We bring out the best in every business.
Senior DevSecOps Engineer
Location
Virginia
Posted
26 days ago
Salary
$131K - $271.6K / year
Seniority
Senior
Job Description
Senior DevSecOps Engineer
SAP
Title: Senior DevSecOps Engineer Location: Herndon, VA, US, 20171 Department: Information Technology Job Description: We help the world run better At SAP, we keep it simple: you bring your best to us, and we'll bring out the best in you. We're builders touching over 20 industries and 80% of global commerce, and we need your unique talents to help shape what's next. The work is challenging – but it matters. You'll find a place where you can be yourself, prioritize your wellbeing, and truly belong. What's in it for you? Constant learning, skill growth, great benefits, and a team that wants you to grow and succeed. COMPANY DESCRIPTION SAP is the global market leader for business software and related services, and SAP National Security Services Inc. ® (SAP NS2®) is an independent U.S. subsidiary, offering SAP solutions with specialized levels of security and support to meet the requirements of U.S. national security and critical infrastructure customers. Must be a U.S. citizen; this position requires access to customer data. SAP NS2 does not offer Visa sponsorships for this role. All internals must have manager’s approval to transfer. ABOUT THE ROLE We are seeking a Senior DevSecOps Engineer to lead security efforts across our cloud infrastructure, CI/CD pipelines, and production workloads. You will be hands-on, building security automation, and hardening multi-cloud environments. This role partners closely with DevOps, Platform Engineering, Corporate IT, and Product teams to embed security into every stage of the development lifecycle. You'll contribute to security tooling strategy, build policy-as-code frameworks, and drive security automation across cloud-native infrastructure. A key requirement for this position is deep, demonstrated expertise in DevSecOps practices — including designing and operating security automation within CI/CD pipelines, implementing policy-as-code, and integrating cloud-native security tooling into developer workflows at scale. PLATFORM EXPERTISE (REQUIRED) This role requires hands-on experience integrating and operating cloud security tooling within modern DevSecOps workflows. Candidates should be prepared to demonstrate depth across multiple areas during the interview process. - - Configured and tuned cloud security policies, rules, and risk scoring to align with organizational risk appetite and compliance frameworks - Built custom integrations using security platform APIs, including automated workflows for ticket creation, alert routing, CI/CD gating, and reporting - Leveraged CSPM, CIEM, vulnerability scanning, container/Kubernetes security, and IaC scanning capabilities in production - Experience with EDR/XDR platforms such as CrowdStrike Falcon for endpoint detection, threat hunting, and incident response across cloud and hybrid environments - Ability to design and operate vulnerability management programs including scan scheduling, prioritization, SLA enforcement, and remediation tracking - Experience with Dynatrace or equivalent APM/observability platforms for infrastructure monitoring, application performance analysis, and security-relevant telemetry - Ability to correlate observability data with security findings to improve detection, triage, and incident response workflows - Experience with Tenable (Tenable.io, Nessus, or Tenable.sc) for vulnerability scanning automation, including API-driven scan scheduling, asset discovery, reporting pipelines, and integration into CI/CD or remediation workflows - Experience with Trend Micro (Cloud One, Vision One, or Deep Security) for automated workload and endpoint protection, including policy deployment and management, container security, and integration with orchestration and incident response tooling KEY RESPONSIBILITIES - - Cloud Security Architecture: Assist with security reviews across cloud infrastructure, CI/CD pipelines, and Kubernetes-based workloads. Develop scalable mitigation strategies and secure baselines. - DevSecOps Integration: Build automation, policy-as-code, and security tooling that enables development teams to shift left. Integrate security findings into CI/CD workflows, IaC pipelines, and developer feedback loops. - Vulnerability Management: Drive vulnerability management and remediation across cloud and container environments. Prioritize issues using risk context, implement mitigations, and design preventative controls across software supply chains. - Infrastructure Hardening: Design and implement secure baselines for cloud resources, Kubernetes clusters (EKS/GKE/AKS), IAM, and network architecture. Enforce guardrails through policy-as-code. - Security Tooling: Support the configuration, optimization, and integration of CNAPP platforms as a core component of our cloud security stack. Drive adoption, tune policies, build API integrations, and ensure CNAPP capabilities are fully leveraged across the organization. - Cross-Functional Partnership: Build deep partnerships with DevOps, Platform Engineering, Security Engineering, Product, and SecOps teams. Enable secure-by-design solutions without becoming a bottleneck. REQUIRED QUALIFICATIONS - - 7+ years of experience in security engineering, DevSecOps, or cloud security operations - Strong DevOps/infrastructure background: you’ve built and operated CI/CD pipelines, managed Kubernetes clusters, and automated infrastructure - Deep AWS cloud security expertise (equivalent Azure/GCP experience also considered with some AWS proficiency) - Hands-on experience with Kubernetes security (EKS, GKE, or AKS) and container security principles - Proficiency with Infrastructure as Code: Terraform, CloudFormation, Helm, or Pulumi - Strong scripting and automation skills in Python, Go, Shell, and/or HCL - Proven ability to lead threat modeling exercises and translate findings into actionable controls - Deep understanding of IAM, cloud identity, and least-privilege principles at scale - Practical knowledge of web application security fundamentals (OWASP Top 10) PREFERRED QUALIFICATIONS - - Experience building custom API integrations for reporting, automation, or SOAR workflows - Experience with FedRAMP or other compliance-driven environments (SOC 2, ISO 27001, NIST 800-53 R5, CMMC) - Background in SRE or platform engineering with a pivot into security - Experience with complementary security tooling: SIEM/SOAR platforms, EDR, network security - AWS, Azure, GCP cloud certifications - Bachelor’s degree in Computer Science, Cybersecurity, or a related field (equivalent experience accepted) - Experience working with remote, globally distributed teams WHAT SETS YOU APART You’re a security engineer with a builder’s mindset. You’ve come up through DevOps or infrastructure and you bring that operational DNA to everything you do. You automate, you ship, you iterate, and you partner with engineering rather than gatekeep. You can walk us through a deployment you’ve architected, explain your policy tuning philosophy, and show us how you’ve used risk data to drive real remediation outcomes. Bring out your best SAP innovations help more than four hundred thousand customers worldwide work together more efficiently and use business insight more effectively. Originally known for leadership in enterprise resource planning (ERP) software, SAP has evolved to become a market leader in end-to-end business application software and related services for database, analytics, intelligent technologies, and experience management. As a cloud company with two hundred million users and more than one hundred thousand employees worldwide, we are purpose-driven and future-focused, with a highly collaborative team ethic and commitment to personal development. Whether connecting global industries, people, or platforms, we help ensure every challenge gets the solution it deserves. At SAP, you can bring out your best. We win with inclusion SAP’s culture of inclusion, focus on health and well-being, and flexible working models help ensure that everyone – regardless of background – feels included and can run at their best. At SAP, we believe we are made stronger by the unique capabilities and qualities that each person brings to our company, and we invest in our employees to inspire confidence and help everyone realize their full potential. We ultimately believe in unleashing all talent and creating a better world. SAP is committed to the values of Equal Employment Opportunity and provides accessibility accommodations to applicants with physical and/or mental disabilities. If you are interested in applying for employment with SAP and are in need of accommodation or special assistance to navigate our website or to complete your application, please send an e-mail with your request to Recruiting Operations Team: Careers@sap.com. For SAP employees: Only permanent roles are eligible for the SAP Employee Referral Program, according to the eligibility rules set in the SAP Referral Policy. Specific conditions may apply for roles in Vocational Training. Qualified applicants will receive consideration for employment without regard to their age, race, religion, national origin, ethnicity, age, gender (including pregnancy, childbirth, et al), sexual orientation, gender identity or expression, protected veteran status, or disability. Compensation Range Transparency: SAP believes the value of pay transparency contributes towards an honest and supportive culture and is a significant step toward demonstrating SAP’s commitment to pay equity. SAP provides the annualized compensation range inclusive of base salary and variable incentive target for the career level applicable to the posted role. The targeted annual combined range for this position is 131000-271600USD. The actual amount to be offered to the successful candidate will be within that range, dependent upon the key aspects of each case which may include education, skills, experience, scope of the role, location, etc. as determined through the selection process. Any SAP variable incentive includes a targeted dollar amount and any actual payout amount is dependent on company and personal performance. Please reference this link for a summary of SAP benefits and eligibility requirements: SAP North America Benefits. AI Usage in the Recruitment Process For information on the responsible use of AI in our recruitment process, please refer to our Guidelines for Ethical Usage of AI in the Recruiting Process. Please note that any violation of these guidelines may result in disqualification from the hiring process. Requisition ID: 453103 | Work Area: Information Technology | Expected Travel: 0 - 10% | Career Status: Professional | Employment Type: Regular Full Time | Additional Locations: #LI-Hybrid
Related Guides
Related Categories
Related Job Pages
More Solutions Engineer Jobs
• Lead the design, development, and implementation of MES solutions across complex manufacturing environments. • Architect, configure, and customize Apriso MES solutions for multi-site, global manufacturing organizations. • Develop MES integrations with ERP systems including SAP MII and other middleware platforms. • Build, enhance, and troubleshoot MES modules including Quality, Material Management, Machine Integration, and Production flows. • Develop robust .NET applications, APIs, and services used for MES-ERP interoperability, provider portals, and enterprise web applications. • Modernize and upgrade legacy .NET applications, including security enhancements, encryption, and performance improvements. • Create REST/SOAP APIs, perform complex SQL development (PL/SQL, T-SQL), and support ETL pipelines across diverse platforms. • Leverage cloud architecture expertise across cloud platforms for MES hosting, migration, and automation solutions. • Deploy and manage distributed development environments, CI/CD pipelines, and cloud-based MES integrations. • Lead development teams, providing architectural guidance, code reviews, and delivery oversight. • Lead complete MES/ERP implementations for Fortune 500 and government clients.
