NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / DevOps Engineer in United States of America
3 days ago
Apply with autofill
Apply with autofill
Exiger·3 days ago
3 days ago

Senior DevSecOps Engineer

McLean, United States of AmericaHybridMid · 5-8 yearsDevOps Engineer

Sign up free to see how well your resume matches this role.

Boost your chances at exiger

How you compare FREE

?
Your scoreYour score: not yet known
→
68
Top 10%Top 10%: 68 out of 100

Top 10% of NextRaise users matched against DevOps Engineer roles in United States.

Must-have skills for this role

  • python
  • java
  • rest apis
  • kubernetes

PDF or DOCX · no account needed

Apply faster with autofill FREEexiger uses Greenhouse - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Design, build, and maintain automated security workflows across the software development lifecycle and broader security environment.
  • Automate security processes such as vulnerability intake, ticket creation, assignment, enrichment, escalation, remediation tracking, exception handling, and reporting.
  • Integrate security platforms with ticketing, CI/CD, cloud, and engineering systems using APIs, webhooks, scripts, and workflow automation.
  • Embed automated application, dependency, secrets, infrastructure-as-code, container, and API security testing into CI/CD pipelines.
  • Define and implement risk-based release gates, remediation timelines, exception processes, and finding ownership.
  • Build reusable secure pipeline templates, hardened images, self-service security controls, and policy-as-code guardrails.
  • Strengthen security across cloud infrastructure, containers, Kubernetes, identity, secrets management, networking, and deployment processes.
  • Triage vulnerabilities and security findings based on severity, exploitability, exposure, asset criticality, and business impact.
  • Automate vulnerability-management workflows to ensure findings are routed to the appropriate owners and tracked through remediation.
  • Secure source code, third-party dependencies, build systems, artifacts, container images, and software supply-chain processes.
  • Support application security reviews, threat modeling, security architecture reviews, monitoring, and incident-response activities.
  • Translate regulatory and compliance requirements into scalable technical controls and automated audit evidence.

What they're looking for

  • Eight or more years of experience in DevOps, platform engineering, cloud engineering, application security, product security, DevSecOps, or cybersecurity engineering.
  • Significant hands-on experience designing, implementing, and operating DevSecOps capabilities in production environments.
  • Demonstrated experience building security automation, including integrations between security tools, ticketing platforms, CI/CD systems, and engineering workflows.
  • Strong software development or scripting experience using Python and/or Java, with additional experience in technologies such as PowerShell, Bash, JavaScript, or TypeScript.
  • Ability to develop maintainable, reusable, and tested automation rather than relying solely on one-time scripts.
  • Strong knowledge of REST APIs, webhooks, and systems integrations.
  • Experience automating ticket creation, assignment, escalation, remediation tracking, or similar security operational workflows.
  • Strong knowledge of CI/CD security, application security testing, vulnerability management, and software supply-chain security.
  • Experience securing cloud platforms, containerized workloads, Kubernetes, infrastructure as code, Linux, networking, identity, encryption, logging, and secrets management.
  • Knowledge of SAST, DAST, software composition analysis, secrets scanning, container scanning, infrastructure-as-code scanning, and related DevSecOps controls.
  • Knowledge of threat modeling, OWASP guidance, web and API security, authentication, authorization, and secrets management.
  • Experience prioritizing vulnerabilities and security findings based on technical and business risk.

Nice to have

  • Hands-on experience with one or more of the following security platforms: CrowdStrike, Microsoft Sentinel, Aikido Security, Code42, Qualys
  • Experience integrating security platforms with Jira, ServiceNow, or similar ticketing and workflow systems.
  • Experience with security orchestration, automation, and response (SOAR) platforms or equivalent automated security workflows.
  • Experience with cloud-native security technologies such as Kubernetes, Docker, Terraform, Helm, and cloud IAM.
  • Experience with policy-as-code technologies such as OPA, Rego, Kyverno, or similar tools.
  • Familiarity with SBOMs, artifact signing, dependency security, provenance, and software supply-chain frameworks.
  • Experience supporting regulated environments and frameworks such as FedRAMP, NIST, SOC 2, ISO 27001, or similar standards.
  • Experience developing security metrics, dashboards, and automated compliance evidence.

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

Who We Are:

Exiger is the AI partner for supply chain and procurement automation. Its centralized 1EXIGER.AI platform allows organizations to manage their entire operating network, from parts to suppliers, regulators, and customers, through an autonomous agentic workforce that learns, adapts, and augments with every decision. The AI-native platform, combined with the largest supply chain knowledge asset, empowers 550+ global customers, including 150 Fortune 500 and 80+ government and defense industrial organizations, to act first. Exiger is FedRAMP® authorized and a 2x Leader in Gartner® Magic Quadrant™ for Supplier Risk Management.

Senior DevSecOps Engineer

Location: Richmond, VA preferred

Position Summary

The Senior DevSecOps Engineer is a hands-on technical leader responsible for embedding scalable security controls, automation, and secure engineering practices throughout the software development lifecycle.

As a member of the Security team, this role partners closely with Engineering, Cloud, Platform, IT, and Compliance teams to automate security processes, improve vulnerability and finding management, and provide timely security feedback without creating unnecessary delivery friction.

A key focus of this role is security automation. The successful candidate will have experience building automated workflows that integrate security tools with engineering and operational systems, including automated ticket creation, routing, enrichment, escalation, remediation tracking, and reporting.

The ideal candidate combines strong DevSecOps and cloud security expertise with hands-on software development and automation experience and is comfortable operating in regulated, cloud-based environments.

