Security Engineer - DevSecOps
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
CVS Health is hiring a Security Engineer DevSecOps to support the day-to-day operations of the DevSecOps team. This role focuses on executing security tasks, maintaining application and CI/CD pipeline security, enabling developer teams, and driving operational efficiency through automation. The ideal candidate is detail-oriented, operationally strong, and comfortable working across security tooling, engineering teams, and development processes., * Perform security operations across application security, infrastructure security, and CI/CD pipeline security.
- Support developer onboarding for security tools and processes by providing guidance and training.
- Ensure complete and consistent security scan coverage for assigned applications.
- Identify opportunities to automate recurring security tasks and reduce manual effort.
- Support compliance and risk management by tracking policy adherence and documenting exceptions.
- Improve operational efficiency through automation of security scans, vulnerability triage, and workflow enhancements.
- Manage vulnerability tracking through accurate tagging, ownership assignment, and remediation workflows.
- Increase developer security awareness through continuous support, coaching, and enablement.
- Participate in ServiceNow ticket handling, daily user story updates, and on-call rotations.
- Automate security workflows within a DevSecOps environment.
Requirements
- 3+ years of experience in Security Engineering, DevSecOps, or a related field.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
- Hands-on experience with application security and CI/CD security tools.
- Strong understanding of secure coding principles and modern software development practices.
- Experience with:
- SAST (Static Application Security Testing)
- SCA (Software Composition Analysis)
- DAST (Dynamic Application Security Testing)
- MAST (Mobile Application Security Testing)
- Container Security Scanning
- Infrastructure as Code (IaC) Security Scanning
- Experience with ServiceNow ticket management and Agile development processes.
- Experience automating security workflows in DevSecOps environments.
- Strong verbal and written communication skills.
- Ability to explain security concepts to both technical and non-technical stakeholders.
- Experience coaching or training developers on security best practices.
Preferred Qualifications
- Experience with mobile application security.
- Knowledge of compliance and regulatory frameworks including:
- HIPAA
- PCI-DSS
- NIST
- GDPR
- CCPA
- Experience with cloud platforms:
- AWS
- Azure
- Google Cloud Platform
- Experience with container technologies:
- Docker
- Kubernetes
- Security certifications are a plus:
- CISSP
- CISM
- CEH
Technical Skills
- DevSecOps
- Application Security
- Infrastructure Security
- CI/CD Pipeline Security
- SAST
- SCA
- DAST
- MAST
- IaC Security
- Container Security
- Docker
- Kubernetes
- AWS
- Azure
- Google Cloud Platform
- Secure Coding
- Security Automation
- Vulnerability Management
- ServiceNow
- Agile/Scrum
- Risk Management
- Compliance
- HIPAA
- PCI
- NIST
- GDPR
- CCPA
Soft Skills
- Excellent communication skills
- Problem-solving mindset
- Detail-oriented
- Team collaboration
- Developer enablement
- Process improvement
- Strong documentation skills
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
The 12 Best Jobs for Software Engineers
Is Software Engineering Over-Saturated?
9 Ways to Make Money Hacking