PPL is an Equal Opportunity Employer dedicated to celebrating diversity and intentionally creating a culture of inclusion. We believe that we work best when our employees feel empowered and accepted, and that starts by honoring each of our unique life experiences. At PPL, all aspects of employment regarding recruitment, hiring, training, promotion, compensation, benefits, transfers, layoffs, return from layoff, company-sponsored training, education, and social and recreational programs are based on merit, business needs, job requirements, and individual qualifications. We do not discriminate on the basis of race, color, religion or belief, national, social, or ethnic origin, sex, gender identity and/or expression, age, physical, mental, or sensory disability, sexual orientation, marital, civil union, or domestic partnership status, past or present military service, citizenship status, family medical history or genetic information, family or parental status, or any other status protected under federal, state, or local law. PPL will not tolerate discrimination or harassment based on any of these characteristics.
AppSec, DevSecOps Engineer
Location
United States
Posted
55 days ago
Salary
$120K - $135K / year
Seniority
Senior
Job Description
AppSec, DevSecOps Engineer
Public Partnerships | PPL
• Integrate security at every phase of the software development lifecycle. • Collaborate with engineering and product teams in Agile/Scrum environments to prioritize, track, and remediate security issues during sprint cycles. • Develop and maintain threat models and perform design reviews. • Lead threat modeling sessions and conduct in-depth security architecture reviews. • Educate development teams on secure coding practices. • Actively support the organization’s secure software development lifecycle (SDLC) initiatives by integrating security controls, processes, and testing into development workflows and CI/CD pipelines. • Integrate security testing tools (SAST, DAST, SCA, IaC scanning) into CI/CD pipelines. • Perform and manage vulnerability assessments, code reviews, and penetration testing. • Secure containerized environments (Docker, Kubernetes). • Ensure cloud infrastructure security (AWS/GCP/Azure) using infrastructure-as-code (IaC) tools like Terraform or CloudFormation. • Support documentation and evidence collection for SOC 2 Type II audits and HIPAA security risk assessments.
Job Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience)
- 5+ years of experience in AppSec, DevSecOps, or related roles
- 7+ years experience in related field (preferred)
- Certifications: OSCP, CISSP, CSSLP, CEH, or similar.
- Experience with cloud-native security in Azure, AWS, and GCP.
- Hands-on experience with NIST, HIPAA, and SOC 2 application security compliance, including security assessments and control implementation.
- Experience leading penetration testing engagements and managing remediation in collaboration with development teams.
- Experience with bug bounty programs or working with security researchers.
- Experience implementing or supporting a security champions program is a plus.
Benefits
- 401k Retirement Plan
- Medical, Dental and Vision insurance on first day of employment
- Generous Paid Time Off
- Employee Assistance Program and more
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
• Design, build, and maintain end-to-end CI/CD pipelines in GitLab, with a strong focus on SAP platforms. • Develop, standardize, and document reusable CI/CD pipeline templates and components. • Automate manual deployment, release, and remediation processes. • Implement and support DevSecOps best practices, including security, quality, and compliance checks within pipelines. • Collaborate closely with infrastructure, security, and application teams to support on-prem (VMware) and cloud (GCP / Kubernetes) environments. • Contribute to the definition and adoption of DevOps standards and best practices across the organization. • Support knowledge sharing and technical guidance within the DevOps team.
DevOps Security Engineer
Decentralized MastersLearn how to leverage the new world of Decentralized Finance to multiply your capital.
