Devsecops Engineer Jobs
Devsecops engineer jobs are open across financial services, healthcare, government contracting, and technology, from mid-level to staff and principal, with specializations in cloud security automation, container security, and CI/CD pipeline hardening. Find a role that fits from the openings below and apply directly.
Find Devsecops Engineer JobsOverview
Showing 5 of 37+ Devsecops Engineer jobs











Position Summary:
CPI is looking for a DevSecOps Engineer to join our application engineering team. This is not a traditional DevOps role. This role must recognize and imbed security across the entire application delivery lifecycle. This teammate drives efficiency into the engineering team's work, while embedding controls, automation, and threat-aware thinking into every pipeline, deployment, and platform.
You'll work at the intersection of Salesforce delivery, cloud infrastructure, and application security, partnering with engineers and security teammates to ship faster and safer.
Key Responsibilities:
- Manage release engineering, branching strategies, automated deployments, metadata diffing, sandbox seeding, and rollback playbooks (Salesforce/GearSet are currently core applications)
- Design and operate secure CI/CD pipelines and cloud-native services (Salesforce, AWS, Snowflake)
- Work in conjunction with other IT teammates to identify and resolve technical pipeline issues and escalate items while retaining ownership
- Embed automated security gates (SAST, DAST, SCA, IaC scanning), container image scanning, and secrets detection directly into developer workflows
- Support and extend AI and Snyk code quality gates
- Architect and maintain AWS infrastructure IaC (Terraform), with security baselines enforced via policy-as-code
- Containerize workloads with Docker, orchestrate via ECS/EKS (or AKS), and harden images against CVEs and supply-chain attacks (SBOMs, signing, provenance)
- Partner with security team for pipeline incident response and infrastructure security events and postmortems
- Continuously evaluate tool alerts and reduce alert fatigue through tuning and automation
- Support and troubleshoot all pipeline & IaC tools to ensure engineering adoption
- Contribute to scrum ceremonies as a technical voice on delivery, release readiness, and risk
Core Experience
- 10+ years of professional software development experience across one or more of: Java, .NET/C#, Python, Node.js, or Apex
- 5+ years in a DevOps, SRE, or Platform Engineering role, with at least the last 2 years explicitly focused on DevSecOps practices
- Demonstrated history of owning production systems end-to-end (design, deployment, monitoring, and incident response)
- Independent problem solver able to investigate, identify, evaluate, and drive practical solutions
Salesforce Delivery
- Hands-on experience for Salesforce CI/CD: pipeline configuration, automated testing, problem analysis, and unit test coverage enforcement (GearSet preferred)
- Strong understanding of Salesforce metadata, sandbox strategy, and Apex test automation
- Experience integrating Salesforce deployments with Git-based source-of-truth workflows
Cloud & Infrastructure
- AWS at depth: IAM, VPC design, KMS, Secrets Manager, GuardDuty, Security Hub, CloudTrail, Config, WAF
- Docker and container orchestration (ECS, EKS, or Kubernetes) in production
- Infrastructure as Code: Terraform (preferred) with modular, reusable, policy-checked patterns.
- CI/CD platforms: GitHub Actions, GitLab CI, Jenkins, or CircleCI
Security Tooling & Practices
- SAST/DAST/SCA tooling; e.g. Snyk (preferrable), Checkmarx, SonarQube
- Container/image scanning, SBOM generation, and policy-as-code
Soft Skills
- Strong communication — you can explain a vulnerability to an executive and a regex to a junior engineer in the same afternoon
- Pragmatic risk thinker — you know when to block a deploy and when to file a ticket
- Collaborative; sensitive to "security as a department of no"
Nice to Have
- Salesforce certifications (Platform Developer I/II)
- AWS certifications (Solutions Architect Professional, Security Specialty)
See All 37+ Devsecops Engineer Jobs
Jump back to the full list of openings and apply to any devsecops engineer role that fits.
Find Devsecops Engineer JobsDevsecops Engineer Job Market
A snapshot from current openings nationwide, updated as new roles post.
Who's Hiring
- AEM Corporation2

