DevSecOps / Application Security Engineer

Beacon Hill Technologies
Indianapolis, IN, United States
14 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Applications Architecture User Authentication Microsoft Azure Cloud Computing Security Code Review Cyber Security Continuous Integration DevOps Programming Tools
+17 more
Github Identity and Access Management Key Management Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering Systems Integration Software Vulnerability Management Software Organization Delivery Pipeline Software Security Software Coding Data Pipelines Devsecops Security Orchestration, Automation & Response Vulnerability Analysis

Job description

Our client is seeking a DevSecOps / Application Security Engineer to help build and mature application security practices across a growing development organization. This role will focus on integrating security into the software development lifecycle, implementing automated security testing within CI/CD pipelines, and establishing practical security standards that support, rather than hinder, development teams. The ideal candidate will bring a blend of application security, DevOps, and software development experience, with hands-on expertise in Azure DevOps, secure SDLC practices, vulnerability management, and security automation. This is an opportunity to play a key role in shaping a shift-left security strategy and building scalable security capabilities from the ground up.

Requirements

Hands-on experience in DevSecOps, Application Security, or Security-focused DevOps Engineering

Experience implementing and supporting Secure Software Development Lifecycle (Secure SDLC) practices

Strong knowledge of CI/CD pipeline security and integrating security controls into development workflows

Experience with Azure DevOps and automated pipeline development

Experience building and implementing security automation, including vulnerability scanning and security testing

Knowledge of application security principles, including secure coding practices, secrets management, encryption, authentication, and secure integrations

Experience with vulnerability management and remediation processes

Understanding of modern software development practices and application architectures

Experience partnering with application developers, DevOps engineers, and security teams

Ability to establish security standards, guardrails, and governance processes that are practical and scalable

Experience implementing shift-left security strategies that move security validation earlier in the development lifecycle

Strong understanding of security scanning tools and integrating them into automated development pipelines

Excellent communication skills with the ability to influence engineering teams and drive security best practices

Desired Skills:

Experience with Application Security Engineering programs and maturing security practices within an organization

Background in software development with hands-on coding experience

Experience in Security Operations (SecOps)

Experience with GitHub, including GitHub Secret Protection

Experience with Snyk or similar application security and code scanning platforms

Knowledge of cloud security within Microsoft Azure environments

Experience in AWS environments with the ability to transition to Azure-based ecosystems

Experience automating remediation workflows and security exception management

Familiarity with security frameworks and industry best practices (OWASP, NIST, secure development standards)

Experience defining application security policies, standards, and governance models

Knowledge of APIs, certificates, identity and access management, and service account security

Experience leveraging AI-powered developer tools (Claude, OpenAI, Copilot, etc.) for code review, vulnerability detection, and secure development practices

Experience helping organizations build and mature application security programs from the ground up

Experience balancing security requirements with development velocity and operational efficiency

About the company

Beacon Hill Technologies, a premier National Information Technology Staffing Group, provides world class technology talent across all industries utilizing a complete suite of staffing services. Beacon Hill Technologies’ dedicated team of recruiting and staffing experts consistently delivers quality IT professionals to solve our customers’ technical and business needs.

Beacon Hill Technologies covers a broad spectrum of IT positions, including Project Management and Business Analysis, Programming/Development, Database, Infrastructure, Quality Assurance, Production/Support and ERP roles.

Learn more about Beacon Hill and our specialty divisions, Beacon Hill Associates, Beacon Hill Financial, Beacon Hill HR, Beacon Hill Legal, Beacon Hill Life Sciences and Beacon Hill Technologies by visiting .

Benefits Information:

Beacon Hill offers a robust benefit package including, but not limited to, medical, dental, vision, and federal and state leave programs as required by applicable agency regulations to those that meet eligibility. Upon successfully being hired, details will be provided related to our benefit offerings.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

Videos

See all

Related articles

See all