DevSecOps Lead

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of YipitData

YipitData

201 - 500 employees

💸 Finance

🏢 Enterprise

Finance • Enterprise • Data Analysis

YipitData is a company that specializes in providing accurate, timely insights on over 1,000 companies by analyzing billions of data points every day. They offer detailed research to help investors make smarter decisions and assist companies in increasing market share, sales, and customer base. YipitData delivers alternative data through a range of datasets, including receipt data, card data, web data, and publicly reported earnings. This data is used to track market trends, consumer behavior, and product categories, enabling businesses to gain transparency into performance metrics. Their services cater to investors, companies, and data partners, with a strong focus on accuracy and near real-time data delivery.

📋 Description

• Own the roadmap for secure SDLC controls and partner with Engineering and Product to roll out standards that are practical, scalable, and auditable. • Develop and maintain secure development policies, implementation standards, and guidance for engineering teams. • Drive adoption of key controls across repositories and pipelines, including branch protection, pull request requirements, code review, secrets scanning, dependency scanning, infrastructure-as-code scanning, and container image scanning. • Partner with Engineering and Product teams to integrate security guardrails into CI/CD workflows and developer tooling. • Support vulnerability management operations, including intake, triage, remediation tracking, verification, and reporting. • Build reference implementations, templates, and onboarding guidance to help teams adopt secure patterns consistently. • Define and report on metrics such as control coverage, vulnerability aging, SLA performance, and remediation progress. • Prepare audit-ready documentation and evidence that demonstrates controls are implemented and operating effectively. • Evaluate and prioritize future enhancements such as SAST, DAST, SBOM generation, image signing, and broader software supply chain security improvements.

🎯 Requirements

• 6+ years of experience in DevSecOps, security engineering, application security, cloud security, or DevOps • Experience building or improving Secure SDLC, CI/CD security, or vulnerability management programs in modern engineering environments • Understand Git-based workflows, CI/CD systems, cloud-native development, containers, and repository security controls • Have implemented or governed controls such as branch protection, code review, secrets scanning, SAST, SCA, infrastructure-as-code scanning, or container scanning • Can translate security requirements into clear standards and practical implementation plans that work for engineering teams • Are comfortable influencing stakeholders across Security, Engineering, and leadership • Have experience with GitHub Enterprise, GitHub Actions, Jenkins, or similar platforms, preferred • Have experience supporting SOC 2, audit readiness, or customer assurance efforts, preferred • Are familiar with software supply chain security concepts such as SBOMs, image signing, and artifact integrity, preferred

🏖️ Benefits

• Flexible work hours • Flexible vacation • Generous 401K match • Parental leave • Team events • Wellness budget • Learning reimbursement

Apply Now

Similar Jobs

🔥 11 hours ago

Guidehouse

10,000+ employees

Site Reliability Engineer collaborating with teams to establish SRE practices and participate in system design reviews at Guidehouse. Focused on AWS cloud infrastructure and promoting automation.

🔥 18 hours ago

EverCommerce

1001 - 5000

☁️ SaaS

🤝 B2B

🛍️ eCommerce

Lead DevOps Engineer at EverCommerce modernizing cloud infrastructure and deployment pipelines. Collaborating with teams for a seamless developer experience and best practices in security and compliance.

🔥 18 hours ago

Intermedia Cloud Communications

1001 - 5000

🤝 B2B

🏢 Enterprise

☁️ SaaS

DevOps Engineer managing GCP infrastructure for cloud communications. Collaborating with development teams to maintain application deployment and infrastructure.

🔥 18 hours ago

Talentuch

11 - 50

👥 HR Tech

🎯 Recruiter

🏢 Enterprise

Senior DevOps Engineer building, scaling, and operating cloud infrastructure behind our AI-powered platform. Collaborating with software engineers and AI teams to ensure reliability, security, and automation.

🔥 22 hours ago

Candescent

1001 - 5000

💳 Fintech

🏦 Banking

☁️ SaaS

DevOps Engineer managing CI/CD pipelines and automation tasks for a fintech company. Collaborating with development and operations teams to ensure smooth software delivery.