Java, Python, DevSecOps, OSS Security Engineering
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+23 more
Job description
Java Solutions; Digital : Python; DevSecOPs; Open Source Software Secuirty; MSS - Vulnerability Management; Secure coding Practices; Digital : DevOps Continuous Integration and Continuous Delivery (CI/CD); Security automation; Security Tooling Integration Roles & Responsibilities We are seeking a highly skilled and security-focused Senior DevSecOps Engineer to join the Akrites OSS Security Engineering team. This role is responsible for securing the open-source software ecosystem by analyzing, validating, and remediating vulnerabilities identified across critical OSS components and services. The engineer will work at the intersection of software engineering, security engineering, and cloud operations to strengthen software supply chain security and improve the security posture of open-source technologies. The ideal candidate possesses strong expertise in Java, Python, DevSecOps practices, vulnerability management, automation engineering, and cloud-native platforms, with a passion for driving secure development and operational excellence. This position will collaborate closely with Microsoft security engineering teams, open-source maintainers, and cross-functional product engineering groups to deliver scalable security solutions and sustainable remediation strategies. Key Responsibilities OSS Vulnerability Analysis and Remediation Analyze, triage, validate, and prioritize Open Source Software (OSS) vulnerabilities identified through security scanning platforms, Software Composition Analysis (SCA) tools, and vulnerability intelligence feeds. Perform technical investigations to determine exploitability, business impact, attack vectors, and remediation requirements. Develop and implement vulnerability fixes across OSS components using Java and Python, ensuring secure coding practices and compliance with security standards. Conduct root cause analysis for recurring vulnerabilities and recommend long-term mitigation strategies. Validate remediation effectiveness through code reviews, testing, proof-of-concept verification, and security assessment techniques. Secure Software Supply Chain Engineering Strengthen software supply chain security through dependency management, secure package validation, and vulnerability governance practices. Partner with engineering teams to evaluate and remediate risks associated with third-party libraries, frameworks, and open-source dependencies. Support coordinated vulnerability disclosure and remediation workflows while maintaining confidentiality and security compliance. Contribute to vulnerability response activities from intake and validation through patch development, testing, and coordinated release processes. DevSecOps Platform Engineering Design, implement, and optimize DevSecOps workflows within the Akrites platform deployed on Google Cloud Platform (GCP). Integrate security controls into CI/CD pipelines, enabling automated vulnerability detection, policy enforcement, and remediation tracking. Enhance platform reliability, observability, and security through automation, infrastructure monitoring, logging, and operational analytics. Collaborate with development teams to embed security practices throughout the Software Development Lifecycle (SDLC). Security Automation and Tooling Build and maintain automated solutions for: o Vulnerability detection and analysis o Security incident triage o Remediation orchestration o Compliance validation o Operational workflow automation Develop scripts, services, and engineering utilities using Python and Java to eliminate manual processes and improve remediation response times. Integrate security tooling into engineering workflows to enable continuous security monitoring and proactive risk reduction. Improve engineering efficiency through automated reporting, dashboarding, and security metrics collection. Incident Response and Security Operations Investigate security incidents, vulnerability alerts, and OSS-related threats impacting supported platforms and services. Lead technical response activities for security findings and coordinate remediation efforts across engineering teams. Document findings, corrective actions, lessons learned, and remediation guidance. Support security reviews, threat assessments, and risk management activities for critical OSS technologies. Cross-Functional Collaboration Partner with Microsoft Security Engineering, product teams, cloud platform teams, and OSS maintainers to drive strategic security initiatives. Provide technical guidance on secure coding, DevSecOps best practices, and vulnerability remediation methodologies. Participate in architecture reviews and security design discussions to proactively reduce security risks. Contribute to continuous improvement initiatives that enhance platform security, operational excellence, and developer productivity., HEAD OF PRODUCT MARKETING Hey, I’m , and I lead marketing at Outpost. I’m looking for a senior, creative, borderline-obsessive product marketer to help us lead a new category of …
- 1 month ago +
Requirements
Bachelor’s degree in Computer Science, Information Security, Software Engineering, or related field, or equivalent industry experience. 8+ years of experience in Software Engineering, DevOps, DevSecOps, Security Engineering, or related disciplines. Strong hands-on development experience with Java and Python. Experience working with cloud platforms, preferably Google Cloud Platform (GCP). Deep understanding of: o OSS Security o Vulnerability Management o Secure Coding Practices o Software Supply Chain Security o CI/CD Security Controls o Security Automation Experience integrating and operating security scanning tools, SAST, DAST, SCA, and dependency management solutions. Strong troubleshooting, debugging, and root cause analysis skills. Experience with Git-based development workflows, code reviews, and modern software engineering practices. Preferred Skills Java Python DevSecOps Engineering OSS Security Vulnerability Management Secure Coding Google Cloud Platform (GCP) CI/CD Automation Incident Response Security Engineering Automation Engineering Software Supply Chain Security Security Tooling Integration Infrastructure as Code (Terraform preferred) Container Security (Docker, Kubernetes) SAST, DAST, SCA Platforms Monitoring and Observability Tools Generic Managerial Skills, If any Digital: Terraform; CodeQL; GitHub Advanced Security; Digital: Cloud Security; Security Engineering
About the company
At Qualtrics, we create software the world’s best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. But we are …
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Highest Paying Tech Companies for Developers
Dev Digest 120 - Apple and peers
Dev Digest 138 - Are you secure about this?
The Best Software Developer Blogs to Read