Role Description You will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets. That is the job. Everything else is secondary. We need someone who breaks things for a living. Someone who looks at a login page and sees six attack vectors. Someone who reads a pull request and catches the injection vulnerability that two senior developers missed. Someone who lies awake thinking about the phishing campaign that hasn't been invented yet. If that sounds exhausting, this is not your role. If that sounds like Tuesday, keep reading. Your primary responsibilities are security and quality assurance: - Own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship. - Own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response. - Write production code when security and QA responsibilities are covered. Qualifications - 5+ years in software engineering roles with meaningful, hands-on security and QA experience. - Fullstack development experience: you can build and ship features across frontend (React or equivalent) and backend (Node.js, Python, Go, or equivalent). - Hands-on penetration testing and vulnerability assessment experience across web applications, APIs, and cloud infrastructure. - Strong working knowledge of OWASP standards, including the OWASP Top 10, OWASP Testing Guide, and OWASP secure coding practices. - Experience building automated test frameworks and integrating testing into CI/CD pipelines. - AWS expertise (EC2, ECS/EKS, Lambda, VPC, IAM, S3, RDS, CloudFront, WAF). - Infrastructure as Code experience (Terraform, CloudFormation, or Pulumi). - Container technologies: Docker and Kubernetes in production environments. - Scripting and automation proficiency in Bash and Python. - Experience with secrets management tools (HashiCorp Vault, AWS Secrets Manager, or similar). - Familiarity with security and testing tools (Burp Suite, OWASP ZAP, Selenium, Cypress, Jest, Postman, or equivalent). - Strong communication skills: you can explain security risks and quality tradeoffs clearly to non-technical stakeholders. Requirements - Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies. - Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks. - Perform security-focused code reviews across frontend, backend, and infrastructure code. - Implement and manage secrets management, access controls, and least-privilege policies. - Build and maintain incident response playbooks. - Stay ahead of Web3 and crypto-specific attack vectors. - Manage and coordinate external security audits and penetration tests from third-party firms. - Design and implement test strategies across all products. - Build and maintain automated testing frameworks and CI quality gates. - Define and track quality metrics. - Write and execute security test cases. - Perform both white-box and black-box testing. - Test across the full stack. - Maintain and improve cloud infrastructure on AWS using Infrastructure as Code. - Own CI/CD pipelines. - Harden infrastructure. - Build logging, monitoring, and alerting across all services. - Ensure audit trails for user actions, system changes, and access events. - Manage production reliability, incident response, and cost optimization. - Contribute production code across frontend and backend. - Participate in architecture discussions and code reviews. Benefits - Competitive salary + performance-based incentives tied to retention & LTV improvement. - Direct exposure to founders. - Team Offsites. - Remote work. - High ownership, high-impact role.
DevOps Security Engineer
Decentralized MastersLearn how to leverage the new world of Decentralized Finance to multiply your capital.
About Legacy Legacy is an easy-to-use, non-custodial Web3 wallet designed to protect digital assets through beneficiary protection and seamless DeFi access. Users can swap across chains, earn yield in one click, and safeguard wealth for the next generation. Legacy is built by the team behind Decentralized Masters - a profitable $50M+ education and investment ecosystem with 4,000+ high-net-worth investors. We’ve launched. Demand is strong. Now we need someone to own the post-acquisition customer journey and turn users into long-term, high-LTV subscribers. About the Software Division We are building a portfolio of software products inside the Decentralized Masters ecosystem, including: - Legacy Wallet – a non-custodial Web3 wallet with beneficiary protection and seamless DeFi access - Trading Bot – automated crypto execution tools for serious investors - Future fintech and investor infrastructure tools We are now building the retention and lifecycle engine that will power long-term recurring revenue across all products. About the Role You will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets. That is the job. Everything else is secondary. We need someone who breaks things for a living. Someone who looks at a login page and sees six attack vectors. Someone who reads a pull request and catches the injection vulnerability that two senior developers missed. Someone who lies awake thinking about the phishing campaign that hasn't been invented yet. If that sounds exhausting, this is not your role. If that sounds like Tuesday, keep reading. Your primary responsibilities are security and quality assurance. You own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship. You also own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response. And because we are a small, senior team, you will write production code when security and QA responsibilities are covered. You are not a consultant or a checkbox auditor. You are an engineer who ships, and whose code happens to make everything else harder to break. The ideal candidate has spent time at major product-driven fintech and crypto companies where a single security failure can destroy user trust overnight. What You Will Own Security (Primary) - Own the security posture across all products: Legacy, Trading Bot, and future platforms. If something gets breached, it is your problem. If nothing gets breached, it is because of your work. - Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies - Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks - Perform security-focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews miss - Implement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least-privilege policies - Build and maintain incident response playbooks. When something breaks, you lead the response, run the post-mortem, and ship the fix - Stay ahead of Web3 and crypto-specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineering - Manage and coordinate external security audits and penetration tests from third-party firms Quality Assurance & Testing (Primary) - Design and implement test strategies across all products: unit tests, integration tests, end-to-end tests, API tests, and regression suites - Build and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching production - Define and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rate - Write and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial data - Perform both white-box and black-box testing, leveraging full codebase access to catch issues that surface-level QA would miss - Test across the full stack: frontend UI, backend APIs, database queries, third-party integrations, and on-chain interactions Infrastructure & DevOps (Foundation) - Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation) - Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deployment - Harden infrastructure: network security, IAM policies, container security, and environment isolation - Build logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent) - Ensure audit trails for user actions, system changes, and access events - Manage production reliability, incident response, and cost optimization Fullstack Development (When the fortress is secure) - Contribute production code across frontend and backend, bringing a security-first mindset to every feature you build - Build features, fix bugs, and ship improvements alongside the engineering team - Every line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by default - Participate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decision
DevOps Security Engineer
Decentralized MastersLearn how to leverage the new world of Decentralized Finance to multiply your capital.
