Senior DevSecOps Engineer

Posted Yesterday
Hiring Remotely in USA
Remote or Hybrid
Senior level
Software
Empowering Construction Through Innovative Software
The Role
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Summary Generated by Built In
We are HCSS. For the last 40 years, we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer. We have earned Best Companies to Work for in Texas honors for 18 consecutive years and have been named a USA Today Top Workplace. HCSS has also been recognized by Built In as a Best Place to Work in Greater Houston and by Construction Executive for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence.

WHO WE NEED: 
As a Senior DevOps Engineer specializing in DevSecOps and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development
teams deliver secure software at scale.

Qualifications:
  • Experience: Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices.
  • Cloud Expertise: Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others.
  • Security Tools & Practices: Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
  • Secure Development Lifecycle: In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development.
  • Vulnerability Management: Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
  • Compliance Knowledge: Familiarity with security and compliance frameworks such as OWASP, NIST, CIS,
  • SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Collaboration & Communication: Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.

Preferred Qualifications:
  • Security Certifications: Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
  • Threat Modeling: Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
  • Experience with Microservices & APIs: Strong understanding of microservices architecture and API security practices.
  • Security Tools: Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.

Role Responsibilities:
  • DevSecOps Integration: Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
  • Application Security Expertise: Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling.
  • Azure Cloud Security: Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more.
  • Static and Dynamic Application Security Testing: Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments.
  • Secrets Management: Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments.
  • Software Composition Analysis (SCA): Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies.
  • Automation and Infrastructure as Code: Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments.
  • Security Policies & Compliance: Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure.
  • Collaboration & Mentorship: Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools.

Travel Requirements:
  • Occasional travel to our office may be requested up to once or twice a year

BENEFITS & PERKS:
Part of our mission is to provide a great life for our employees. We believe that when our people are happy, they do their best work. Some of the benefits and perks we offer include:
  • Flexibility to work Remotely
  • Medical, dental, and vision coverage with company-paid and employee-paid options
  • Paid holidays, sick days, and personal time off
  • Employee Resource Groups (ERGs) that foster connection and inclusion
  • On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
  • Dog-friendly campus and WiFi-accessible courtyards
  • 401(k) with a 5% company match
  • Coverage for employee professional development and wellness
  • And more!

Skills Required

  • Minimum 5 years experience in application security, DevSecOps, or related field
  • Hands-on experience securing applications in Azure environments
  • Experience with Azure Key Vault, Azure Security Center, and Azure DevOps
  • Expertise in SAST, DAST, SCA, and secrets management (e.g., HashiCorp Vault, Azure Key Vault)
  • Experience integrating security tools into CI/CD pipelines
  • In-depth understanding of secure development lifecycle (SDLC) and DevSecOps best practices
  • Vulnerability management experience including scanning, risk assessment, and remediation
  • Familiarity with security and compliance frameworks (OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR)
  • Ability to communicate security concepts to technical and non-technical stakeholders and collaborate cross-functionally
  • Experience developing and maintaining infrastructure as code (IaC) using Terraform
  • Security certifications (e.g., Microsoft Certified: Azure Security Engineer, CISSP, CCSP)
  • Threat modeling experience
  • Experience with microservices architecture and API security
  • Familiarity with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua

What the Team is Saying

Jordan Bales
Falk Hoeppner
Sierra
Betty
Henry

HCSS Compensation & Benefits Highlights

  • Healthcare Strength Company-paid medical and dental premiums for employees, along with company-paid life insurance and short/long-term disability, are prominently listed; multiple Cigna plan options and strong core coverage are emphasized. These protections are repeatedly described as a standout element of the package.
  • Wellbeing & Lifestyle Benefits A campus with an on-site gym and fitness classes, sports courts/fields, a track, wellness funds (often cited up to $1,000), free snacks, and catered Friday lunches are highlighted. These amenities and funds materially enhance day-to-day experience, especially for those near the Sugar Land campus.
  • Parental & Family Support Paid parental leave provides up to 6 weeks for primary caregivers and up to 3 weeks for secondary caregivers, with maintained health benefits during qualifying FMLA leave. This sits alongside other family-friendly policies noted in employer materials.

HCSS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sugar Land, TX
589 Employees
Year Founded: 1986

What We Do

Since 1986, HCSS been developing software to help construction companies streamline their operations. Today, HCSS is recognized as a pioneer and leader in the market, serving thousands of construction companies across the nation. Year after year, they continue to innovate, refine, and expand their products as the industry evolves. HCSS'​ mission is to help customers dramatically improve their business through innovative, high-quality software and exceptionally helpful service, while providing a great life for employees.

Why Work With Us

At HCSS, we prioritize people—empowering both our customers and employees to achieve excellence. We promote from within, provide continuous professional growth, and embrace challenges as learning opportunities. Join us to build a meaningful career while delivering exceptional solutions and service.

Gallery

Gallery
Gallery
Gallery

HCSS Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We support a flexible, hybrid work environment that empowers employees to do their best work while balancing the needs of their lives outside of work.

Typical time on-site: Flexible
HQSugar Land, TX

Similar Jobs

Remote or Hybrid
USA
589 Employees
Remote or Hybrid
USA
589 Employees
Remote or Hybrid
USA
589 Employees
Remote or Hybrid
USA
589 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account