Responsibilities

  • Design, build, and maintain automated security workflows across the software development lifecycle and broader security environment.

  • Automate security processes such as vulnerability intake, ticket creation, assignment, enrichment, escalation, remediation tracking, exception handling, and reporting.

  • Integrate security platforms with ticketing, CI/CD, cloud, and engineering systems using APIs, webhooks, scripts, and workflow automation.

  • Embed automated application, dependency, secrets, infrastructure-as-code, container, and API security testing into CI/CD pipelines.

  • Define and implement risk-based release gates, remediation timelines, exception processes, and finding ownership.

  • Build reusable secure pipeline templates, hardened images, self-service security controls, and policy-as-code guardrails.

  • Strengthen security across cloud infrastructure, containers, Kubernetes, identity, secrets management, networking, and deployment processes.

  • Triage vulnerabilities and security findings based on severity, exploitability, exposure, asset criticality, and business impact.

  • Automate vulnerability-management workflows to ensure findings are routed to the appropriate owners and tracked through remediation.

  • Secure source code, third-party dependencies, build systems, artifacts, container images, and software supply-chain processes.

  • Support application security reviews, threat modeling, security architecture reviews, monitoring, and incident-response activities.

  • Translate regulatory and compliance requirements into scalable technical controls and automated audit evidence.

  • Partner directly with Engineering teams to remediate security issues and promote secure development practices.

  • Evaluate and integrate emerging security capabilities and technologies.

  • Develop metrics and dashboards to measure security posture, remediation performance, and automation effectiveness.

  • Lead cross-functional security initiatives and mentor engineers on DevSecOps and secure engineering practices.

Required Qualifications

  • Eight or more years of experience in DevOps, platform engineering, cloud engineering, application security, product security, DevSecOps, or cybersecurity engineering.

  • Significant hands-on experience designing, implementing, and operating DevSecOps capabilities in production environments.

  • Demonstrated experience building security automation, including integrations between security tools, ticketing platforms, CI/CD systems, and engineering workflows.

  • Strong software development or scripting experience using Python and/or Java, with additional experience in technologies such as PowerShell, Bash, JavaScript, or TypeScript.

  • Ability to develop maintainable, reusable, and tested automation rather than relying solely on one-time scripts.

  • Strong knowledge of REST APIs, webhooks, and systems integrations.

  • Experience automating ticket creation, assignment, escalation, remediation tracking, or similar security operational workflows.

  • Strong knowledge of CI/CD security, application security testing, vulnerability management, and software supply-chain security.

  • Experience securing cloud platforms, containerized workloads, Kubernetes, infrastructure as code, Linux, networking, identity, encryption, logging, and secrets management.

  • Knowledge of SAST, DAST, software composition analysis, secrets scanning, container scanning, infrastructure-as-code scanning, and related DevSecOps controls.

  • Knowledge of threat modeling, OWASP guidance, web and API security, authentication, authorization, and secrets management.

  • Experience prioritizing vulnerabilities and security findings based on technical and business risk.

  • Strong communication skills with the ability to explain security risks, remediation options, and engineering tradeoffs to technical and non-technical stakeholders.

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related discipline, or equivalent practical experience.

Preferred Qualifications

  • Hands-on experience with one or more of the following security platforms:

    • CrowdStrike

    • Microsoft Sentinel

    • Aikido Security

    • Code42

    • Qualys

  • Experience integrating security platforms with Jira, ServiceNow, or similar ticketing and workflow systems.

  • Experience with security orchestration, automation, and response (SOAR) platforms or equivalent automated security workflows.

  • Experience with cloud-native security technologies such as Kubernetes, Docker, Terraform, Helm, and cloud IAM.

  • Experience with policy-as-code technologies such as OPA, Rego, Kyverno, or similar tools.

  • Familiarity with SBOMs, artifact signing, dependency security, provenance, and software supply-chain frameworks.

  • Experience supporting regulated environments and frameworks such as FedRAMP, NIST, SOC 2, ISO 27001, or similar standards.

  • Experience developing security metrics, dashboards, and automated compliance evidence.

Exiger is named a Leader in the Gartner® Magic Quadrant™ for Supplier Risk Management, twice selected as one of Fast Company's 'Brands That Matter,' and recipient of the Third Party Risk Association's Innovator Award, Exiger's technology has been recognized by leading analyst evaluations and 50+ awards. Learn more at Exiger.com and follow Exiger on LinkedIn.

At Exiger, our values define how we work and why we lead. We are mission-inspired, imagination-driven, trust-anchored, and compassion-focused—committed to building technology that makes the world safer, more transparent, and more resilient.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Exiger’s hybrid work policy is periodically reviewed and adjusted to align with evolving business needs.

Company

Exiger
McLean, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Exiger's careers site·first seen 17 Sept 2026·last verified 17 Sept 2026·How we source jobs

Similar jobs

  • Software DevOps Engineer - Grad at ThalesOrlando, United States of America–match not yet calculated
  • Computing Undergraduate Student Intern: DevOps Internship Program - Summer 2027 at llnlLivermore, United States of America–match not yet calculated
  • DevOps Engineer at RocheIndianapolis, United States of America–match not yet calculated
  • Staff DevSecOps Engineer | Bankrate at redventuresUnited States–match not yet calculated
  • Senior DevOps Engineer at RELXRichmond, United States of America–match not yet calculated

Browse more jobs

  • DevOps Engineer jobs in United States
  • Systems Engineer jobs in United States
  • Network Engineer jobs in United States
  • Platform Engineer jobs in United States
  • DevOps Engineer jobs in India
  • DevOps Engineer jobs in France