About Legacy Legacy is an easy-to-use, non-custodial Web3 wallet designed to protect digital assets through beneficiary protection and seamless DeFi access. Users can swap across chains, earn yield in one click, and safeguard wealth for the next generation. Legacy is built by the team behind Decentralized Masters - a profitable $50M+ education and investment ecosystem with 4,000+ high-net-worth investors. We’ve launched. Demand is strong. Now we need someone to own the post-acquisition customer journey and turn users into long-term, high-LTV subscribers. About the Software Division We are building a portfolio of software products inside the Decentralized Masters ecosystem, including: - Legacy Wallet – a non-custodial Web3 wallet with beneficiary protection and seamless DeFi access - Trading Bot – automated crypto execution tools for serious investors - Future fintech and investor infrastructure tools We are now building the retention and lifecycle engine that will power long-term recurring revenue across all products. About the Role You will be the single person responsible for the security of a platform that tracks hundreds of millions in digital assets. That is the job. Everything else is secondary. We need someone who breaks things for a living. Someone who looks at a login page and sees six attack vectors. Someone who reads a pull request and catches the injection vulnerability that two senior developers missed. Someone who lies awake thinking about the phishing campaign that hasn't been invented yet. If that sounds exhausting, this is not your role. If that sounds like Tuesday, keep reading. Your primary responsibilities are security and quality assurance. You own penetration testing, vulnerability assessments, threat modeling, automated test frameworks, and CI quality gates across every product we ship. You also own infrastructure: AWS, CI/CD pipelines, monitoring, and incident response. And because we are a small, senior team, you will write production code when security and QA responsibilities are covered. You are not a consultant or a checkbox auditor. You are an engineer who ships, and whose code happens to make everything else harder to break. The ideal candidate has spent time at major product-driven fintech and crypto companies where a single security failure can destroy user trust overnight. What You Will Own Security (Primary) - Own the security posture across all products: Legacy, Trading Bot, and future platforms. If something gets breached, it is your problem. If nothing gets breached, it is because of your work. - Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies - Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks - Perform security-focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews miss - Implement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least-privilege policies - Build and maintain incident response playbooks. When something breaks, you lead the response, run the post-mortem, and ship the fix - Stay ahead of Web3 and crypto-specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineering - Manage and coordinate external security audits and penetration tests from third-party firms Quality Assurance & Testing (Primary) - Design and implement test strategies across all products: unit tests, integration tests, end-to-end tests, API tests, and regression suites - Build and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching production - Define and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rate - Write and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial data - Perform both white-box and black-box testing, leveraging full codebase access to catch issues that surface-level QA would miss - Test across the full stack: frontend UI, backend APIs, database queries, third-party integrations, and on-chain interactions Infrastructure & DevOps (Foundation) - Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation) - Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deployment - Harden infrastructure: network security, IAM policies, container security, and environment isolation - Build logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent) - Ensure audit trails for user actions, system changes, and access events - Manage production reliability, incident response, and cost optimization Fullstack Development (When the fortress is secure) - Contribute production code across frontend and backend, bringing a security-first mindset to every feature you build - Build features, fix bugs, and ship improvements alongside the engineering team - Every line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by default - Participate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decision


