> Markdown version of [/jobs/ext/2719247-java-python-devsecops-oss-security-engineering](https://www.wearedevelopers.com/jobs/ext/2719247-java-python-devsecops-oss-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Java, Python, DevSecOps, OSS Security Engineering - **Company:** Northern Base - **Location:** Bellevue, WA, United States - **Experience:** Expert - **Salary:** $15,000.0 - $18,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Software Debugging, DevOps, Github, Monitoring of Systems, Python (Programming Language), Microsoft Security Essentials, Open Source Technology, Systems Development Life Cycle, Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Data Logging, Google Cloud, Cloud Platform System, Software Security, Software Troubleshooting, Git, Kubernetes, Information Technology, Free and Open-Source Software, Terraform, Devsecops, Docker, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/jobad/usfc737a7d340e60905dd62322b20c4435 ## About the Role Bachelor's degree in Computer Science, Information Security, Software Engineering, or related field, or equivalent industry experience. 8+ years of experience in Software Engineering, DevOps, DevSecOps, Security Engineering, or related disciplines. Strong hands-on development experience with Java and Python. Experience working with cloud platforms, preferably Google Cloud Platform (GCP). Deep understanding of: o OSS Security o Vulnerability Management o Secure Coding Practices o Software Supply Chain Security o CI/CD Security Controls o Security Automation Experience integrating and operating security scanning tools, SAST, DAST, SCA, and dependency management solutions. Strong troubleshooting, debugging, and root cause analysis skills. Experience with Git-based development workflows, code reviews, and modern software engineering practices. Preferred Skills Java Python DevSecOps Engineering OSS Security Vulnerability Management Secure Coding Google Cloud Platform (GCP) CI/CD Automation Incident Response Security Engineering Automation Engineering Software Supply Chain Security Security Tooling Integration Infrastructure as Code (Terraform preferred) Container Security (Docker, Kubernetes) SAST, DAST, SCA Platforms Monitoring and Observability Tools Generic Managerial Skills, If any Digital: Terraform; CodeQL; GitHub Advanced Security; Digital: Cloud Security; Security Engineering ## Description Java Solutions; Digital : Python; DevSecOPs; Open Source Software Secuirty; MSS - Vulnerability Management; Secure coding Practices; Digital : DevOps Continuous Integration and Continuous Delivery (CI/CD); Security automation; Security Tooling Integration Roles & Responsibilities We are seeking a highly skilled and security-focused Senior DevSecOps Engineer to join the Akrites OSS Security Engineering team. This role is responsible for securing the open-source software ecosystem by analyzing, validating, and remediating vulnerabilities identified across critical OSS components and services. The engineer will work at the intersection of software engineering, security engineering, and cloud operations to strengthen software supply chain security and improve the security posture of open-source technologies. The ideal candidate possesses strong expertise in Java, Python, DevSecOps practices, vulnerability management, automation engineering, and cloud-native platforms, with a passion for driving secure development and operational excellence. This position will collaborate closely with Microsoft security engineering teams, open-source maintainers, and cross-functional product engineering groups to deliver scalable security solutions and sustainable remediation strategies. Key Responsibilities OSS Vulnerability Analysis and Remediation Analyze, triage, validate, and prioritize Open Source Software (OSS) vulnerabilities identified through security scanning platforms, Software Composition Analysis (SCA) tools, and vulnerability intelligence feeds. Perform technical investigations to determine exploitability, business impact, attack vectors, and remediation requirements. Develop and implement vulnerability fixes across OSS components using Java and Python, ensuring secure coding practices and compliance with security standards. Conduct root cause analysis for recurring vulnerabilities and recommend long-term mitigation strategies. Validate remediation effectiveness through code reviews, testing, proof-of-concept verification, and security assessment techniques. Secure Software Supply Chain Engineering Strengthen software supply chain security through dependency management, secure package validation, and vulnerability governance practices. Partner with engineering teams to evaluate and remediate risks associated with third-party libraries, frameworks, and open-source dependencies. Support coordinated vulnerability disclosure and remediation workflows while maintaining confidentiality and security compliance. Contribute to vulnerability response activities from intake and validation through patch development, testing, and coordinated release processes. DevSecOps Platform Engineering Design, implement, and optimize DevSecOps workflows within the Akrites platform deployed on Google Cloud Platform (GCP). Integrate security controls into CI/CD pipelines, enabling automated vulnerability detection, policy enforcement, and remediation tracking. Enhance platform reliability, observability, and security through automation, infrastructure monitoring, logging, and operational analytics. Collaborate with development teams to embed security practices throughout the Software Development Lifecycle (SDLC). Security Automation and Tooling Build and maintain automated solutions for: o Vulnerability detection and analysis o Security incident triage o Remediation orchestration o Compliance validation o Operational workflow automation Develop scripts, services, and engineering utilities using Python and Java to eliminate manual processes and improve remediation response times. Integrate security tooling into engineering workflows to enable continuous security monitoring and proactive risk reduction. Improve engineering efficiency through automated reporting, dashboarding, and security metrics collection. Incident Response and Security Operations Investigate security incidents, vulnerability alerts, and OSS-related threats impacting supported platforms and services. Lead technical response activities for security findings and coordinate remediation efforts across engineering teams. Document findings, corrective actions, lessons learned, and remediation guidance. Support security reviews, threat assessments, and risk management activities for critical OSS technologies. Cross-Functional Collaboration Partner with Microsoft Security Engineering, product teams, cloud platform teams, and OSS maintainers to drive strategic security initiatives. Provide technical guidance on secure coding, DevSecOps best practices, and vulnerability remediation methodologies. Participate in architecture reviews and security design discussions to proactively reduce security risks. Contribute to continuous improvement initiatives that enhance platform security, operational excellence, and developer productivity., HEAD OF PRODUCT MARKETING Hey, I'm , and I lead marketing at Outpost. I'm looking for a senior, creative, borderline-obsessive product marketer to help us lead a new category of … + 1 month ago + ## Related Videos - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)