DevSecOps Secuirty Engineer

Remote • Posted 2 hours ago • Updated 2 hours ago
Contract W2
Contract Corp To Corp
12 Months
No Travel Required
Remote
$45 - $50/hr
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Devsecops

Summary

Job Title: DevSecOps Secuirty Engineer
Remote
12 months contract/ Fulltime 
 
Job Description:
In this role, you will build and operate the automated security controls embedded in L-CAP’s delivery pipeline — the scanning, gating, signing, and hardening that make security continuous rather than periodic. You will work alongside platform and application teams to raise the security posture of every build and every container image without stalling delivery, and you will produce the pipeline evidence that supports platform security authorization.
 
What You’ll Do:
  • Implement and maintain automated security controls in CI/CD pipelines, including SAST, DAST, software composition analysis, container scanning, and infrastructure-as-code scanning.
  • Enforce security gates, artifact signing, provenance verification, and SBOMs (CycloneDX/SPDX) to prevent vulnerable or unverified deployments.
  • Drive container vulnerability remediation and hardening, including hardened minimal base images and elimination of critical/high findings.
  • Implement Kubernetes security controls, including pod security, network policies, RBAC, admission controls, and security context constraints.
  • Secure workloads through secrets management, mutual TLS (mTLS), service mesh policies, and Linux/container hardening.
  • Build and maintain policy-as-code and infrastructure guardrails using OPA/Rego, Kyverno, or equivalent tools.
  • Produce security evidence supporting authorization and continuous monitoring requirements.
  • Partner with platform and application teams to triage vulnerabilities, remediate findings, and support security incident response and root cause analysis.
  • Leverage AI-assisted development, automation, and modern engineering practices to improve security, code quality, productivity, and delivery speed.
 
Core Technical Qualifications:
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience. (additional experience, education and training may be considered in lieu of degree)
  • Hands-on experience integrating SAST, DAST, software composition analysis, and container scanning into CI/CD pipelines.
  • Experience securing Kubernetes and container environments, including pod security, network policies, RBAC, admission controls, and hardened/minimal base images.
  • Experience with vulnerability scanning and remediation, using tools such as Nessus, Trivy, Grype, or Qualys, including CVE triage and tracking.
  • Experience with secrets management (HashiCorp Vault or equivalent) and security automation using Python, Bash, or Go.
  • Experience with Git-based workflows and CI/CD tooling, such as GitLab CI, GitHub Actions, or Jenkins.
  • Working knowledge of NIST 800-53, automated security evidence, and AWS or Azure cloud security.
  • Understanding of network security, including segmentation and default-deny policies.
  • U.S. citizenship required, with the ability to obtain and maintain a Public Trust and meet government background investigation requirements.
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the prior 5 years.
 
Preferred / Desired Qualifications:
  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.
  • Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)
  • Knowledge of software supply chain security, including SLSA, Sigstore/cosign, in-toto, and FIPS 140-3.
  • Experience with policy-as-code (OPA/Rego, Kyverno) and infrastructure-as-code security scanning (Terraform, CloudFormation).
  • Experience securing Kubernetes/OpenShift environments, including service mesh security (Istio, Linkerd) and security context constraints.
  • Experience with GitOps deployment using ArgoCD, Flux, or equivalent.
  • Experience in aviation, FAA, or other safety-critical environments.
  • Experience with SAFe or large-scale Agile delivery
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91133294
  • Position Id: 19711-10625-1791578921
  • Posted 2 hours ago

Company Info

About IMR Soft LLC

We're building a great company, and we're very excited about the future of the company.

IMR Soft. is one of the fastest-growing, USA based Information Technology company specializing in software development and IT Services. Founded in 2017, by a team of experienced professionals with a solid base in IT and Management. Headquartered in Princeton, New Jersey.

We help clients Create the Future. We deliver innovative information technology solutions and unlimited services that benefit our clients by maximizing their performance. We combine tech expertise and business intelligence to catalyze change and deliver results. In a world that is constantly changing, companies are faced with the challenge of continually adapting to a dynamic environment.

Create job alert
Never miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs