HCSS
Posted 3w ago

Senior DevSecOps Engineer

HCSS
United States
RemoteFull Time
Responsibilities
  • integrating security
  • mitigating vulnerabilities
  • mentoring engineers
Requirements
  • Requires 5+ years in application security or DevSecOps
  • Azure security experience
  • Secure SDLC
  • CI/CD security automation
  • Vulnerability management
  • Compliance frameworks, and strong cross-functional communication
Technical tools mentioned
Microsoft AzureAzure Key VaultAzure Security CenterAzure DevOpsSASTDASTSCAHashiCorp VaultCI/CDSonarQubeVeracodeCheckmarxSnykBlack DuckMendGitHub Advanced SecuritySemgrepBurp SuiteOWASP ZAPWizPrisma CloudAquaTerraformIaCMicroservicesAPIs

Job description

We are HCSS. For the last 40 years, we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer. We have earned Best Companies to Work for in Texas honors for 18 consecutive years and have been named a USA Today Top Workplace. HCSS has also been recognized by Built In as a Best Place to Work in Greater Houston and by Construction Executive for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence.

WHO WE NEED: 
As a Senior DevOps Engineer specializing in DevSecOps and Application Security, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement.

This role is especially focused on application security, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development
teams deliver secure software at scale.

Qualifications:
  • Experience: Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices.
  • Cloud Expertise: Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others.
  • Security Tools & Practices: Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines.
  • Secure Development Lifecycle: In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development.
  • Vulnerability Management: Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation.
  • Compliance Knowledge: Familiarity with security and compliance frameworks such as OWASP, NIST, CIS,
  • SOC 2, ISO 27001, PCI DSS, GDPR, or similar.
  • Collaboration & Communication: Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams.

Preferred Qualifications:
  • Security Certifications: Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent).
  • Threat Modeling: Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process.
  • Experience with Microservices & APIs: Strong understanding of microservices architecture and API security practices.
  • Security Tools: Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar.

Role Responsibilities:
  • DevSecOps Integration: Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines.
  • Application Security Expertise: Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling.
  • Azure Cloud Security: Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more.
  • Static and Dynamic Application Security Testing: Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments.
  • Secrets Management: Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments.
  • Software Composition Analysis (SCA): Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies.
  • Automation and Infrastructure as Code: Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments.
  • Security Policies & Compliance: Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure.
  • Collaboration & Mentorship: Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools.

Travel Requirements:
  • Occasional travel to our office may be requested up to once or twice a year

BENEFITS & PERKS:
Part of our mission is to provide a great life for our employees. We believe that when our people are happy, they do their best work. Some of the benefits and perks we offer include:
  • Flexibility to work Remotely
  • Medical, dental, and vision coverage with company-paid and employee-paid options
  • Paid holidays, sick days, and personal time off
  • Employee Resource Groups (ERGs) that foster connection and inclusion
  • On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc.
  • Dog-friendly campus and WiFi-accessible courtyards
  • 401(k) with a 5% company match
  • Coverage for employee professional development and wellness
  • And more!

About HCSS

Provides estimation and operations software for heavy civil construction projects.

Year founded
1986
Employees
700
Organization type
Private
Latest investment
Private Equity (2021) — led by Thoma Bravo
Subsidiaries
Headquarters
US

