Overview
Remote
$200000
Full Time
Job Details
Vaco is actively seeking a DevSecOps Advisor / GRC Architect to support our client’s continued growth by ensuring a well-defined IT security and compliance posture. This is a unique direct-hire opportunity to join a stable and growing global manufacturing organization that is a respected leader in their field.
Position Summary
DevSecOps Advisor / Compliance Architect is responsible for guiding enterprise-wide IT security and compliance integration across a global SAP and SDLC environment. This strategic role bridges software development, ERP customization, application security, and operations with a strong focus on GRC, NIST, SOX, and secure SDLC practices.
The ideal candidate brings both technical acumen and governance expertise; acting as a liaison between technical development teams, security, audit, and business stakeholders. This is a hands-on advisory role, with a strong emphasis on architecting visibility, automating compliance, and enabling proactive reporting through dashboarding and integrated controls.
Key Responsibilities:
Technical Skills & Knowledge:
Additional Details:
Interested Candidates are Encouraged to Apply for Immediate Consideration!
Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual’s skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company’s 401(k) retirement plan.
Position Summary
DevSecOps Advisor / Compliance Architect is responsible for guiding enterprise-wide IT security and compliance integration across a global SAP and SDLC environment. This strategic role bridges software development, ERP customization, application security, and operations with a strong focus on GRC, NIST, SOX, and secure SDLC practices.
The ideal candidate brings both technical acumen and governance expertise; acting as a liaison between technical development teams, security, audit, and business stakeholders. This is a hands-on advisory role, with a strong emphasis on architecting visibility, automating compliance, and enabling proactive reporting through dashboarding and integrated controls.
Key Responsibilities:
- Serve as a DevSecOps SME and strategic advisor across enterprise ERP / custom development landscapes.
- Develop and implement security and compliance guardrails within CI/CD pipelines and development workflows.
- Champion OWASP best practices (e.g., Top 10, ASVS, SAMM) in application design, development, and code review processes.
- Translate and convey regulatory frameworks (NIST, SOX, GDPR, etc.) into actionable technical standards and procedural controls.
- Build and maintain compliance dashboards, real-time risk visibility tools, and automated reporting for business stakeholders, developers, and internal / external auditors.
- Integrate and automate security scanning, policy enforcement, and change management processes into DevOps toolchains.
- Guide teams through secure SDLC principles, threat modeling, and risk assessment for new and legacy environments.
- Support internal/external audit cycles and stakeholder interactions to provide evidence of control effectiveness.
- Champion a culture of compliance by strategic design and continuous improvement across a global enterprise.
Technical Skills & Knowledge:
- Minimum of 5 years of dedicated experience in DevSecOps, AppSec, Security Architecture, or GRC-adjacent roles.
- Strong working knowledge of security/GRC development, custom app development, and CI/CD pipelines.
- Deep familiarity with NIST 800-53, SOX, OWASP Top 10, and secure SDLC frameworks.
- Proven experience designing or deploying automated compliance and monitoring dashboards (e.g., Splunk, Power BI, SAP GRC, or custom solutions)
- Hands-on experience with DevSecOps tooling: GitLab CI, Azure DevOps, Jenkins, Checkmarx, Snyk, HashiCorp Vault, etc.
- Background in manufacturing or similar is preferred.
- Familiarity with SAP S/4HANA, SAP Cloud, and modern ERP security architectures is a plus.
- Training / Certifications: CISSP, CISA, CRISC, SAP Security, or OWASP based training is desired.
Additional Details:
- Employment Type: Direct-Hire / Perm
- Start Date: Immediate
- Location: Remote
- Primary Cadence: CST business hours / Monday - Friday
- Travel: Limited
- Target Compensation: $150k - $165k plus Bonus
- Engagement Status: No form of sponsorship or employment arrangements are being considered at this time.
Interested Candidates are Encouraged to Apply for Immediate Consideration!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.