Senior DevSecOps Engineer

Posted 4 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Artificial Intelligence • Information Technology
The Role
Designs and operates security automation across the software development lifecycle, integrating security tools with ticketing, CI/CD, cloud, and engineering systems. Builds secure pipelines, policy-as-code guardrails, vulnerability-management workflows, and automated compliance controls. Secures cloud infrastructure, containers, Kubernetes, identities, secrets, and software supply chains. The role also supports threat modeling, security architecture, incident response, metrics, remediation, and cross-functional security initiatives while mentoring engineers.
Summary Generated by Built In

Who We Are:

Exiger is the AI partner for supply chain and procurement automation. Its centralized 1EXIGER.AI platform allows organizations to manage their entire operating network, from parts to suppliers, regulators, and customers, through an autonomous agentic workforce that learns, adapts, and augments with every decision. The AI-native platform, combined with the largest supply chain knowledge asset, empowers 550+ global customers, including 150 Fortune 500 and 80+ government and defense industrial organizations, to act first. Exiger is FedRAMP® authorized and a 2x Leader in Gartner® Magic Quadrant™ for Supplier Risk Management.

Senior DevSecOps Engineer

Location: Richmond, VA preferred

Position Summary

The Senior DevSecOps Engineer is a hands-on technical leader responsible for embedding scalable security controls, automation, and secure engineering practices throughout the software development lifecycle.

As a member of the Security team, this role partners closely with Engineering, Cloud, Platform, IT, and Compliance teams to automate security processes, improve vulnerability and finding management, and provide timely security feedback without creating unnecessary delivery friction.

A key focus of this role is security automation. The successful candidate will have experience building automated workflows that integrate security tools with engineering and operational systems, including automated ticket creation, routing, enrichment, escalation, remediation tracking, and reporting.

The ideal candidate combines strong DevSecOps and cloud security expertise with hands-on software development and automation experience and is comfortable operating in regulated, cloud-based environments.

Responsibilities
  • Design, build, and maintain automated security workflows across the software development lifecycle and broader security environment.

  • Automate security processes such as vulnerability intake, ticket creation, assignment, enrichment, escalation, remediation tracking, exception handling, and reporting.

  • Integrate security platforms with ticketing, CI/CD, cloud, and engineering systems using APIs, webhooks, scripts, and workflow automation.

  • Embed automated application, dependency, secrets, infrastructure-as-code, container, and API security testing into CI/CD pipelines.

  • Define and implement risk-based release gates, remediation timelines, exception processes, and finding ownership.

  • Build reusable secure pipeline templates, hardened images, self-service security controls, and policy-as-code guardrails.

  • Strengthen security across cloud infrastructure, containers, Kubernetes, identity, secrets management, networking, and deployment processes.

  • Triage vulnerabilities and security findings based on severity, exploitability, exposure, asset criticality, and business impact.

  • Automate vulnerability-management workflows to ensure findings are routed to the appropriate owners and tracked through remediation.

  • Secure source code, third-party dependencies, build systems, artifacts, container images, and software supply-chain processes.

  • Support application security reviews, threat modeling, security architecture reviews, monitoring, and incident-response activities.

  • Translate regulatory and compliance requirements into scalable technical controls and automated audit evidence.

  • Partner directly with Engineering teams to remediate security issues and promote secure development practices.

  • Evaluate and integrate emerging security capabilities and technologies.

  • Develop metrics and dashboards to measure security posture, remediation performance, and automation effectiveness.

  • Lead cross-functional security initiatives and mentor engineers on DevSecOps and secure engineering practices.

Required Qualifications
  • Eight or more years of experience in DevOps, platform engineering, cloud engineering, application security, product security, DevSecOps, or cybersecurity engineering.

  • Significant hands-on experience designing, implementing, and operating DevSecOps capabilities in production environments.

  • Demonstrated experience building security automation, including integrations between security tools, ticketing platforms, CI/CD systems, and engineering workflows.

  • Strong software development or scripting experience using Python and/or Java, with additional experience in technologies such as PowerShell, Bash, JavaScript, or TypeScript.

  • Ability to develop maintainable, reusable, and tested automation rather than relying solely on one-time scripts.

  • Strong knowledge of REST APIs, webhooks, and systems integrations.

  • Experience automating ticket creation, assignment, escalation, remediation tracking, or similar security operational workflows.

  • Strong knowledge of CI/CD security, application security testing, vulnerability management, and software supply-chain security.

  • Experience securing cloud platforms, containerized workloads, Kubernetes, infrastructure as code, Linux, networking, identity, encryption, logging, and secrets management.

  • Knowledge of SAST, DAST, software composition analysis, secrets scanning, container scanning, infrastructure-as-code scanning, and related DevSecOps controls.

  • Knowledge of threat modeling, OWASP guidance, web and API security, authentication, authorization, and secrets management.

  • Experience prioritizing vulnerabilities and security findings based on technical and business risk.

  • Strong communication skills with the ability to explain security risks, remediation options, and engineering tradeoffs to technical and non-technical stakeholders.

  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related discipline, or equivalent practical experience.

