Назад
Company hidden
обновлено 2 часа назад

DevSecOps Engineer

95 000 - 130 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Engineer (Cloud Security/CI/CD): Building and maintaining secure cloud infrastructure, CI/CD pipelines, automated testing environments, and compliance processes for firmware and software products with an accent on vulnerability management, security testing, and release reliability. Focus on automating infrastructure, integrating SAST/DAST/SCA and SBOM tooling, improving observability, and resolving complex development and security issues.

Location: Niwot, Colorado, United States; hybrid schedule with on-site work at least 3 days per week

Salary: $95,000–$130,000 annually, depending on experience

Company

hirify.global develops and manufactures micro-contamination monitoring equipment and related technologies for the semiconductor and pharmaceutical industries.

What you will do

  • Design and maintain secure cloud environments and CI/CD pipelines for firmware and software products.
  • Integrate automated security testing, vulnerability management, compliance controls, SBOM management, and continuous monitoring.
  • Collaborate with software, firmware, quality, and cybersecurity teams on secure development workflows, release strategies, and automated testing environments.
  • Automate provisioning and configuration of servers, containers, and infrastructure using IaC and configuration management tools.
  • Maintain artifact repositories, monitoring, logging, and observability solutions for CI/CD infrastructure.
  • Investigate vulnerabilities and incidents, troubleshoot complex development environments, and provide technical guidance across teams.

Requirements

  • Bachelor’s degree in Computer Science or a related engineering field.
  • Professional experience as a DevSecOps Engineer, security-focused DevOps Engineer, or in a similar role, including embedded firmware or software development.
  • Experience integrating SAST, DAST, SCA, SBOM, vulnerability scanning, and compliance tools into CI/CD pipelines.
  • Hands-on experience with binary repositories, AWS or another major cloud platform, IaC, configuration management, Docker, and CI/CD tools such as Jenkins, Bitbucket Pipelines, or GitHub Actions.
  • Strong scripting skills with Bash, Python, or PowerShell and familiarity with CMake, Make, Prometheus, and Grafana.
  • Strong troubleshooting, communication, collaboration, cybersecurity, vulnerability management, and shift-left development skills.

Nice to have

  • Expertise in Git and Atlassian development tools, including Bitbucket Pipelines.
  • Knowledge of Agile, DevOps, and DevSecOps methodologies, DORA metrics, software composition analysis, open-source compliance, SPDX, and CycloneDX.
  • AWS, cybersecurity, or DevSecOps certifications.
  • Familiarity with EN 18037, IEC 62443, and the EU Cyber Resilience Act.
  • Experience in multidisciplinary engineering environments.

Culture & Benefits

  • Hybrid work with regular on-site office, laboratory, and manufacturing environment attendance.
  • Medical, dental, vision, FSA, life insurance, and access to an on-site clinic for Colorado employees.
  • 401(k) retirement plan with company match.
  • Vacation, holidays, leave policies, tuition reimbursement, employee recognition, and employee assistance programs.
  • Inclusive and supportive workplace focused on challenging engineering projects.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →