reporting
  • MEAN Stack
  • Auditing
  • Documentation
  • Computer Science
  • Information Security
  • Software Security
  • DevSecOps
  • Security Engineering
  • Security Controls
  • Analytical Skill
  • Management
  • Communication
  • IT Service Management
  • IDE
  • Cloud Computing
  • Amazon Web Services
  • Google Cloud Platform
  • Google Cloud
  • Scripting
  • Terraform
  • ARM
  • Kubernetes
  • Continuous Integration
  • Continuous Delivery
  • Version Control
  • Microsoft Azure
  • DevOps
  • GitHub
  • GitLab
  • Jenkins
  • Oracle Policy Automation
  • Workflow
  • ServiceNow
  • Python
  • Bash
  • Windows PowerShell
  • Cloud Security
  • Collaboration
  • Privacy
  • Marketing

Summary

Location: Concord, NC Salary: $89.00 USD Hourly - $95.00 USD Hourly Description:

Infrastructure as Code (IaC) Security Engineer

We are not accepting C2C or 1099 arrangements.

Location: Charlotte, NC (Open to Zone 2 locations including Charlotte, NC; Irving, TX; Minneapolis, MN; Chandler, AZ; Des Moines, IA; Columbus, OH; Raleigh, NC; San Antonio, TX; Washington, DC)
About the Role

We are seeking an experienced Infrastructure as Code (IaC) Security Engineer to help scale and secure cloud-native development environments through automated security controls and developer-first enablement. In this role, you will build, operate, and optimize IaC security capabilities using Wiz, integrating security seamlessly into CI/CD pipelines and developer workflows.

You will work closely with Application Security, Cloud Engineering, Platform Engineering, and Development teams to identify and prevent infrastructure misconfigurations before deployment. Success in this role requires balancing strong security controls with a frictionless developer experience while maintaining high platform reliability and low operational noise.
What You'll Do
Security Policy Engineering
  • Design, develop, and maintain custom security policies using OPA/Rego to extend IaC security coverage beyond out-of-the-box capabilities.
  • Translate internal security standards, compliance requirements, and cloud governance guardrails into scalable policy-as-code frameworks.
  • Implement version-controlled policy packages and establish governance processes for policy lifecycle management.
CI/CD Security Integration
  • Integrate Wiz security scanning into CI/CD platforms including Azure DevOps, GitHub, GitLab, and Jenkins.
  • Implement automated security gates and enforcement strategies using phased rollout models (Report Warn Block).
  • Optimize scan performance, concurrency, and developer feedback loops to minimize pipeline impact.
Platform Operations & Reliability
  • Monitor and maintain IaC security tooling, ensuring high availability and operational excellence.
  • Manage Wiz CLI upgrades, scanner integrations, policy bundle updates, and CI/CD plugin maintenance.
  • Develop regression testing frameworks to validate policy quality and prevent disruption during changes.
Security Findings Management
  • Triage, validate, and prioritize IaC findings across large-scale environments.
  • Reduce false positives through continuous tuning and policy refinement.
  • Automate ownership routing, exception management, and remediation workflows.
  • Maintain compliance evidence, exception records, and audit-ready documentation.
Developer Experience & Enablement
  • Enable developers through pull request scanning, local development workflows, and IDE integrations.
  • Provide actionable remediation guidance, reusable templates, and secure coding best practices.
  • Facilitate office hours, training sessions, and support channels to accelerate adoption of secure infrastructure practices.
  • Partner with platform teams to embed security into standardized pipelines and reusable infrastructure modules.
Governance & Reporting
  • Integrate with ServiceNow workflows to support ticket synchronization, SLA tracking, and security lifecycle management.
  • Deliver operational metrics and executive reporting, including:
    • Security coverage
    • Policy adoption
    • Block rates
    • Mean Time to Resolution (MTTR)
    • False positive trends
    • Exception aging
  • Support audit requests with policy mappings, change records, and governance documentation.
Minimum Qualifications
  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
  • 8+ years of experience in Application Security, Cloud Security, DevSecOps, or related security engineering roles.
  • Hands-on experience securing Terraform and Kubernetes environments.
  • Experience implementing and operating Wiz or comparable cloud security and IaC security platforms.
  • Strong understanding of Policy as Code, including practical experience with OPA/Rego or similar frameworks.
  • Experience integrating security controls within CI/CD pipelines and modern software delivery practices.
  • Strong analytical and troubleshooting skills with the ability to manage security findings at scale.
  • Excellent written and verbal communication skills with a demonstrated ability to influence and enable engineering teams.
Preferred Qualifications
  • Experience integrating security workflows with ServiceNow AVR/CVR/ITSM or similar governance platforms.
  • Experience supporting developer tooling and IDE integrations, including VS Code.
  • Cloud certifications such as AWS, Azure, or Google Cloud Professional certifications.
  • HashiCorp Terraform Associate certification.
  • Kubernetes certifications such as CKA or CKAD.
  • Automation and scripting experience using Python, Bash, or PowerShell.
  • Experience building developer-focused security programs within large enterprise environments.
Technologies
  • Cloud Security: Wiz
  • Infrastructure as Code: Terraform, ARM/Bicep, CloudFormation, Kubernetes, Helm
  • CI/CD & Source Control: Azure DevOps, GitHub, GitLab, Jenkins
  • Policy as Code: OPA, Rego
  • Workflow & Governance: ServiceNow
  • Automation: Python, Bash, PowerShell
Why Join Us

You'll help shape the future of cloud security by building scalable, automated controls that protect critical infrastructure while enabling developers to move quickly and confidently. This role offers significant ownership, cross-functional collaboration, and the opportunity to influence security practices across a large enterprise environment.

By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: cxjudgpa
  • Position Id: 1148424
  • Posted 2 hours ago

Company Info

About Judge Group, Inc.

The Judge Group, is a leading professional services firm specializing in talent, technology, and learning solutions. We consult, staff, train, and solve. Through our work we make people and organizations better.

Our services are successfully delivered through a network of more than 30 offices across the United States, Canada, and India. The Judge Group is proud to partner with the best and brightest companies in business today, including over 60 of the Fortune 100. We serve organizations in financial services, healthcare, life sciences, insurance, government (including aerospace and defense), manufacturing, and technology and telecommunications.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Charlotte, North Carolina

Today

Contract

Compensation information provided in the description

Charlotte, North Carolina

Today

Contract

Compensation information provided in the description

Charlotte, North Carolina

Today

Contract

Compensation information provided in the description

Charlotte, North Carolina

Today

Contract

USD 64.00 - 69.00 per hour

Search all similar jobs