View all jobs

DevSecOps Engineer -Remote

  • United States, United States

DevSecOps Engineer -Remote
No 3rd PARTIES or Sponsorships at this point
100% Remote

Great Company
Unlimited Growth

*4 Months
*MUST be very professional and have great communication skills-Client facing position
*This is a VERY Sr Level and Specific Skill Set- Read Closely
*You MUST have done all this!! NOT I can do it, but I am currently doing it or did it at my last position.

Client is seeking a DevSecOps Engineer to establish and operationalize a vulnerability management program within GitLab. The selected resource will build processes, standards, and automation around vulnerability scanning, SBOM generation, dependency scanning, and container security, then transition ownership to the internal DevOps team at the conclusion of the engagement.

This role will focus on standardizing security scanning across projects, reducing false positives, building remediation workflows, automating dependency management, supporting SBOM generation, and documenting processes for long-term operational support. Fixing application vulnerabilities is out of scope; application teams will own remediation efforts.

Skills Must Have
- Hands-on GitLab CI/CD pipeline authoring
- GitLab security features (SAST, dependency scanning, container scanning, security policies, vulnerability reporting)
- Experience building a vulnerability management program
- Vulnerability triage processes
- Remediation workflow development
- Severity-based remediation timelines
- Security exception management
- SBOM generation
- Dependency scanning
- Container image scanning
- Experience documenting operational processes and procedures


Skills Nice to Have
- Experience with dependency management tooling such as Renovate
- Experience with AWS ECS
- Experience with Elixir/Hex
- Experience with Node.js
- Experience with Ruby
- Experience with Lucee/CFML on the JVM
- CycloneDX SBOM experience
- SPDX SBOM experience
- Experience supporting SOC 2 audits from the engineering side