Source Job

Global Unlimited PTO

  • Own and enforce DevSecOps practices across CI/CD pipelines.
  • Drive vulnerability identification, triage, and remediation across infrastructure and applications.
  • Act as the primary security SME for the engineering organization.

DevSecOps SAST DAST SCA Cloud Security

20 jobs similar to Manager, DevSecOps Engineering

Jobs ranked by similarity.

EMEA

  • Embed security into CI/CD pipelines and own secure controls.
  • Lead the process of vulnerability and patch management, automating discovery.
  • Strengthen cloud and Kubernetes environments through secure configurations.

Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure provider for stocks, ETFs, options, crypto, fixed income, and more. They are a dynamic team of 230+ globally distributed members committed to opening financial services to everyone.

$435,468–$458,056/yr
US Unlimited PTO

  • Design, implement, and manage the integration of security tooling into CI/CD pipelines.
  • Develop and maintain automation scripts to streamline security processes and workflows.
  • Own the vulnerability management lifecycle: identification, triage, prioritization, and reporting.

MoonPay is a unified payments platform for digital currency, making it easy for anyone to buy, sell, swap, and pay in digital currencies. Trusted by over 30 million customers and over 500 ecosystem partners, MoonPay's secure, enterprise-grade platform is driving mainstream crypto adoption worldwide.

Global

  • Integrate security activities across all SDLC phases.
  • Partner closely with engineering teams to ensure secure development practices.
  • Review security controls for new features, services, and architectural changes.

Infiterra simplifies subscription service delivery, enabling IT distributors, Managed Service Providers (MSPs), and telcos to succeed in the subscription economy. They are recognized as a global leader in subscription commerce, combining innovation, performance excellence, and trusted expertise to help partners transform and grow.

US Unlimited PTO

  • Lead security architecture and design reviews across applications, infrastructure, and integrations.
  • Conduct and coordinate penetration testing, threat modeling, and security reviews.
  • Design and implement security automation within CI/CD pipelines.

Assured modernizes insurance by providing software solutions to large insurers that help them win in a technology-driven world. Their products include self-service claim-filing software to backend fraud detection and are dynamic, collaborative, and rewarding.

$160,000–$188,000/yr
US Unlimited PTO

  • Own and drive the company’s security strategy, roadmap, and overall posture
  • Lead threat modeling, secure code reviews, and architecture reviews
  • Build and maintain security tooling, automation, and infrastructure as code

Seesaw's mission is to provide every elementary student with joyful and connected learning experiences that lay the foundation for success in life. Trusted and loved by 25 million educators, students, and families worldwide, Seesaw is the only elementary learning experience platform.

$180,000–$190,000/yr
US

  • Embed security into the SDLC by partnering with Engineering to implement secure design patterns, conduct threat modeling, and deliver developer-focused AppSec training.
  • Lead and perform application security assessments including SAST, DAST, SCA, and manual code review across web, mobile, and API surfaces.
  • Own and mature the vulnerability management program, including prioritization frameworks, SLA tracking, and cross-functional remediation coordination.

Branch is on a mission to empower workers with financial freedom by helping companies accelerate payments and providing working Americans with accessible, free financial services. They are committed to building inclusive and transparent financial products while valuing diversity of opinions and working styles, fostering innovation, and promoting teamwork.

US Unlimited PTO

  • Focus on automation, integrating security within the CI/CD pipeline, and DevOps toolchain.
  • Strong working knowledge of security fundamentals including OWASP Top10.
  • Experience with public cloud infrastructure (AWS or Azure) and cloud security fundamentals.

GuidePoint Security provides cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. They have grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serve as a trusted advisor to more than 6,200 customers.

India

  • Own and evolve vulnerability management end-to-end.
  • Embed secure design principles across mobile applications, APIs, and microservices.
  • Partner closely with engineering teams to remediate security issues.

Smart Working connects skilled professionals with global teams for full-time, long-term roles. They help you discover meaningful work with teams that invest in your success, where you’re empowered to grow personally and professionally.

US

  • Design and implement scalable vulnerability scanning solutions.
  • Automate vulnerability ingestion, prioritization, and remediation workflows.
  • Partner with Engineering and DevOps teams to remediate vulnerabilities.

Keeper Security is a cybersecurity software company protecting organizations and individuals globally. They are known for zero-knowledge and zero-trust security, securing passwords, infrastructure secrets, and remote connections with role-based enforcement policies.

Global

  • Build AI agents that handle vulnerability triage, automated security reviews of PRs, and initial incident forensics at scale.
  • Build systems that automatically detect and remediate security gaps across AWS, GCP, and Azure -- configuration drift, IAM misconfigurations, vulnerable dependencies, exposed secrets.
  • Lead threat modeling, security reviews, and risk assessments across web applications, APIs, and services.

Atlan is building the missing context layer for data and AI, helping enterprises close the AI value chasm. They connect to every part of the modern data and AI stack to unify this context into a single, shared layer that both humans and AI agents can rely on.

