Senior DevSecOps Engineer – Capital Group
We want you to bring your authentic self to your work and contribute to a culture that values diversity and belonging. This role supports the security of continuous integration and continuous deployment (CI/CD) initiatives and collaborates with software developers, system engineers, cybersecurity engineers, and system administrators to deliver secure enterprise applications.
Location: New York, NY – hybrid (3 days in office per week).
Responsibilities
- Simplify automation that applies security across CI/CD pipelines.
- Learn and share advanced skills and practices that promote team excellence.
- Build relationships with developers, stakeholders, and scrum masters to incorporate security principles.
- Supervise testing and validation of application security controls across projects.
- Oversee implementation of defensive practices and countermeasures across infrastructure and applications.
- Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads.
- Serve as a point of contact for security-based escalations and remain involved through resolution.
- Build services and tools to enable developers and engineers to easily use security components produced by Application Security team members.
- Support the ability to shift left and incorporate security early in and throughout the development lifecycle.
- Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance.
- Leverage vulnerability database sources to understand weaknesses and remediation options supplied by vendors.
- Join forces and provision security principles in architecture, infrastructure, and code.
- Research and learn new tactics, techniques, and procedures (TTPs) in public and closed forums and assess risk to implement/validate controls as necessary.
- Enrich DevOps architecture with security standards and best practices.
- Partner with teams to define KPIs and metrics across business units.
Qualifications
- Bachelor’s degree in Computer Science or related field and/or at least 7+ years’ experience in information technology, information security administration, or security operations.
- Experience with agile workflows, including Scrum and Kanban.
- Hands‑on experience with containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes).
- Understanding of DevSecOps tooling, including Terraform, Ansible, and CI/CD pipelines.
- Experience with operations and security across Amazon Web Services (AWS).
- Ability to influence collaboration to reduce attack surface while performing rapid, continuous implementation.
- Proficient in designing, building, and deploying complex engineering solutions.
- Expert programming knowledge in Python (other languages a bonus).
- Experience in agentic software development and developing agentic skills to accelerate feature requests.
- Excellent communication of business risk and remediation requirements from assessments.
Compensation & Benefits
- Competitive base salary ranging from $136,749 to $270,278 depending on location.
- Individual annual performance bonus and Capital’s annual profitability bonus.
- Retirement plan with a 15% company contribution to eligible earnings.
- Bonuses and benefits including health, generous time‑away, flexible work options, matching gifts for charitable contributions, and on‑demand professional development resources.
Equal Opportunity Employer
Capital Group is an equal opportunity employer. We comply with all federal, state and local laws that prohibit discrimination. Our policies prohibit unlawful discrimination on the basis of race, religion, color, national origin, ancestry, sex, pregnancy, childbirth and related medical conditions, age, physical or mental disability, medical condition, genetic information, marital status, sexual orientation, citizenship status, AIDS/HIV status, political activities or affiliations, military or veteran status, status as a victim of domestic violence, assault or stalking or any other characteristic protected by law.
#J-18808-Ljbffr