Senior DevSecOps Engineer (Hybrid)

Sorry, this job was removed at 04:20 p.m. (CST) on Monday, Oct 27, 2025
Be an Early Applicant
Mechanicsburg, PA, USA
In-Office
Information Technology
The Role
Job Title: Senior DevSecOps Engineer (Hybrid)
Location: Mechanicsburg, PA
Duration: 8 Months
Overview:
Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.
Scope boundaries:
  • Does not own enterprise AWS Organizations or SCP operations.
  • Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
  • Focuses on preventive controls and compliance automation, not incident response.

What you will deliver First 90 days
  • Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates.
  • Compliance as code in reference accounts: AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with exceptions workflow documented.
  • IaC reference modules using AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; Terraform equivalents provided where teams require them.
  • Evidence exports tying checks to control IDs and producing auditor-ready artifacts.

Ongoing:
  • Harden CDK/CFT modules and pipeline templates as compliance needs evolve.
  • Coach pilot teams to adopt templates.
  • Raise gaps to enterprise teams for org-level enforcement.

Day-to-day responsibilities:
  • Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
  • Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
  • Wire scanning in CI/CD for app code, containers, and IaC.
  • Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
  • Generate posture and evidence reports mapped to CJIS and NIST controls.

Required skills:
  • 5+ years AWS security automation and DevOps.
  • Strong with AWS CDK and CloudFormation; working proficiency in Terraform.
  • CI/CD authoring in GitHub Actions and Azure DevOps.
  • Proficient in Python and Bash, with PowerShell for Windows automation.
  • Able to read Java and C# to integrate and tune SAST/SCA.
  • Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence.

Nice to have
  • EKS/ECS/Lambda hardening patterns.
  • OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
  • Basic Azure security automation for future phases.

Decision rights
  • Independent on design and build within standards; proposes guardrails and reference patterns; escalates enterprise-wide changes.

Similar Jobs

In-Office or Remote
2 Locations
125 Employees
80K-100K Annually

SailPoint Logo SailPoint

Enterprise Account Exec Philadelphia Metro

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
2461 Employees
109K-184K Annually

SailPoint Logo SailPoint

Product Analyst

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
122K-206K Annually

SailPoint Logo SailPoint

Sr. Director/VP, Product Management - Agentic

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
191K-322K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Baltimore, MD
146 Employees

What We Do

Serigor provides IT Services and IT staffing to Government and Commercial enterprises of all sizes. Serigor has twelve years of proven track record in IT Services, Government Solutions, and Staffing Solutions. ● MBE/WBE/WBENC/WOSB company, headquartered in Baltimore, MD. ● Multiple, multi-year contracts with Government Agencies at State, County, City, and Federal. ● Commercial clients include Fortune 1000 and Start-Ups all over the US. ● Onshore and offshore IT delivery centers. ● IT solutions encompass contracts that are Fixed Price, T&M, Product Development in all technologies. ● Workforce and staffing solutions encompass contract, contract-to-hire, permanent placement and statement of work job assignments.

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account