DevSecOps Engineer [SK-11649]
Skill · Seattle, WA · 3 wk ago
On-siteDesignContract
About the Role
We are seeking a senior DevSecOps professional to join a dedicated engineering team, focused on enhancing product security and achieving compliance with significant regulatory requirements. This is a unique chance to apply your expertise in a complex, high-impact environment, translating regulatory mandates into tangible, scalable technical solutions. You will be instrumental in integrating robust security controls into an existing, diverse product landscape, working with a wide array of systems and codebases. Your work will directly contribute to the long-term security and compliance of critical products, making a profound difference in a globally recognized organization.
Responsibilities
- Implement and scale Static Application Security Testing (SAST) and Software Composition Analysis (SCA) across heterogeneous and often legacy codebases.
- Generate and maintain comprehensive Software Bills of Materials (SBOMs).
- Integrate security tooling into multiple build systems and Continuous Integration/Continuous Delivery (CI/CD) pipelines, including vendor-specific and custom toolchains.
- Design scalable, reusable security workflows applicable across numerous repositories and product teams.
- Contribute to a central vulnerability and waiver database, supporting consistent risk-acceptance management, audit traceability, and long-term reporting.
- Translate regulatory requirements into concrete, engineering-pragmatic technical controls.
- Drive end-to-end ownership of initial priorities, including rapid implementation of security scanning and achieving full visibility of the current security posture.
Scope & Environment
- This role focuses on introducing security controls into an existing and diverse product ecosystem rather than building greenfield solutions.
- A broad portfolio of products across embedded systems and long-lifecycle device lines.
- A large number of repositories, including legacy codebases predating modern DevSecOps/CI/CD practices.
- High heterogeneity: multiple build systems, toolchains, and packaging processes — standard, custom, and vendor-specific.
- Continuous balancing of regulatory compliance, engineering pragmatism, and portfolio-wide scalability.
- Solutions must be long-term maintainable, auditable, and reusable across teams.
Requirements
- Demonstrable product-security or regulated-compliance background with the ability to translate regulation into technical solutions.
- Hands-on, production-scale experience with industry-leading SAST and SCA tools.
- Practical experience generating and maintaining SBOMs.
- CI/CD build and automation across various platforms and cloud environments.
- Working knowledge of C and C++.
- Working knowledge of Python (for automation scripts and supporting tools).
- Experience integrating security into multiple build systems and toolchains.
- Track record scaling security workflows across portfolios with many repositories and a mix of legacy and greenfield work.
- Experience designing or contributing to vulnerability, waiver, or risk-acceptance databases.
- Awareness of embedded systems and long-lifecycle product constraints.
- This role requires US Citizenship; Lawful Permanent Residents do not qualify.
Nice-to-Have Qualifications
- Prior exposure to semi-automated or AI-assisted vulnerability remediation workflows (as engineering support, not replacement for engineering decisions).
- Previous DevSecOps work at OEMs with broad hardware portfolios.
- Familiarity with federal or highly regulated industries.
Benefits
- Health benefit contributions
- Retirement plans with match
- Flexible spending accounts