- Crown Castle2

- DoubleVerify2

- Equinix2

- Gap2

Top Industries Hiring
- Technology & Software18
- Consulting & Professional Services3
- Retail3
- Healthcare & Medical Services2
- Investment & Asset Management2
What Employers Look For
The qualifications that appear most often in devsecops engineer jobs.
- Experience securing CI/CD pipelines using tools such as Jenkins, GitHub Actions, or GitLab CI
- Proficiency with infrastructure-as-code tools including Terraform, Ansible, or CloudFormation
- Hands-on knowledge of container security in Kubernetes or Docker environments
- Familiarity with cloud security controls across AWS, Azure, or Google Cloud Platform
- Experience with SAST, DAST, or SCA tooling integrated into development workflows
- Bachelor's degree in computer science, cybersecurity, or a related technical field
Tips for Your Devsecops Engineer Job Search
Tailor your resume to the stack
Hiring managers scan for specific tools before reading anything else. List the exact platforms you've worked with, such as Terraform, Kubernetes, Vault, or Falco, in a dedicated skills section so your resume clears automated filters quickly.
Certify before you apply to federal roles
Government and defense contractors almost always require a DoD 8570 or 8140 baseline certification like Security+ or CISSP. If you're targeting those postings, confirm your certification is active and list it prominently near the top of your resume.
Apply early to roles that fit
Migrate Mate lists devsecops engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Show pipeline ownership, not participation
Recruiters distinguish candidates who built and owned secure CI/CD pipelines from those who contributed to them. Describe the scope of what you owned, the threat model you addressed, and the measurable outcome, rather than listing tools you touched.
Prepare for a live threat-modeling exercise
Many devsecops engineer interviews include a whiteboard or collaborative threat-modeling session rather than a purely algorithmic coding round. Practice walking through an architecture diagram, naming attack surfaces, and proposing controls out loud before your first technical screen.
Negotiate on scope before salary
Devsecops roles vary widely in actual authority. Before discussing compensation, clarify whether the role has enforcement power over developers or is purely advisory. That distinction changes the job's day-to-day demands and your leverage in the offer conversation.
Devsecops Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most devsecops engineers?
The companies hiring the most devsecops engineers right now include AEM Corporation, Crown Castle, and DoubleVerify, with the largest share of openings in Texas, Massachusetts, and North Carolina, based on current listings on Migrate Mate as of June 2026. Demand is concentrated in technology, defense contracting, and financial services.
How many devsecops engineer jobs are remote?
About 41% of devsecops engineer openings are fully remote or hybrid as of June 2026, making it one of the more distributed roles in the security field. Cloud-focused and platform engineering sub-areas tend to offer the most remote flexibility, while roles involving classified systems or on-premises infrastructure typically require in-office presence.
How do you become a devsecops engineer?
Start with a foundation in either software development or systems administration, then layer in security fundamentals through a certification like Security+ or Certified Kubernetes Security Specialist. Build practical experience by hardening CI/CD pipelines in personal or open-source projects, then move into a security engineering or platform engineering role where you can take on devsecops responsibilities directly.
Can you get hired as a devsecops engineer without direct experience?
Yes, candidates with strong software engineering or cloud infrastructure backgrounds can transition into devsecops engineer roles by demonstrating security depth through certifications and hands-on projects. Contributing to open-source security tooling, publishing a pipeline-hardening write-up, or earning a cloud security specialty credential signals practical readiness to hiring managers who are evaluating non-traditional backgrounds.
What does the devsecops engineer interview process look like?
Most devsecops engineer interviews include an initial recruiter screen, a technical phone interview covering CI/CD and security tooling, and a practical round that often involves a threat-modeling exercise or a live pipeline review. Final rounds typically include a system design conversation focused on secure architecture and a behavioral interview with engineering leadership assessing cross-functional collaboration.
Where can I find and apply to devsecops engineer jobs?
You can find and apply to devsecops engineer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience and specialization, then apply directly to each listing from the page.
See All 37+ Devsecops Engineer Jobs
Jump back to the full list of openings and apply to any devsecops engineer role that fits.
Find Devsecops Engineer Jobs