> Markdown version of [/jobs/ext/3102346-devsecops-security-engineer](https://www.wearedevelopers.com/jobs/ext/3102346-devsecops-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps Security Engineer - **Company:** Cnc Software Inc - **Location:** Tolland, CT, United States - **Salary:** $96,750.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Computing Platforms, Audit Trail, User Authentication, Microsoft Azure, Bash Shell, Cloud Computing Security, Static Program Analysis, Cyber Security, Information Systems, Computer Networks, Continuous Integration, DevOps, Multi-Factor Authentication, Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Python (Programming Language), Key Management, PostgreSQL, Enterprise Messaging Systems, OAuth, Open Web Application Security, Windows PowerShell, RabbitMQ, Role-Based Access Control, Openid Connect, Azure Active Directory, Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Single Sign-On, Software Deployment, Software Engineering, Software Vulnerability Management, Scripting, Google Cloud, Cloud Platform System, Okta, Spring Cloud, Istio, Large Language Models, Grafana, Software Security, Generative AI, Rate Limiting, Containerization, AI Platforms, Git Flow, Kubernetes, Information Technology, Hashicorp, CIS Benchmarks, Software Version Control, Devsecops, Api Management, Mastercam, Docker, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 27, 2026 - **Apply:** https://www.jofdav.com/jobs/59881946-devsecops-security-engineer ## About the Role * Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required; equivalent combinations of education, military service, and relevant professional experience will also be considered. * 4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering. * 1+ year of hands-on experience supporting Kubernetes or containerized application environments. * Experience securing cloud-native applications and services. * Experience implementing vulnerability management and application security programs. * Experience working with software development teams and CI/CD pipelines. * Experience supporting cloud environments such as AWS, Azure, or Google Cloud. Required Skills Kubernetes Knowledge of: * Kubernetes architecture * Pods, Deployments, Services, and Ingresses * RBAC * Network Policies * Container security * Workload isolation * Cluster security fundamentals Containers Experience with: * Docker * Container image security * Image scanning * Vulnerability remediation * Secure image lifecycle management, * CI/CD pipelines * Source code management platforms * Git workflows * Automation and scripting Understanding of: * SAST * DAST * Dependency scanning * Secret scanning * Infrastructure-as-Code security Identity Management Knowledge of: * OAuth2 * OpenID Connect * SAML * MFA * Role-Based Access Control Security Operations Experience with: * Vulnerability management * Threat detection * Security monitoring * Incident response support * Risk assessments Scripting Ability to automate security processes using: * Python * Bash * PowerShell Preferred Skills Experience with any of the following technologies is highly desirable: Platform Technologies * Kubernetes * Istio * FluxCD * APISIX * OpenTelemetry * Grafana Identity & Security Technologies * Keycloak * OpenBao * HashiCorp Vault * Azure Entra ID * AWS IAM Data & Messaging Platforms * PostgreSQL * RabbitMQ * Qdrant AI Platforms * Amazon Bedrock * Generative AI applications * Retrieval Augmented Generation (RAG) * Vector databases * LLM Security Preferred Security Knowledge Knowledge of: * OWASP Top 10 * OWASP API Security Top 10 * OWASP Top 10 for LLM Applications * NIST Cybersecurity Framework * CIS Benchmarks * Zero Trust Architecture * Secure Software Development Lifecycle (SSDLC) Preferred Certifications One or more of: * Security+ * Certified Kubernetes Administrator (CKA) * Certified Kubernetes Security Specialist (CKS) * AWS Certified Security Specialty * CISSP * CCSP * GIAC Certifications ## Description The DevSecOps Security Engineer is responsible for securing and governing Mastercam's cloud-native application platforms, AI-enabled solutions, and supporting infrastructure. This role integrates security throughout the software development lifecycle, including CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads. Working closely with Software Engineering, Platform Engineering, Infrastructure, and IT Operations teams, the DevSecOps Security Engineer designs, implements, and maintains security controls that protect applications, infrastructure, data, and AI services while supporting the efficient delivery of business solutions. The role helps establish security standards, improve risk management practices, and promote secure-by-design principles across development and operational processes. This position requires expertise in cloud-native technologies, Kubernetes, container security, CI/CD environments, and modern application security practices, along with the ability to contribute to emerging AI and platform security initiatives. The role serves as a key technical resource in advancing the organization's security posture while enabling innovation and operational scalability. How You'll Drive Success Platform Security * Secure Kubernetes-based platforms and containerized workloads. * Implement and maintain Kubernetes security controls including RBAC, Network Policies, Pod Security Standards, and namespace segmentation. * Perform security reviews of platform architecture and application deployments. * Develop infrastructure hardening standards and security baselines. DevSecOps * Integrate security controls into CI/CD pipelines. * Implement automated vulnerability scanning, code analysis, and compliance checks. * Establish secure software supply chain processes. * Partner with development teams to remediate vulnerabilities and improve secure coding practices. * Develop and maintain security guardrails within GitOps workflows. Identity & Access Management * Secure authentication and authorization systems. * Implement least-privilege access controls across applications and infrastructure. * Support identity federation, Single Sign-On (SSO), OAuth2, OpenID Connect, and Multi-Factor Authentication (MFA). * Review systems for access governance and privileged access risks. Secret Management * Implement secure management of secrets, certificates, encryption keys, and service credentials. * Support automated secret rotation and certificate lifecycle management. * Ensure secure application integration with centralized secrets management platforms. API & Service Security * Secure API gateways and service-to-service communications. * Review API implementations against OWASP API Security standards. * Implement authentication, authorization, rate limiting, and API threat protection controls. * Support Zero Trust networking initiatives. Security Monitoring & Detection * Create dashboards and alerts for security events. * Develop security metrics and monitoring capabilities. * Collaborate with operations teams during security investigations and incident response activities. * Analyze platform telemetry and audit logs to identify threats and control gaps. AI & Emerging Technology Security * Support security reviews for AI and machine learning workloads. * Assist with implementing controls to protect against prompt injection, sensitive data exposure, and model misuse. * Participate in AI governance and risk assessment activities. * Evaluate emerging risks associated with Large Language Models (LLMs), vector databases, and AI platforms. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)