> Markdown version of [/jobs/ext/1409634-software-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/1409634-software-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer, DevSecOps - **Company:** The Apex - **Location:** Los Angeles, CA, United States - **Experience:** Experienced - **Salary:** $150,000.0 - $187,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Static Program Analysis, Continuous Integration, Linux, DevOps, Embedded Software, Github, Secure Coding, Software Systems, Apex Code, Software Security, Kubernetes, Information Technology, Tenable Nessus, Devsecops, Docker, Vulnerability Analysis, Artifactory - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2b088acabeea92c0 ## About the Role * U.S. Person status - this role requires access to export-controlled data. * 4+ years of hands-on experience in DevOps, platform / DevSecOps, or cloud infrastructure roles. * Bachelor's degree in Computer Science, Electrical Engineering, or equivalent experience. * Strong proficiency building and maintaining CI/CD pipelines in GitHub Actions. * Hands-on experience with Docker and container development - building, hardening, and optimizing images. * Experience with secure container, SBOM, and scanning tools (e.g., Chainguard, JFrog Xray, Binarly). * Experience with artifact management (JFrog Artifactory). Nice to Have * Experience with container orchestration (Kubernetes). * Working knowledge of Linux and system administration. * Experience with cloud infrastructure (AWS preferred), networking, and services. * Familiarity with static analysis tooling (Black Duck, Klocwork). ## Description As a key member of the integrated solutions software team, you will design, develop, and own the software infrastructure that lets Apex teams move faster, scale, and keep delivering reliable products. You will build the critical systems that automate software builds, container image creation, security scanning, and SBOM generation across embedded software, flight software, and internal tooling - making security and compliance automatic, auditable, and invisible., DevOps & CI/CD * Build and maintain CI/CD pipelines across a range of languages and functions, primarily in GitHub Actions. * Develop and optimize containerized build and test workflows; own base images, build caching, and artifact management (JFrog Artifactory). Secure Containers, SBOM & Scanning * Own the secure container supply chain: harden base images, manage trusted registries, and integrate image scanning into every build. * Automate SBOM generation and vulnerability/license scanning (e.g., JFrog Xray) across artifacts and container images, delivering results back to software teams in a clear, actionable, automated format. * Own static analysis tooling (e.g., Black Duck, Klocwork) and surface findings in a digestible, automated way. Software Supply-Chain Security * Code Signing: Own code-signing infrastructure and verification workflows that guarantee the authenticity and integrity of Apex software * Build lightweight internal solutions - policy-as-code, custom scanners, CI/CD integrations - that make security and compliance automatic and auditable. Collaboration * Partner with software engineers to identify, triage, and remediate application security vulnerabilities; champion secure coding, threat modeling, and developer security training. * Work with embedded, ground, and infrastructure teams to embed security principles directly into CI/CD pipelines. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)