Security Engineer - DevSecOps

CVS Health
United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Agile Methodology Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Continuous Integration Mobile Application Software PCI Data Security Standards Scrum Methodology Secure Coding Software Vulnerability Management
+14 more
Software Organization Google Cloud Software Security Infrastructure as Code (IaC) Containerization Kubernetes Information Technology Devsecops Docker Security Orchestration, Automation & Response Servicenow Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

CVS Health is hiring a Security Engineer DevSecOps to support the day-to-day operations of the DevSecOps team. This role focuses on executing security tasks, maintaining application and CI/CD pipeline security, enabling developer teams, and driving operational efficiency through automation. The ideal candidate is detail-oriented, operationally strong, and comfortable working across security tooling, engineering teams, and development processes., * Perform security operations across application security, infrastructure security, and CI/CD pipeline security.

  • Support developer onboarding for security tools and processes by providing guidance and training.
  • Ensure complete and consistent security scan coverage for assigned applications.
  • Identify opportunities to automate recurring security tasks and reduce manual effort.
  • Support compliance and risk management by tracking policy adherence and documenting exceptions.
  • Improve operational efficiency through automation of security scans, vulnerability triage, and workflow enhancements.
  • Manage vulnerability tracking through accurate tagging, ownership assignment, and remediation workflows.
  • Increase developer security awareness through continuous support, coaching, and enablement.
  • Participate in ServiceNow ticket handling, daily user story updates, and on-call rotations.
  • Automate security workflows within a DevSecOps environment.

Requirements

  • 3+ years of experience in Security Engineering, DevSecOps, or a related field.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Hands-on experience with application security and CI/CD security tools.
  • Strong understanding of secure coding principles and modern software development practices.
  • Experience with:
  • SAST (Static Application Security Testing)
  • SCA (Software Composition Analysis)
  • DAST (Dynamic Application Security Testing)
  • MAST (Mobile Application Security Testing)
  • Container Security Scanning
  • Infrastructure as Code (IaC) Security Scanning
  • Experience with ServiceNow ticket management and Agile development processes.
  • Experience automating security workflows in DevSecOps environments.
  • Strong verbal and written communication skills.
  • Ability to explain security concepts to both technical and non-technical stakeholders.
  • Experience coaching or training developers on security best practices.

Preferred Qualifications

  • Experience with mobile application security.
  • Knowledge of compliance and regulatory frameworks including:
  • HIPAA
  • PCI-DSS
  • NIST
  • GDPR
  • CCPA
  • Experience with cloud platforms:
  • AWS
  • Azure
  • Google Cloud Platform
  • Experience with container technologies:
  • Docker
  • Kubernetes
  • Security certifications are a plus:
  • CISSP
  • CISM
  • CEH

Technical Skills

  • DevSecOps
  • Application Security
  • Infrastructure Security
  • CI/CD Pipeline Security
  • SAST
  • SCA
  • DAST
  • MAST
  • IaC Security
  • Container Security
  • Docker
  • Kubernetes
  • AWS
  • Azure
  • Google Cloud Platform
  • Secure Coding
  • Security Automation
  • Vulnerability Management
  • ServiceNow
  • Agile/Scrum
  • Risk Management
  • Compliance
  • HIPAA
  • PCI
  • NIST
  • GDPR
  • CCPA

Soft Skills

  • Excellent communication skills
  • Problem-solving mindset
  • Detail-oriented
  • Team collaboration
  • Developer enablement
  • Process improvement
  • Strong documentation skills

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all