> Markdown version of [/jobs/ext/552196-senior-development-security-operations-engineer](https://www.wearedevelopers.com/jobs/ext/552196-senior-development-security-operations-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Development Security Operations Engineer - **Company:** American Tower - **Location:** Boston, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Azure, Bash Shell, Cloud Computing, Cyber Security, Continuous Delivery, Github, Python (Programming Language), Performance Tuning, Windows PowerShell, Secure Coding, Policy as Code, Data Logging, DevOps Tools - Open-source, Software Security, Gitlab, Cloudformation, Containerization, Kubernetes, Infrastructure Automation Frameworks, Bitbucket, Opsworks, Terraform, Devsecops, Azure Resource Manager, Atlassian Bamboo, Docker, Jenkins - **Published:** June 15, 2026 - **Apply:** https://www.juju.com/job/00000000g8duz9 ## About the Role + 7+ years of experience in DevSecOps, security engineering, or platform engineering, with strong hands-on experience implementing CI/CD and automation solutions. + Strong hands-on experience with code repository platforms (e.g., GitHub, GitLab, Azure DevOps), including implementation of advanced security controls and governance. + Deep experience with cloud-native technologies, including containers (Docker), orchestration platforms (Kubernetes), and infrastructure-as-code tools such as Terraform, Azure Resource Manager (ARM), and AWS CloudFormation. + Strong understanding of software supply chain security risks and controls, including dependency management and Software Bill of Materials (SBOM) practices. + Experience implementing policy-as-code frameworks using tools such as Azure Policy, AWS Config, Open Policy Agent (OPA), or similar technologies. + Proficiency in scripting and automation (e.g., Python, PowerShell, Bash) and DevOps tooling (e.g., Jenkins, GitHub Actions, Azure Pipelines). + Strong understanding of the Secure Development Lifecycle (SDLC) and the ability to operationalize controls within engineering environments. + Ability to collaborate effectively with Application, Cybersecurity, and business teams to implement scalable security solutions. + Strong written and oral communication skills, including the ability to present ideas and suggestions clearly and effectively. + Ability to work with different functional groups and levels of employees to effectively and professionally achieve results. + Strong organizational skills; ability to accomplish multiple tasks within the agreed upon timeframes through effective prioritization of duties and functions in a fast-paced environment. + Approximately 5% travel may be required in support of the position's responsibilities. ## Description + Implement and enforce policy-as-code frameworks, ensuring that security requirements are version-controlled, machine-readable, and automatically enforced across build, deployment, and runtime environments. + Lead the implementation of code repository security controls (e.g., Bitbucket, GitHub, GitLab, Azure DevOps), including branch protections, access controls, commit integrity checks, and prevention of unauthorized or insecure code changes. + Develop and maintain security guardrails for developer platforms, ensuring secure configurations for pipelines, repositories, and development environments. + Integrate security controls into cloud-native environments, including container platforms (e.g., Kubernetes) and infrastructure-as-code provisioning tools such as Terraform, Azure Resource Manager (ARM), and AWS CloudFormation. + Implement secrets management solutions, ensuring secure storage, rotation, and usage of credentials, Application Programming Interface (API) keys, and tokens across applications and pipelines. + Automate enforcement of secure development standards by embedding security checks directly into engineering workflows and deployment processes. + Partner with Application Security to translate requirements into technical controls and ensure consistent enforcement across all application environments. + Design and implement controls to secure the software supply chain, including dependency management, Software Bill of Materials (SBOM) generation, and protection against malicious or vulnerable third-party components. + Build and maintain monitoring, logging, and alerting capabilities for pipeline and application security events to enable rapid detection and response. + Drive continuous improvement of DevSecOps capabilities, including automation, standardization, and performance optimization of security tooling. + Provide technical leadership and mentorship to engineers on DevSecOps practices, automation, and secure platform engineering. + Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)