Full Stack + DevSecOps Platform Engineer

InfoVision, Inc.
Irving, TX, United States
about 2 months ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Amazon Web Services Amazon S3 Build Automation Cipher DevOps Amazon DynamoDB Identity and Access Management Python (Programming Language) Node.Js Fortify (Software)
+22 more
RSA (Cryptosystem) Secure Hash Algorithm Transport Layer Security Grafana Spring-boot Sonatype Software Application Programming Veracode Build Management Gitlab-ci Enterprise Integration Checkmarx Functional Programming Cloudwatch Api Gateway Kibana Restful APIs Splunk Devsecops Jenkins Vulnerability Analysis Microservices

Job description

We are looking for a hands-on Senior Full Stack + DevSecOps Platform Engineer to help build an internal security automation platform for SBOM/CBOM inventory, vulnerability scanning, and Claude-based auto-remediation,

This is not a traditional full-stack developer role. The right candidate should be able to build applications, design CI/CD pipelines, integrate security scanning tools, understand cryptography inventory, and automate remediation safely.

Key Responsibilities

  • Design and build a centralized platform for SBOM and CBOM inventory.
  • Scan applications, repositories, containers, dependencies, certificates, keys, crypto algorithms, TLS configurations, and runtime components.
  • Integrate SBOM/CBOM and vulnerability scanning into Jenkins/GitLab CI/CD pipelines.
  • Identify vulnerable dependencies, CVEs, weak cryptography, expired certificates, insecure TLS versions, hardcoded secrets, and non-compliant libraries.
  • Build automation workflows to support remediation using Claude or similar AI coding agents.
  • Automate safe fixes such as dependency upgrades, base image updates, configuration changes, and pull request creation.
  • Ensure all AI-assisted remediations are validated through build, test, scan, approval, and audit workflows before merge or deployment.
  • Build dashboards and reports for application inventory, vulnerability posture, crypto posture, remediation status, and SLA tracking.
  • Work closely with application, security, DevOps, and platform teams.

Requirements

  • Strong hands-on experience with Java/Spring Boot.
  • Experience with at least one additional language such as Node.js, Python, or Go.
  • Experience building REST APIs, microservices, batch jobs, and platform integrations.
  • Hands-on experience with Jenkins and/or GitLab CI/CD.
  • Strong understanding of SBOM, dependency scanning, transitive dependencies, CVEs, and container image scanning.
  • Experience with tools such as Syft, Grype, CycloneDX, SPDX, JFrog Xray, Sonatype, Checkmarx, Fortify, or Veracode.
  • Good understanding of CBOM and cryptography inventory, including TLS/HTTPS, certificates, keys, cipher suites, encryption algorithms, hashing algorithms, signing algorithms, keystores, truststores, and secrets.
  • Ability to identify weak crypto such as MD5, SHA-1, DES/3DES, RC4, RSA-1024, TLS 1.0/TLS 1.1, and disabled certificate validation.
  • Hands-on AWS experience with services such as Lambda, API Gateway, S3, DynamoDB, IAM, ECS/EKS, CloudWatch, X-Ray, Secrets Manager, and KMS.
  • Experience with observability tools such as Splunk, ELK/Kibana, CloudWatch, and X-Ray.
  • Strong troubleshooting skills across application, pipeline, cloud, and security issues.
  • The candidate should understand how to use Claude or similar AI tools in a controlled engineering workflow.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all