Senior DevSecOps Engineer

Posted 23 Days Ago
Hiring Remotely in USA
Remote or Hybrid
Senior level
Software
Empowering Construction Through Innovative Software
The Role
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Summary Generated by Built In
We are HCSS. For the last 40 years, we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer. We have earned Best Companies to Work for in Texas honors for 18 consecutive years and have been named a USA Today Top Workplace. HCSS has also been recognized by Built In as a Best Place to Work in Greater Houston and by Construction Executive for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence.

WHO WE NEED: 
As a Senior DevOps Engineer specializing in DevSecOps and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development
teams deliver secure software at scale.

Requirements:
  • 8+ years of experience in DevOps, DevSecOps, application security, security engineering, software engineering, platform engineering, or a related technical field.
  • Strong hands-on experience with cloud services, preferably Azure, including application hosting, networking, storage, databases, identity, monitoring, access control, and security services.
  • 5+ years of experience designing, developing, securing, and maintaining CI/CD pipelines using tools such as Azure DevOps, GitHub Actions, YAML, GitLab CI, Jenkins, or similar platforms.
  • Strong experience embedding security tools and controls into CI/CD pipelines, including SAST, DAST, SCA, secrets scanning, dependency scanning, container scanning, and other automated security validation tools
  • Deep understanding of secure SDLC, DevSecOps principles, secure software development practices, and modern application security concepts.
  • Strong understanding of OWASP Top 10, API security, authentication, authorization, input validation, session management, encryption, secure error handling, secrets handling, and software supply chain risk.
  • Experience identifying, triaging, prioritizing, and driving remediation of application security vulnerabilities across new and existing applications.
  • Experience with vulnerability management practices, including security scanning tools, risk assessment, remediation tracking, exception handling, and risk acceptance workflows.
  • Experience with secrets management solutions such as Azure Key Vault, HashiCorp Vault, or equivalent technologies
  • Experience with scripting and automation using PowerShell, Azure CLI, Bash, Python, Go, or similar technologies.
  • Ability to read, understand, and reason about application code in one or more modern programming languages such as C#, Java, JavaScript, TypeScript, Python, Go, or similar.
  • Familiarity with security and compliance frameworks such as OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Strong troubleshooting, analytical, and problem-solving skills
  • Excellent communication skills with the ability to explain security concepts, risks, and remediation guidance to both technical and non-technical stakeholders.
  • Ability to work independently, manage multiple priorities, and collaborate effectively with cross-functional teams.
  • Proactive attitude toward continuous improvement, automation, secure engineering practices, and developer enablement.

Bonus Qualifications:
  • Advanced cloud, DevOps, or security certifications such as AZ-400, Microsoft Certified: Azure Security Engineer, CISSP, CSSLP, CCSP, GWEB, GWAPT, or equivalent.
  • Strong hands-on experience with Azure security services such as Azure Key Vault,
  • Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID, Azure Monitor, Azure DevOps, and related Azure-native security capabilities.
  • Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.
  • Experience with threat modeling techniques and frameworks such as STRIDE, attack trees, abuse cases, or similar approaches.
  • Strong understanding of microservices architecture and API security practices.
  • Experience with OpenAPI/Swagger, OAuth2, OIDC, SAML, JWT, identity federation, and modern authentication and authorization patterns.
  • Experience creating developer-facing security documentation, secure coding guidance, reusable pipeline templates, and security training materials.
  • Experience building vulnerability dashboards, security KPIs, remediation workflows, and risk acceptance processes.

Role Responsibilities:

Vulnerability Management and Risk Governance 
  • Own or support application vulnerability management processes from detection through remediation, exception, or formal risk acceptance. 
  • Triage findings from security tools, penetration tests, dependency scans, cloud scans, code reviews, and internal assessments.
  • Prioritize vulnerabilities based on severity, exploitability, business impact, application criticality, exposure, compensating controls, and compliance requirements.
  • Partner with development teams to drive timely remediation of high-risk and recurring vulnerabilities. 
  • Track and communicate remediation progress, vulnerability trends, SLA performance, and application security posture to technical and non-technical stakeholders. 
  • Identify recurring vulnerability patterns and drive systemic improvements through automation, education, standards, and reusable security controls. 
  • Help define vulnerability remediation SLAs, exception processes, risk acceptance criteria, and security reporting standards. 

Cloud and Azure Security 
  • Design, implement, manage, and secure cloud-based application environments, preferably within Azure. 
  • Apply Azure security best practices using services such as Azure Key Vault, Microsoft Defender for Cloud, Azure Policy, Azure DevOps, identity and access controls, encryption, logging, and monitoring. 
  • Implement secure access patterns using RBAC, least privilege, managed identities, secure networking, encryption, and policy-based controls. 
  • Monitor and troubleshoot cloud services to help ensure secure, reliable, and high-performing application environments. 
  • Collaborate with stakeholders to design cloud solutions that meet current and future business, security, compliance, and operational needs. 
  • Support secure configuration and hardening of application hosting environments, databases, networking components, storage, and related platform services. 

