> Markdown version of [/jobs/ext/1028780-sr-devsecops-software-engineer](https://www.wearedevelopers.com/jobs/ext/1028780-sr-devsecops-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. DevSecOps Software Engineer - **Company:** Echodyne's Technology - **Location:** Kirkland, United States - **Experience:** Expert - **Salary:** $124,733.0 - $187,048.0 - **Contract:** Permanent contract - **Skills:** Testing (Software), Amazon Web Services, Systems Engineering, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Computer Programming, Continuous Integration, Linux, DevOps, Embedded Software, Firmware, Github, Identity and Access Management, Python (Programming Language), Key Management, Open Web Application Security, Systems Development Life Cycle, Real-Time Operating Systems, Zero Trust Network Access, Secure Coding, Software Engineering, Policy as Code, Scripting, Google Cloud, Cloudformation, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Terraform, Devsecops, Docker, Jenkins, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** June 9, 2026 - **Apply:** https://www.dice.com/job-detail/257bcc8d-5df8-4486-9c9c-b5bf836bc104 ## About the Role * Bachelor's degree or higher in Computer Science, Engineering, or a related field (or equivalent industry experience) * 6 or more years of experience in DevOps, DevSecOps, security engineering, or software engineering * Experience with programming/scripting in environments like Python, Go, Bash, or similar * Experience building and maintaining CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, etc.) * Experience with cloud platforms (AWS, Azure, or Google Cloud Platform) and secure cloud architecture * Proficiency with containerization and orchestration (Docker, Kubernetes) * Understanding of application and infrastructure security (OWASP Top 10, secure coding practices) * Experience with security tools such as SAST, DAST, SCA, container scanning * A working knowledge of Linux, networking, and system security fundamentals * Strong ownership mindset and ability to operate in a fast-paced startup environment. * Pragmatic approach to balancing security, compliance, and development velocity. * Excellent cross-functional communication skills. * Systems thinking across software, hardware, and infrastructure layers. * Continuous learning mindset in a rapidly evolving threat landscape DESIRED SKILLS / EXPERIENCE (Looking for one or more as a complement to the core skills) * Experience with managing pipeline for embedded firmware, real time software and test software infrastructure in addition to application or cloud software. * Background in defense, aerospace, or other regulated industries * Familiarity with compliance frameworks such as NIST 800-171, CMMC, RMF, or FedRAMP * Experience with secure embedded development or RTOS environments * Knowledge of Zero Trust architecture and policy-as-code (e.g., Open Policy Agent) * Experience working with air-gapped or high-security environments * Relevant certifications (e.g., CISSP, Security+, AWS Security Specialty) ## Description We are seeking a Senior DevSecOps Software Engineer to lead the design and implementation of secure development and deployment practices across our software and systems stack. This is a high-impact, hands-on role where you will own the DevOps space and our stack for managing the CI/CD pipeline and help define DevSecOps strategy working with our VP of Cybersecurity, build secure pipelines, and ensure compliance with defense and commercial security standards-all while enabling rapid innovation. RESPONSIBILITIES * Architect, build, and maintain secure CI/CD pipelines supporting cloud, on-prem, and embedded systems * Proactively identify and resolve bottlenecks in CI/CD pipelines to maintain fast, reliable and scalable build and test workflows * Integrate automated software test into the CI/CD pipeline with metrics to ensure that builds are clearly controlled and tested * Integrate automated security testing (SAST, DAST, SCA, fuzzing) into development workflows * Lead "shift-left" security initiatives across the software development lifecycle (SDLC) * Design and enforce secure software supply chain practices, including artifact signing, SBOM generation, and dependency management * Develop and manage Infrastructure-as-Code (IaC) with security-first principles (e.g., Terraform, CloudFormation) * Establish and maintain secure build environments, including support for controlled or air-gapped systems * Collaborate with software, firmware, and systems engineers to remediate vulnerabilities and improve secure coding practices * Implement identity and access management (IAM), secrets management, and encryption strategies * Monitor, detect, and respond to security events across environments * Support compliance efforts aligned with standards such as NIST 800-171, CMMC, and related frameworks ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)