Similar jobs

DevSecOps Engineer roles
11h
Save
Mark Applied
Hide
DevSecOps Engineer - USSF XC3
San Antonio, Texas, United States
HybridFull Time
Silotech Group
Silotech Group: Cybersecurity and managed IT services for government and businesses.
5+ YOEBachelor's degree or equivalent experience, 5+ years in DevSecOps or cloud infrastructure, AWS and GovCloud expertise, CI/CD, infrastructure as code, containers, security practices, and production credential management.
AWS, AWS GovCloud, GitHub Actions, GitLab CI, Jenkins, Terraform, CloudFormation, Ansible, Docker, Kubernetes, ECS, ATO, RMF, FedRAMP, IL4, IL5
11h
Save
Mark Applied
Hide
Sr. DevSecOps Engineer I
Washington, District of Columbia, United States
$170k-$220k/yr OnsiteFull Time
M9 Solutions
M9 Solutions: Provides IT modernization and technology services to federal agencies.
5+ YOERequires active TS/SCI clearance, BA/BS in an IT-related field or equivalent experience, DoD 8140 certification, and 5+ years of DevSecOps experience with enterprise CI/CD and security platforms.
.NET, CI/CD
13h
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Chantilly or Herndon
$150k-$170k/yr OnsiteFull Time
Dark Wolf Solutions
Dark Wolf Solutions: Provides cybersecurity and software development services to defense agencies.
7+ YOEBachelor's degree and 7+ years building CI/CD pipelines, including 3+ years in infrastructure automation. Requires US citizenship, active TS/SCI clearance with Full-Scope Polygraph, and expertise in DevSecOps tools and cloud platforms.
Jenkins, GitLab CI/CD, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Kubernetes, Open Policy Agent (OPA), Kyverno, Falco, HashiCorp Vault, AWS Secrets Manager, ArgoCD, Flux, Prometheus, Grafana, ELK, OpenSearch, OpenTelemetry, Python, Go, Bash, C/C++, Docker, Podman, AWS, Azure, GCP, SonarQube, Snyk, Trivy, OWASP ZAP, Git, Jira, Linux, Agile, Scrum
13h
Save
Mark Applied
Hide
DevSecOps Engineer I
Huntsville, Alabama, United States
$66k-$113k/yr OnsiteFull Time
Akima
Akima: Provider of mission-focused technical and administrative support for government agencies.
Bachelor's degree, CompTIA Security+ certification, systems administration and hybrid cloud experience, Active Directory, MDM, AWS, ACAS, DISA STIGs, NIST compliance, and US citizenship with ability to obtain Secret clearance.
Active Directory, MDM, AWS, EC2, ACAS, DISA STIGs, NIST 800-171, NIST 800-53
15h
Save
Mark Applied
Hide
Lead DevSecOps Engineer-ACWS
Fort Dix, New Jersey, United States
$155k-$165k/yr OnsiteFull Time
Data Systems Analysts
Data Systems Analysts: Provides IT and cybersecurity solutions for government agencies.
7+ YOERequires 10 years in data architecture, migration, and API integration; 7+ years in DevOps/DevSecOps; AWS and Kubernetes/EKS; team management; security operations; and relevant certifications.
Microsoft Copilot, AWS, Kubernetes, EKS, GitLab CI/CD, Azure, AWS GovCloud, Appian, RMF
18h
Save
Mark Applied
Hide
DevSecOps Engineer
Chantilly, Virginia, United States
$62k-$141k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
DevSecOps, CI/CD, container, AWS or OpenShift, Kubernetes, and infrastructure/configuration-as-code experience; TS/SCI clearance, high school diploma/GED, and DoD 8570 IAT certification eligibility required.
CI/CD, Amazon Web Services (AWS), OpenShift, Kubernetes, Terraform, Ansible, EKS, AKS, Azure, Flux, Argo CD, Kustomize, Linux, UNIX
18h
Save
Mark Applied
Hide
DevSecOps
San Jose, California, United States
$111k-$184k/yr HybridFull Time
Veeam
Veeam: Data resilience and security for hybrid cloud environments
5+ YOERequires 5+ years of software development and cloud-native operations experience, Terraform or CloudFormation, Kubernetes, CI/CD, Python or Go, databases, Linux, networking, and observability expertise.
Terraform, AWS CloudFormation, Kubernetes, ArgoCD, Spinnaker, GitOps, Prometheus, Grafana, ELK, AWS, Azure, GCP, Python, Go, Jenkins, GitHub Actions, SQL, Postgres, MongoDB, Elasticsearch, Neo4j, Neptune, Linux, Bash, Istio, Linkerd, Consul, Chaos Monkey, Litmus, Microsoft LinkedIn Learning, O'Reilly
1d
Save
Mark Applied
Hide
GMD DevSecOps Engineer
Huntsville, Alabama, United States
OnsiteFull Time
PeopleTec
PeopleTec: Provides technical services and solutions to defense agencies.
12+ YOERequires Terraform, Kubernetes, CI/CD, AWS, Azure, Windows administration, Active Directory, STIG analysis, Security+, active Secret clearance, and a master's plus 12 or bachelor's plus 20 years' experience.
Terraform, Kubernetes, GitLab CI, Jenkins, Azure DevOps, Microsoft Azure, AWS, Windows Server, Windows Active Directory, Group Policy Objects (GPOs), System Center Configuration Manager (SCCM), Coder, GitLab, CI/CD