Secrets Management
  • Implement, manage, and continuously improve secrets management practices across development, test, staging, and production environments. 
  • Use solutions such as Azure Key Vault, HashiCorp Vault, or equivalent platforms to protect sensitive information. 
  • Partner with teams to eliminate hardcoded secrets, improve secret rotation, and enforce secure access patterns. 
  • Integrate secrets scanning and prevention controls into source code repositories and CI/CD pipelines. 
  • Define standards for secret storage, access, lifecycle management, auditability, and remediation of exposed secrets. 

Developer Enablement and Security Culture 
  • Act as a trusted security and DevOps advisor to developers, architects, QA engineers, product teams, and engineering managers.
  • Create practical secure coding guidance, reusable examples, internal documentation, reference patterns, and developer-friendly security standards. 
  • Conduct training, workshops, and coaching on topics such as OWASP Top 10, API security, secure coding, CI/CD security, secrets management, dependency risk, and cloud security. 
  • Mentor and guide junior DevOps engineers and help raise the overall security maturity of engineering teams. 
  • Promote a collaborative security culture where security is embedded into engineering practices rather than treated as a blocker. 
  • Influence teams through partnership, automation, practical guidance, and risk-based decision-making. 

Governance, Compliance, and Standards 
  • Contribute to application security standards, secure coding policies, cloud security standards, pipeline requirements, and DevSecOps governance. 
  • Ensure applications, cloud environments, pipelines, and development workflows align with organizational security and compliance requirements. 
  • Support compliance with frameworks and standards such as OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR, or similar. 
  • Help define and enforce security policies related to application security, cloud security, vulnerability remediation, secrets management, and CI/CD practices. 
  • Continuously evaluate the effectiveness of security tooling, automation, standards, and processes. 

Travel Requirements:
  • Occasional travel to our office may be requested up to once or twice a year

BENEFITS & PERKS:
Part of our mission is to provide a great life for our employees. We believe that when our people are happy, they do their best work. Some of the benefits and perks we offer include:
  • Flexibility to work Remotely
  • Medical, dental, and vision coverage with company-paid and employee-paid options
  • Paid holidays, sick days, and personal time off
  • Employee Resource Groups (ERGs) that foster connection and inclusion
  • On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
  • Dog-friendly campus and WiFi-accessible courtyards
  • 401(k) with a 5% company match
  • Coverage for employee professional development and wellness
  • And more!

Skills Required

  • Minimum 5 years experience in application security, DevSecOps, or related field
  • Hands-on experience securing applications in Azure environments
  • Experience with Azure Key Vault, Azure Security Center, and Azure DevOps
  • Expertise in SAST, DAST, SCA, and secrets management (e.g., HashiCorp Vault, Azure Key Vault)
  • Experience integrating security tools into CI/CD pipelines
  • In-depth understanding of secure development lifecycle (SDLC) and DevSecOps best practices
  • Vulnerability management experience including scanning, risk assessment, and remediation
  • Familiarity with security and compliance frameworks (OWASP, NIST, CIS, SOC 2, ISO 27001, PCI DSS, GDPR)
  • Ability to communicate security concepts to technical and non-technical stakeholders and collaborate cross-functionally
  • Experience developing and maintaining infrastructure as code (IaC) using Terraform
  • Security certifications (e.g., Microsoft Certified: Azure Security Engineer, CISSP, CCSP)
  • Threat modeling experience
  • Experience with microservices architecture and API security
  • Familiarity with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua

What the Team is Saying

Jordan Bales
Falk Hoeppner
Sierra
Betty
Henry

HCSS Compensation & Benefits Highlights

  • Healthcare Strength Company-paid medical and dental premiums, plus employer-paid life, disability, and long-term care, point to broad and generous core coverage. Multiple plan options are described with strong employer contributions.
  • Wellbeing & Lifestyle Benefits An amenity-rich campus (gyms, fitness classes, sports courts/fields, track/trail) and a dedicated wellness fund are emphasized, alongside snacks and regular catered meals. These everyday perks are presented as central to the employee experience.
  • Parental & Family Support Paid parental leave for primary and secondary caregivers is outlined, with maintained health benefits under FMLA and onsite facilities like a Mother’s Room. These policies are positioned to support work–family balance.

HCSS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sugar Land, TX
589 Employees
Year Founded: 1986

What We Do

Since 1986, HCSS been developing software to help construction companies streamline their operations. Today, HCSS is recognized as a pioneer and leader in the market, serving thousands of construction companies across the nation. Year after year, they continue to innovate, refine, and expand their products as the industry evolves. HCSS'​ mission is to help customers dramatically improve their business through innovative, high-quality software and exceptionally helpful service, while providing a great life for employees.

Why Work With Us

At HCSS, we prioritize people—empowering both our customers and employees to achieve excellence. We promote from within, provide continuous professional growth, and embrace challenges as learning opportunities. Join us to build a meaningful career while delivering exceptional solutions and service.

Gallery

Gallery
Gallery
Gallery

HCSS Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We support a flexible, hybrid work environment that empowers employees to do their best work while balancing the needs of their lives outside of work.

Typical time on-site: Flexible
HQSugar Land, TX

Similar Jobs

Remote or Hybrid
Houston, TX, USA
589 Employees
Remote or Hybrid
USA
589 Employees
Remote or Hybrid
USA
589 Employees
Remote or Hybrid
USA
589 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account