Preferred Qualifications
  • Hands-on experience with one or more of the following security platforms:

    • CrowdStrike

    • Microsoft Sentinel

    • Aikido Security

    • Code42

    • Qualys

  • Experience integrating security platforms with Jira, ServiceNow, or similar ticketing and workflow systems.

  • Experience with security orchestration, automation, and response (SOAR) platforms or equivalent automated security workflows.

  • Experience with cloud-native security technologies such as Kubernetes, Docker, Terraform, Helm, and cloud IAM.

  • Experience with policy-as-code technologies such as OPA, Rego, Kyverno, or similar tools.

  • Familiarity with SBOMs, artifact signing, dependency security, provenance, and software supply-chain frameworks.

  • Experience supporting regulated environments and frameworks such as FedRAMP, NIST, SOC 2, ISO 27001, or similar standards.

  • Experience developing security metrics, dashboards, and automated compliance evidence.

Exiger is named a Leader in the Gartner® Magic Quadrant™ for Supplier Risk Management, twice selected as one of Fast Company's 'Brands That Matter,' and recipient of the Third Party Risk Association's Innovator Award, Exiger's technology has been recognized by leading analyst evaluations and 50+ awards. Learn more at Exiger.com and follow Exiger on LinkedIn.

At Exiger, our values define how we work and why we lead. We are mission-inspired, imagination-driven, trust-anchored, and compassion-focused—committed to building technology that makes the world safer, more transparent, and more resilient.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Exiger’s hybrid work policy is periodically reviewed and adjusted to align with evolving business needs.

Skills Required

  • Eight or more years of experience in DevOps, platform engineering, cloud engineering, application security, product security, DevSecOps, or cybersecurity engineering.
  • Hands-on experience designing, implementing, and operating DevSecOps capabilities in production environments.
  • Experience building security automation integrating security tools, ticketing platforms, CI/CD systems, and engineering workflows.
  • Strong software development or scripting experience using Python and/or Java.
  • Additional experience with PowerShell, Bash, JavaScript, or TypeScript.
  • Ability to develop maintainable, reusable, and tested automation.
  • Strong knowledge of REST APIs, webhooks, and systems integrations.
  • Experience automating ticket creation, assignment, escalation, remediation tracking, or similar security workflows.
  • Strong knowledge of CI/CD security, application security testing, vulnerability management, and software supply-chain security.
  • Experience securing cloud platforms, containerized workloads, Kubernetes, infrastructure as code, Linux, networking, identity, encryption, logging, and secrets management.
  • Knowledge of SAST, DAST, software composition analysis, secrets scanning, container scanning, infrastructure-as-code scanning, and related DevSecOps controls.
  • Knowledge of threat modeling, OWASP guidance, web and API security, authentication, authorization, and secrets management.
  • Experience prioritizing vulnerabilities and security findings based on technical and business risk.
  • Strong communication skills for explaining security risks, remediation options, and engineering tradeoffs.
  • Bachelor’s degree in computer science, cybersecurity, engineering, or a related discipline, or equivalent practical experience.
  • Hands-on experience with CrowdStrike, Microsoft Sentinel, Aikido Security, Code42, or Qualys.
  • Experience integrating security platforms with Jira, ServiceNow, or similar ticketing and workflow systems.
  • Experience with SOAR platforms or equivalent automated security workflows.
  • Experience with Kubernetes, Docker, Terraform, Helm, and cloud IAM.
  • Experience with policy-as-code technologies such as OPA, Rego, or Kyverno.
  • Familiarity with SBOMs, artifact signing, dependency security, provenance, and software supply-chain frameworks.
  • Experience supporting regulated environments and frameworks such as FedRAMP, NIST, SOC 2, or ISO 27001.
  • Experience developing security metrics, dashboards, and automated compliance evidence.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA

What We Do

Exiger is revolutionizing the way corporations, government agencies and banks manage risk through its combination of technology-enabled and SaaS solutions. In recognition of the growing volume and complexity of data and regulation, Exiger is committed to creating a more sustainable risk and compliance environment through its holistic and innovative approach to problem solving. Exiger’s mission to make the world a safer place to do business drives its award-winning AI technology platform built to anticipate the market’s most pressing needs related to evolving ESG, cyber, financial crime, third-party and supply chain risk. Over the past four years, Exiger has achieved in excess of 100% compound annual growth in software license revenue worldwide, winning 30+ AI, RegTech and Supply Chain partner awards. Learn more at Exiger.com and Follow us on LinkedIn. WANT TO WORK WITH US? Exiger is hiring! We have many exciting global opportunities across our business. Please visit our Careers page at https://www.exiger.com/careers/ to view our open positions

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

Devsecops Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling, VA, USA
40000 Employees
150K-254K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Devsecops Engineer

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Sterling, VA, USA
40000 Employees
147K-249K Annually

Peraton Logo Peraton

Platform Engineer

Aerospace • Information Technology • Security • Cybersecurity • Defense
In-Office
3 Locations
18000 Employees
112K-179K Annually

MetroStar Logo MetroStar

Devsecops Engineer

Information Technology • Consulting
In-Office
Reston, VA, USA
250 Employees
170K-235K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account