> Markdown version of [/jobs/ext/2867757-java-python-devsecops-oss-security-engineering](https://www.wearedevelopers.com/jobs/ext/2867757-java-python-devsecops-oss-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Java, Python, DevSecOps, OSS Security Engineering - **Company:** Northern Base - **Location:** Bellevue, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $15,000.0 - $18,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Software Debugging, DevOps, Github, Monitoring of Systems, Python (Programming Language), Secure Coding, Software Engineering, Systems Integration, Software Vulnerability Management, Google Cloud, Cloud Platform System, Software Security, Software Troubleshooting, Git, Information Technology, Free and Open-Source Software, Terraform, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://www.careerjet.com/jobad/uscb4541757871353540b31777bd9b1f84 ## About the Role * 8+ years of experience in Software Engineering, DevOps, DevSecOps, or Security Engineering * Strong hands-on development experience with Java and Python * Strong expertise in Open Source Software (OSS) Security * Experience with OSS vulnerability analysis, triage, validation, prioritization, and remediation * Strong knowledge of Vulnerability Management and vulnerability intelligence * Experience analyzing exploitability, attack vectors, business impact, and remediation requirements * Strong Secure Coding Practices and security standards knowledge * Experience performing root cause analysis for recurring vulnerabilities * Experience developing and implementing vulnerability fixes using Java/Python * Strong understanding of Software Supply Chain Security * Experience with dependency management, third-party libraries, package validation, and vulnerability governance * Strong DevSecOps engineering experience * Experience integrating security controls into CI/CD pipelines * Hands-on experience with security automation and remediation orchestration * Experience with security scanning and application security technologies: * SAST * DAST * SCA * Dependency Management * Experience integrating and operating security tooling within engineering workflows * Experience with Git-based development, code reviews, and modern software engineering practices * Cloud experience, preferably Google Cloud Platform (GCP) * Experience building automation for: * Vulnerability detection and analysis * Security incident triage * Remediation orchestration * Compliance validation * Operational workflows * Experience investigating security incidents, vulnerability alerts, and OSS-related threats * Strong troubleshooting, debugging, and RCA skills * Experience with security reviews, threat assessments, and risk management * Ability to collaborate with security engineering, product engineering, cloud platform, and OSS teams * Strong communication and technical leadership skills Preferred Experience * Google Cloud Platform (GCP) * Terraform / Infrastructure as Code * Docker and Kubernetes container security * CodeQL * GitHub Advanced Security * Cloud Security * Security Engineering and Automation Engineering * Incident Response * Monitoring and Observability * CI/CD security automation * Security metrics, reporting, and dashboarding * Architecture reviews and security design * Software supply chain security programs * Coordinated vulnerability disclosure and remediation Education * Bachelor's Degree in Computer Science, Information Security, Software Engineering, or related field, or equivalent industry experience ## Description HEAD OF PRODUCT MARKETING Hey, I'm , and I lead marketing at Outpost. I'm looking for a senior, creative, borderline-obsessive product marketer to help us lead a new category of … + 1 month ago + ## Related Videos - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)