DevSecOps Engineer

Job Code
DevSecOps-082526
Location
Remote
Terms
Contract / Full-Time • 3+ Years Experience
Salary/Rate
Depends on Experience
Skills Required
Cloud security, CI/CD pipeline security, vulnerability management, SAST and DAST, secure software supply chain, WAF and DDoS protection, IAM and RBAC, secrets management, SIEM and security monitoring, incident response

Job Overview

We are seeking an experienced DevSecOps Engineer to design, automate, implement, and maintain security controls across enterprise cloud and Drupal environments.

The DevSecOps Engineer will integrate security throughout the application and infrastructure lifecycle, ensuring that cloud systems and Drupal applications are secure by design, continuously monitored, appropriately hardened, and supported by automated security controls.

Responsibilities

  • Design and implement DevSecOps practices for enterprise cloud and Drupal environments.
  • Integrate security controls into CI/CD pipelines.
  • Implement automated vulnerability scanning and security testing.
  • Configure SAST, DAST, dependency, container, and infrastructure security scanning.
  • Implement secure software supply-chain practices.
  • Support Software Bill of Materials (SBOM) processes.
  • Implement cloud security configuration and continuous monitoring.
  • Configure and maintain Web Application Firewall (WAF) protections.
  • Support DDoS protection and mitigation.
  • Implement secure secrets and credential management.
  • Configure and review Role-Based Access Control (RBAC).
  • Enforce least-privilege access.
  • Support Identity and Access Management (IAM).
  • Implement operating-system and infrastructure hardening.
  • Conduct cloud configuration and security posture reviews.
  • Manage vulnerability identification, prioritization, remediation, and reporting.
  • Coordinate infrastructure and application security patching.
  • Monitor and support Drupal security advisories and remediation.
  • Integrate security logging with SIEM platforms.
  • Develop security alerts and detection mechanisms.
  • Participate in security incident investigation and response.
  • Support penetration testing and remediation.
  • Implement encryption for data at rest and in transit.
  • Review Infrastructure-as-Code for security weaknesses.
  • Support backup and disaster recovery security.
  • Develop security procedures, runbooks, incident-response plans, and compliance documentation.

Skills and Qualifications

Required Skills and Qualifications

  • 3+ years of DevSecOps, Cloud Security, Cybersecurity Engineering, Application Security, or related experience.
  • Experience securing enterprise applications in cloud environments.
  • Hands-on experience with AWS, Microsoft Azure, Google Cloud, or comparable platforms.
  • Experience securing CI/CD pipelines.
  • Experience with cloud IAM and access-control technologies.
  • Strong understanding of vulnerability management.
  • Experience with SAST, DAST, and software-composition analysis.
  • Knowledge of WAF and DDoS protection.
  • Experience with secrets management.
  • Understanding of Linux and web-server security.
  • Experience with SIEM, centralized logging, and security monitoring.
  • Knowledge of Infrastructure-as-Code security.
  • Understanding of security incident response.
  • Strong security documentation and reporting skills.

Preferred Drupal Security Experience

Experience with the following is highly desirable:

  • Drupal 9/10/11 security
  • Drupal security advisories
  • Drupal core and module patching
  • Composer dependency security
  • PHP application security
  • Acquia environments
  • Drupal access controls
  • Drupal configuration security
  • Secure Drupal deployment
  • Drupal vulnerability scanning
  • OWASP web application security practices

Preferred Security Technologies and Practices

  • SAST/DAST
  • Software Composition Analysis (SCA)
  • SBOM
  • OWASP Top 10
  • Vulnerability management
  • WAF
  • DDoS protection
  • IAM/RBAC
  • Secrets management
  • CIS Benchmarks
  • SIEM
  • Security incident response
  • Infrastructure-as-Code scanning
  • Cloud Security Posture Management
  • ISO 27001 security controls
  • Secure software supply chain
  • Container security

Preferred Certifications

  • AWS Certified Security: Specialty
  • Microsoft Azure Security Engineer
  • Certified Kubernetes Security Specialist (CKS)
  • CISSP
  • CCSP
  • CompTIA Security+
  • GIAC certifications
  • Certified Ethical Hacker (CEH)
  • Acquia or Drupal certifications
  • Other relevant cloud or cybersecurity certifications

Additional Requirements

Ideal Candidate

The ideal candidate is a hands-on DevSecOps and Cloud Security Engineer with experience integrating security into cloud infrastructure, CI/CD pipelines, and enterprise web applications.

The candidate should understand the intersection of cloud security, application security, automation, and Drupal operations and be capable of implementing security controls throughout the complete development, deployment, and production lifecycle.