Cloud DevSecOps Engineer

Regions Bank
Birmingham, AL, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$109,086.0 - $142,750.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Application Services Architectural Patterns Automation of Tests Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Continuous Integration
+26 more
Python (Programming Language) OpenShift Reliability Engineering Cloud Services Ansible Software Engineering Virtual Machines Software Vulnerability Management Data Logging Delivery Pipeline Large Language Models Software Security Git Build Management Infrastructure Automation Frameworks Information Technology Hashicorp Azure AKS Terraform Devsecops Serverless Computing Jenkins Servicenow Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

Regions is dedicated to taking appropriate steps to safeguard and protect private and personally identifiable information you submit. The information that you submit will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience for job opportunities and will not be used for marketing purposes, sold, or shared outside of Regions unless required by law. Such information will be stored in accordance with regulatory requirements and in conjunction with Regions’ Retention Schedule for a minimum of three years. You may review, modify, or update your information by visiting and logging into the careers section of the system., At Regions, the Cloud DevSecOps Engineer contributes to the advancement of cloud strategy. The primary focus of this role includes developing, communicating, and implementing robust and secure cloud continuous integration and continuous delivery (CI/CD) pipelines. This role works closely with stakeholders to create fully automated pipelines which support current DevSecOps best practices., * Assists with releasing candidate CI/CD pipelines as a mechanism to communicate the states and steps necessary to determine a release candidate for each application and service

  • Designs and develops fully autonomous CI/CD pipelines which facilitate cloud deployments which includes automation of all infrastructure, services and application build and deployment
  • Ensures that all parts of the pipeline follow good software engineering practices to include automated tests and infrastructure tests
  • Builds tools which reduce errors and improve our overall customer experiences
  • Assists in troubleshooting of production issues and ensure pipeline and infrastructure produces clear documentation and metrics which enables Root Cause Analysis
  • Develops and tests - Ansible Playbooks, Terraform Scripts, Packer Scripts and establish immutable infrastructure such that patches are an artifact of the past
  • Works with Enterprise Architecture, Information Security (InfoSec), Software Delivery, and Quality Assurance to enable the organization to move to the cloud using complete automation
  • Ensures compliance with risk management programs, rules and regulations, and cybersecurity practices; identifies opportunities for and supports process improvements; applies disciplined change management practices

This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay., The Cloud DevSecOps Engineer will drive innovation through the adoption of AI-enabled security capabilities, including LLM-integrated workflows, intelligent automation, and AI-assisted vulnerability remediation, to improve the effectiveness and efficiency of the Exposure Management program. In this role, you will:

  • Build the integration of security practices, controls, and automated remediation capabilities into CI/CD pipelines, infrastructure-as-code (IaC), and cloud-native development processes to reduce organizational cyber exposure.
  • Partner with Application Development, Platform Engineering, Cloud Engineering, and Security teams to identify, prioritize, and remediate vulnerabilities across applications, containers, cloud services, and code repositories.
  • Drive the adoption and optimization of security tooling, including SAST, DAST, SCA, IaC scanning, secrets detection, container security, and software supply chain security solutions.
  • Develop and maintain risk-based remediation workflows that align vulnerability findings with asset criticality, threat intelligence, exploitability, and business impact.
  • Support the organization’s Exposure Management program by establishing security guardrails, preventative controls, and continuous monitoring capabilities that reduce attack surface and security risk.
  • Build security automation and orchestration capabilities to improve vulnerability detection and remediation, policy enforcement, configuration management, and developer self-service security functions.
  • Define and report on key performance indicators (KPIs) and metrics related to application security, remediation effectiveness, security debt reduction, and secure development maturity.
  • Serve as a security advocate for engineering teams, promoting secure-by-design principles, developer education, and a culture of shared responsibility for cybersecurity risk management.

Requirements

  • High School Diploma or GED and six (6) years of related post-secondary education and/or experience in Information Security or Information Technology

Preferences

  • Two (2) years of relevant DevSecOps experience
  • AWS DevOps certification or Azure DevOps certification
  • Experience in building / deploying cloud native applications - OpenShift, Azure Kubernetes Service (AKS)
  • Experience with interfacing with secrets management solutions like Hashicorp Vault
  • Familiar with implementing Chaos engineering principles in the pipeline to determine weak links and suggest solutions.
  • Familiar with testing tools used to facilitate automation and integration of the tools into CI/CD pipelines

Skills and Competencies

  • Ability to interpret and ensure compliance with applicable rules, regulations, and industry guidance
  • Excellent knowledge of Cloud infrastructure, networking, services, and cloud architectural patterns; specifically, compute using virtual machines, managed infrastructure, containers, serverless, as well as database services, security services, and application services
  • Proficient in python programming language
  • Understanding of Shift Left principles and facilitation technologies
  • Working Knowledge of Jenkins, Azure DevOps, Ansible, Terraform, Packer, Git, ServiceNow a big plus, This position is currently offsite, preferably close to a Regions office within our retail branch footprint (click here (https://careers.regions.com/us/en/explore-regions) to see our locations). Associates will work from their home primarily and may be expected to go on site for meetings or other events as needed.

Regions will not sponsor applicants for work visas for this position at this time. Applicants for this position must currently be authorized to work in the United States on a full-time basis.

Position Type

Full time

Benefits & conditions

Regions offers a benefits package that is flexible, comprehensive and recognizes that ā€œone size does not fit allā€ for benefits-eligible associates. (https://www.regions.com/about-regions/benefits/benefits-eligibility) Listed below is a synopsis of the benefits offered by Regions for informational purposes, which is not intended to be a complete summary of plan terms and conditions.

  • Paid Vacation/Sick Time
  • 401K with Company Match
  • Medical, Dental and Vision Benefits
  • Disability Benefits
  • Health Savings Account
  • Flexible Spending Account
  • Life Insurance
  • Parental Leave
  • Employee Assistance Program
  • Associate Volunteer Program

Please note, benefits and plans may be changed, amended, or terminated with respect to all or any class of associate at any time. To learn more about Regions’ benefits, please click or copy the link below to your browser.

https://www.regions.com/about-regions/welcome-portal/benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:32 min

Shifting to a DevOps career from non-technical backgrounds

Megha Kadur Ā· LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer Ā· Coffee With Developers

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier Ā· WWC 2023

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto Ā· WWC 2024

4:18 min

Technical roles and digitalization scale at Finance Informatic

Alexander Weißhaupt Alexander Weißhaupt +3 · WWC 2025

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 Ā· Coffee With Developers

Videos

See all

Related articles

See all