ApplySarthi Match jobs to your CV

Staff DevSecOps Engineer

Jobgether

Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

56 open devsecops roles across 38 companies are on ApplySarthi right now, most of them in Bengaluru (5), Hyderabad (3), Pune (1).

What devsecops roles keep asking for: CI/CD (75%), Terraform (57%), AWS (55%), Python (46%), Kubernetes (41%), IAM (39%), Jenkins (34%), Shell scripting (32%) — counted across their open postings here.

Devsecops Engineer jobs in the United States · CI/CD jobs · IAM jobs · LLMs jobs · SIEM jobs

Jobgether has 3,942 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for devsecops roles keep coming back to CI/CD, Terraform, AWS, Python. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with CI/CD? Tell me one thing you learned the hard way.
  3. What do you do when a production issue happens on your code?
  4. Walk me through a system you built. How was it designed, and what would you change now?
  5. Tell me about a hard bug you tracked down. How did you find the cause?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Staff DevSecOps Engineer at Jobgether interview free →

Accountabilities:: Own the engineering side of the SOC 2 Type 2 compliance program, including control implementation, evidence collection, and audit readiness. Operate and improve compliance automation platforms, integrations, evidence pipelines, and control mappings. Productize compliance through policy-as-code, automated evidence generation, and security guardrails embedded into engineering workflows. Own cloud security posture management and runtime security capabilities, including posture monitoring, container scanning, infrastructure-as-code scanning, and runtime coverage. Triage, prioritize, and remediate security findings against defined SLAs while developing automation and alerting to manage security at scale. Build automated remediation workflows, including AI-assisted pipelines that can detect, create, and safely resolve security findings with minimal manual intervention. Design and maintain CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container and IaC scanning. Encode security and compliance requirements into infrastructure-as-code and policy-as-code so secure practices become the default path for engineering teams. Help transition prototypes into production-ready systems by introducing secure-by-default architectures and automated controls. Develop reusable infrastructure modules, pipeline components, internal tooling, and AI/agentic capabilities that turn security operations into scalable self-service functionality. Partner with corporate security and GRC teams while strengthening the organization’s internal security engineering capabilities and decision-making processes. Requirements: 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus; Staff-level candidates should have 8+ years and a track record of building security functions or programs. Deep hands-on experience securing cloud environments, including compute, networking, IAM, key management, and logging on a major cloud platform. Strong infrastructure-as-code expertise, particularly with Terraform and policy-as-code. Proven experience implementing CI/CD security controls such as SAST, SCA, secret scanning, dependency scanning, and container security within developer workflows. Hands-on experience managing vulnerabilities at scale, including triage, prioritization, SLA-driven remediation, and automation. Working knowledge of SOC 2 or comparable compliance frameworks, including implementing and evidencing controls within real engineering environments. Familiarity with modern security tooling across CSPM, application security, SAST, secret scanning, compliance automation, and SIEM. Strong coding and scripting skills with the ability to build scalable automation, pipelines, infrastructure modules, and security tooling rather than simply configure existing products. Experience establishing or maturing an in-house security engineering function. Multi-cloud experience and a background securing internal developer platforms. Experience designing security monitoring, detection, alerting, and response capabilities. Experience applying AI and LLM technologies to security operations, including automated remediation, evidence generation, and agentic workflows. Ability to collaborate effectively across engineering, security, compliance, and GRC teams while operating with a high degree of technical ownership. Benefits: Total cash compensation range of $150,000–$225,000 per year, depending on location, experience, and qualifications. Remote or hybrid work options, with a preference for candidates on the East Coast. Hybrid opportunities centered around New York, NY and Charlotte-area offices. Health insurance coverage, including medical, dental, and vision. Life insurance. Short- and long-term disability insurance. Flexible spending accounts. Holiday pay. 401(k) plan with company match. Employee Assistance Program. Paid parental bonding benefit program. Flexible paid time off, with full-time employees accruing 20 days annually and increasing to 25 days after five years of service. The role requires availability during Eastern Standard Time working hours. The position does not offer visa sponsorship or transfer of visa sponsorship and is not available for corp-to-corp arrangements.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-09-21. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.