DevSecOps Specialist securing the software development lifecycle at Vanguard. Collaborating with teams to improve application security tooling and processes, and provide development guidance.
Responsibilities
Secure the software development lifecycle (SDLC) by applying application development, deployment, and security expertise.
Operate, configure, and continuously improve application security tooling, with a primary focus on SAST and SCA, including policy tuning and integration into CI/CD pipelines.
Identify, analyze, and triage application security vulnerabilities; apply risk-based prioritization and work with engineering teams to drive timely remediation.
Collaborate with App Sec engineers and peer security teams to ensure consistent implementation, coverage, and alignment of application security tools, standards, and processes.
Champion a low-friction developer experience by streamlining scan workflows, reducing false positives, and providing clear, actionable feedback.
Participate in an on-call rotation to support application security tooling, assist developers, and respond to security threat events when required.
Identify and implement opportunities to automate application security processes to improve scalability, efficiency, and coverage.
Gather and report meaningful metrics to measure vulnerability trends, tool effectiveness, and application security program maturity.
Develop and maintain documentation for application security technologies, processes, and standards.
Provide guidance and training to development and cloud engineering teams on secure coding, dependency management, and deployment best practices.
Stay current on application security trends, tools, and standards, and contribute to continuous improvement of the AppSec program.
Participate in special projects and perform other duties as assigned.
Requirements
Minimum of five years related work experience.
Undergraduate degree in a related field or the equivalent combination of training and experience.
DevOps Manager responsible for managing a team for multi - cloud solutions supporting the USAF Cloud One project. Focus on scalable cloud - native solutions and CI/CD practices.
Lead Site Reliability Engineer overseeing SRE practices across Azure and GCP platforms. Driving reliability improvements and leading a team at Lloyds Banking Group.
DevOps Engineer responsible for managing Microsoft Intune operations at Bundesdruckerei GmbH. Focused on ensuring secure digital solutions for identity and data protection in Berlin.
Senior Site Reliability Engineer driving observability and reliability for business - critical systems at Incedo. Collaborating with engineering teams to enhance system resilience and performance.
Site Reliability Engineer automating infrastructure deployment for Scaleway's sovereign cloud products. Collaborating with product teams to enhance observability and reliability of the platform.
Reliability Engineer responsible for equipment reliability and safety using data - driven analysis for Wood in Aberdeen. Focus on proactive maintenance and operational efficiency.
Principal Safety and Reliability Engineer developing and supporting safety design for mission - critical aerospace systems. Engaging in design reviews and ensuring compliance with requirements.
Cloud DevOps Engineer playing a pivotal role in developing migration plans for Coast Guard Cloud Architecture. Collaborating with teams to ensure effectiveness and best practices in cloud implementation.
Reliability Engineer III at Daimler Truck developing propulsion technology solutions for electrified and conventional axle components. Leading testing and validation for complex powertrain systems.