Senior Application & DevSecOps Engineer

 Posted 5 months ago
     
5-10 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The Senior Application & DevSecOps Engineer is responsible for integrating security into the software development lifecycle and empowering developers to deliver secure software. This includes designing secure SDLC frameworks, conducting code reviews, and leading threat modeling sessions.

The Senior Application & DevSecOps Engineer is responsible for ensuring that security is built into every line of code and every stage of the software development lifecycle (SDLC). This is a hands-on engineering role that requires a deep understanding of modern software architecture, microservices, and automated delivery pipelines.

You will act as the technical authority for Product Security, performing everything from manual code reviews and threat modeling to the integration of automated security gates. Your mission is to empower developers to ship high-quality, secure software without compromising velocity.

What you will do:

Secure SDLC & Pipeline Integration

  • Design and implement the Secure SDLC framework, integrating security gates directly into DevOps pipelines.
  • Deploy and manage SAST, DAST, and SCA tooling (e.g., Veracode, Checkmarx, SonarQube, Snyk) to automate vulnerability detection.
  • Secure containerized environments (Docker/Kubernetes) and microservices architecture within the CI/CD flow.

Code Review & Security Testing

  • Perform manual and automated code reviews across multiple languages, including Java, C#, Python, and Go.
  • Execute API security testing and advanced vulnerability assessments using tools like Burp Suite Professional.
  • Lead Threat Modeling sessions during the design phase to identify and mitigate architectural flaws before code is written.

Product Security & Architecture

  • Define and promote secure design patterns and coding standards across the engineering organization.
  • Partner with development teams to prioritize and remediate vulnerabilities based on business risk.
  • Support incident response teams during application-level security events or data breach investigations.

Tools & Technologies:

  • Security Tooling: Veracode, Checkmarx, SonarQube, Snyk, Burp Suite, or Mend.io.
  • DevOps & CI/CD: GitHub Actions, GitLab CI, Jenkins, and Azure DevOps.
  • Environments: Docker, Kubernetes (K8s), and Serverless architectures.
  • Languages: Proficiency in reading/analyzing Java, C#, Python, or Go.
  • Frameworks: Strong knowledge of OWASP Top 10 (Web, API, and Mobile).

What you bring:

  • 6–8+ years in Application Security, DevSecOps, or Software Engineering with a focus on security.
  • Technical Depth: Ability to explain complex vulnerabilities to developers and provide actionable remediation guidance.
  • Automation Mindset: Experience treating "Security as Code" and automating security checks in high-velocity environments.
  • Strategic Perspective: Proven track record of implementing threat modeling and secure design principles.
  • Background: Often comes from a Software Development background with a transition into Cybersecurity.


Equal Opportunity Employer:

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified