> Markdown version of [/jobs/ext/3241968-staff-engineer-devsecops-security-engineering](https://www.wearedevelopers.com/jobs/ext/3241968-staff-engineer-devsecops-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Engineer, DevSecOps Security Engineering - **Company:** CVS Health - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,295.0 - $260,590.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Amazon Web Services, Android Software Development, Apple IOS, Microsoft Azure, Bash Shell, Big Data, Cloud Computing, Cloud Engineering, Computer Programming, Continuous Integration, Data Warehousing, Mobile Application Software, Python (Programming Language), Network Security, Open Source Technology, Windows PowerShell, Mobile Security, Software Engineering, Software Vulnerability Management, Scripting, Google Cloud, Cloud Platform System, Snowflake, Software Security, Kubernetes, Information Technology, SDN Network, Checkmarx, Devsecops, Docker, Static Application Security Testing, Golang - **Published:** September 22, 2026 - **Apply:** https://www.dice.com/job-detail/9616eee9-38c6-46fe-88b7-289e31936481 ## About the Role * A senior technical employee with deep expertise in application security, DevSecOps, automation and secure delivery practices. * Experienced translating security strategy into implementations that development teams can adopt consistently. * Strong in automation, tooling integration and process improvement that reduce manual effort and improve engineering outcomes. * Comfortable using metrics to communicate technical risk, delivery progress and measurable outcomes. * Able to balance hands-on engineering depth with cross-functional influence across application, platform, cloud and security teams., * 7+ years of experience in DevSecOps, application security engineering, platform security or software engineering. * Experience integrating SAST, SCA, secrets detection, container scanning, IaC scanning or comparable security controls into CI/CD pipelines. * Experience leading security implementations or tool migrations in large or complex engineering environments. * Proficiency in public cloud platforms such as AWS, Azure or Google Cloud Platform, plus cloud and network security concepts. * Experience with Docker, Kubernetes, Security-as-Code and Infrastructure-as-Code. * Hands-on scripting or programming experience in languages such as Python, Java, JavaScript, Go, Shell or PowerShell. * Experience with application vulnerability management, open-source risk and software supply chain security. * Experience with mobile application security testing, mobile threat modeling, or remediation of iOS and Android application security findings. * Demonstrated ability to use metrics to drive adoption, remediation and measurable technical outcomes. Preferred Qualifications * Experience supporting portfolio-based initiatives or prioritized application sets such as Health 100. * Hands-on experience with application security tools such as Snyk, Checkmarx, Gitleaks, SBOM tooling or comparable platforms. * Hands-on experience with mobile application security platforms such as Data Theorem, MobSF, or comparable mobile testing tools. * Expertise architecting public cloud security solutions and scalable engineering processes. * Strong understanding of networking and Software-Defined Networking principles. * Experience with security solutions for data warehouses or big-data platforms, including Snowflake. * Familiarity with regulated environments and frameworks such as HIPAA, HITRUST, PCI, NIST, GDPR or CCPA. * Experience communicating technical security outcomes and risk posture to senior leadership., * Bachelor's degree in Computer Science, Software Development, Software Engineering or a related field, or equivalent practical experience. ## Description The Staff Engineer, DevSecOps Security Engineering, is responsible for leading technical implementation, migration, automation, mobile application security and standardization across the Health 100 portfolio. This role translates application security strategy into scalable engineering solutions that strengthen release readiness, improve vulnerability remediation, expand security and mobile testing coverage, and enable secure-by-default delivery across engineering teams., * Support application onboarding and security enablement for Health 100 initiatives. * Help development teams meet security requirements through standard tooling, pipeline integration and repeatable implementation patterns. * Translate release-readiness expectations into repeatable technical patterns and evidence. * Ensure mobile applications are included in Health 100 security enablement through mobile application security testing, secure configuration validation and clear remediation guidance. 2. Security Implementation & Major Initiatives * Lead DevSecOps implementation initiatives aligned to security goals and engineering priorities. * Own technical planning, architecture, delivery, issue resolution and implementation outcomes. * Coordinate across application, platform and security teams to remove blockers and sustain adoption. 3. Pipeline Enforcement & Automation * Design, implement and improve CI/CD security controls, pipeline enforcement and automated scanning workflows. * Partner with development and platform teams to embed security controls without creating unnecessary delivery friction. * Build self-service security solutions and reusable automation that reduce manual intervention and improve engineering efficiency. * Automate secret-detection and CI/CD security workflows, including Gitleaks or comparable capabilities. 4. Security Tool Migration & Standardization * Lead security-tool migrations, including transitions such as Checkmarx to Snyk, from design through stable production operation. * Produce and validate initial post-migration scan results to demonstrate successful implementation and integration. * Standardize tooling configurations across development teams to improve consistency, ease of use and policy alignment. * Partner with platform teams to reduce legacy pipeline risk, fragmented configurations and duplicated manual processes. 5. Vulnerability Reduction & SLA Compliance * Drive remediation of critical and high-risk vulnerabilities across Health 100 applications with clear technical ownership and follow-through. * Monitor remediation against established SLAs and identify aging, recurrence and systemic issues. * Lead technical prioritization of high-impact open-source and software supply chain exposures affecting multiple applications. * Provide remediation guidance and scalable fixes that teams can adopt consistently. 6. Supply Chain, Cloud & Container Security * Improve open-source visibility through SBOM coverage and related software supply chain practices. * Drive secure-by-default dependency usage and remediation of high-risk third-party components. * Engineer controls for public cloud, container, Kubernetes, Security-as-Code and Infrastructure-as-Code environments. * Apply network-security and cloud-architecture expertise to design practical, resilient solutions. * Apply mobile security expertise to assess iOS and Android application risk, validate mobile security testing results and guide remediation of mobile-specific findings. 7. Metrics, Reporting & Continuous Improvement * Track and report scan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption, tool coverage and pipeline compliance. * Use metrics to identify control gaps, adoption barriers and opportunities for continuous improvement. * Provide concise, executive-ready updates on implementation progress, delivery risk and measurable security outcomes. 8. Technical Leadership & Knowledge Enablement * Serve as a senior technical authority for DevSecOps implementation, migration and automation decisions. * Mentor engineers, establish reusable engineering patterns and strengthen technical consistency across teams. * Create clear implementation guidance and education that foster developer self-service and security awareness. * Build resilient ownership and support models that reduce single points of failure. Success Measures * Migration delivery: Tooling and process migrations are delivered with validated results and minimal operational disruption. * Automation enablement: Secret detection and CI/CD security workflows are automated, reducing manual effort and improving consistency. * Standardization: Security tooling and pipeline configurations are standardized across participating development teams. * Risk reduction: Critical and high-risk vulnerabilities are reduced, with remediation performance measured against established SLAs. * Coverage and adoption: Scan coverage, mobile application security testing coverage, tool adoption, pipeline compliance and self-service usage show measurable improvement. * Release readiness: Health 100 applications have consistent, enforceable security controls and clear evidence supporting launch decisions., * Shape scalable DevSecOps patterns that improve both risk reduction and developer efficiency. * Work across application, platform, cloud and security teams to deliver measurable enterprise outcomes. * Contribute to a collaborative environment that values innovation, technical leadership and professional growth. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)