$66,000–$106,000/yr
US

  • Responsible for supporting the integration of security, automation, and operational controls into development and deployment pipelines to enable secure, reliable delivery of MODES III systems.
  • Supports development, implementation, and maintenance of CI/CD pipelines that integrate security, testing, and compliance controls.
  • Assists with automation of build, deployment, and configuration processes to improve reliability, repeatability, and deployment efficiency.

Peraton is a next-generation national security company that drives missions of consequence spanning the globe. As the world’s leading mission capability integrator and transformative enterprise IT provider, they deliver trusted, highly differentiated solutions and technologies.

US

  • Design, implement, and sustain security architecture across AWS GovCloud.
  • Execute and maintain RMF activities across all system components.
  • Implement, validate, and continuously maintain DISA STIG compliance across all infrastructure components.

Foxhole Technology provides robust cybersecurity and IT support capabilities for federal civilian and defense agencies. A recognized leader in navigating technology and security challenges, Foxhole delivers mission-focused innovations to answer evolving and complex needs.

$90,000–$135,000/yr
US

  • Contribute to automated response patterns for security alerts.
  • Embed security controls into CI/CD pipelines.
  • Support governance controls for secure AI usage.

Oddball builds products when companies understand what they are working on. They value learning, growth, and the ability to make a big impact at a small company.

$200,000–$260,000/yr
US

  • Lead the ongoing maintenance and operation of secure cloud infrastructures, focusing on AWS and cloud-native technologies.
  • Secure applications built for cloud environments by automating security assessments, monitoring runtime environments, and integrating security practices into the development lifecycle.
  • Implement robust security controls for cloud workloads and data, including containers, virtual machines, and serverless architectures.

Ro is a direct-to-patient healthcare company with a mission of helping patients achieve their health goals by delivering the easiest, most effective care possible. Ro is the only company to offer nationwide telehealth, labs, and pharmacy services and is recognized as a top workplace, earning more than 20 honors since 2021.

US

  • Assist in designing and maintaining secure infrastructure on EKS in our multi-cloud environment (AWS) using Infrastructure as Code (Terraform).
  • Write code (Python, Go, or Bash) to automate manual tasks, threat detection, and vulnerability management processes.
  • Integrate security tools (SAST, DAST, SCA) into our CI/CD pipelines, ensuring developers receive fast, actionable feedback on their code.

Smartsheet helps people and teams achieve anything with seamless work management and scalable solutions. They empower teams to automate the manual, uncover insights, and scale smarter, creating space for impactful work. The company values diverse perspectives and supports employee growth.

Europe

  • Participate in threat modeling exercises with engineering team members
  • Triage SCA/SAST/DAST/CSPM findings by eliminating false positives and providing well-vetted vulnerabilities to engineering teams
  • Support vulnerability management efforts for networks and infrastructure

They offer a SaaS-based Global Employment Platform that enables clients to expand into over 180 countries. Their diverse, remote-first teams are essential to their success, fostering innovation and valuing every contribution.

$125,000–$175,000/yr
US

  • Architect, build, and maintain GitLab Pipelines for seamless application deployment.
  • Design, deploy, and manage infrastructure across AWS GovCloud, edge, and Navy networks using Terraform, Ansible, and GitLab.
  • Engineer automated processes for RHEL image hardening and execute automated STIG checklists.

LMI accelerates government impact with digital solutions and innovation. They bring commercial-grade platforms and mission-ready AI to federal agencies, focusing on agility and collaboration across defense, space, healthcare, and energy sectors.

US

  • Support the ISSM in managing security requirements and documentation throughout the SDLC.
  • Review Merge/Pull Requests for security implications and adherence to secure coding standards.
  • Analyze CI/CD pipeline security outputs, including SAST, DAST, SBOM findings, and CVSS scoring.

CommIT Enterprises, Inc. is a Certified Veteran-Owned Small Business (CVOSB) providing innovative technical engineering and data science services. Established in 2001, our enterprise systems support includes the Department of Defense’s (DoD) GCSS-MC, CAC2S, TBMCS-MC, and the Department of Veteran’s Affairs’ (VA) telehealth communications.

$165,000–$185,000/yr
Global Unlimited PTO

  • Own and lead Limble’s application security program, partnering with the Head of Information Security and key stakeholders to define strategy and roadmap.
  • Perform hands-on security work including threat modeling and secure design reviews, using engagements as opportunities to educate and influence engineering decisions.
  • Partner with engineering teams to triage, prioritize, and remediate vulnerabilities across the platform.

Limble empowers the unsung heroes who support the world by revolutionizing how businesses manage their maintenance operations. They provide a comprehensive suite of software solutions to optimize asset performance and drive operational excellence; their CMMS platform features streamline operations and enhance productivity.

$153,986–$192,482/yr
US

  • Design, develop, and implement cloud security architecture solutions in Microsoft Azure.
  • Build and maintain security automation using Infrastructure as Code (IaC) tools.
  • Collaborate with development and platform engineering teams to embed security into CI/CD pipelines.

Hanger, Inc. is the world's premier provider of orthotic and prosthetic (O&P) services and products, offering the most advanced O&P solutions, clinically differentiated programs and unsurpassed customer service. With 160 years of clinical excellence and innovation, Hanger's vision is to lead the orthotic and prosthetic markets by providing superior patient care, outcomes, services and value.