• Own and drive the project management for the modules within your scope, including ensuring the right tasks are getting done, and the status of each implementation is reported correctly. • Work with customers to understand their specific needs, special situations, and use cases, then identify and implement solutions. • Hands-on configuration of the module, including setup, data triage, and customization. • Understand data dependencies and help resolve data issues. • Develop expertise in how the module fits within the broader SchooLinks product ecosystem. • Continuously engage with customers to maintain project velocity, generate buy-in, and drive adoption. • Work with Customer Success to collaborate on customer interaction, escalation, and timelines. • Continuously define and document problems and challenges faced by our partners. • Assist the Product team with quality assurance and improvement of the product.
Solutions Architect, Data Analytics – TS Cleared
Trace3We Believe All Possibilities Live in Technology
• Assess customer technical and operational requirements, with a primary focus on the State of Colorado, and develop near- and long-term analytics strategies aligned to existing environments, regulatory constraints, and funding models. • Lead technical discovery and solution shaping in collaboration with account executives, customers, and technology partners, providing presales architectural guidance across Trace3 Government's Data & Analytics portfolio (not limited to Splunk). • Serve as a senior technical resource throughout presales and delivery activities, contributing to solution design, architectural validation, service scoping, and Statements of Work (SOWs), while ensuring alignment with customer objectives and delivery best practices. • Independently perform complex architecture and consulting activities while collaborating with peer architects and engineers to stay current on vendor capabilities, platform best practices, and emerging analytics solutions for regulated environments. • Lead technical solution definition and service scoping, including contributing to architectures, solution designs, and Statements of Work (SOWs); support Bill of Materials (BOMs) development as needed to ensure alignment with customer requirements and delivery outcomes. • Apply delivery and architectural expertise to continuously improve presales-to-delivery workflows, tooling, and technical engagement models; provide recommendations to leadership based on real-world customer and project experience. • Use a consultative, collaborative approach to bridge account executives, engineering teams, and customers to ensure technical feasibility, clear expectations, and smooth handoff from presales to delivery. • Support strategic account planning and technical execution by aligning customer objectives, platform capabilities, and delivery methodologies to drive long-term analytics success within target government environments.
Solutions Architect - Enterprise Applications
ArdurraArdurra is an engineering consulting company delivering quality services and practical solutions that exceed client expectations, improve communities, and respe
Role Description Ardurra is looking to hire a Solutions Architect to join our Enterprise Applications team in Dallas, TX! This position is open to remote applicants. The Solutions Architect will be responsible for defining and governing the architecture across the company’s enterprise application landscape, including ERP (Deltek), integrations, and adjacent business systems. This role ensures that solutions are scalable, integrated, and aligned with business processes, while supporting ongoing operations, M&A integrations, and future transformation initiatives. The architect will partner closely with application owners, delivery teams, and business stakeholders to design practical, high-impact solutions across the enterprise. Primary Duties - Enterprise Application Architecture - Define and maintain the end-to-end architecture across enterprise systems, including ERP and other business applications - Ensure alignment between business processes, application capabilities, and system design - Guide decisions on configuration vs. customization - Integration Architecture - Own architecture for system integrations (APIs, middleware, Workato, etc.) - Define scalable and reusable integration patterns, including: - Real-time vs. batch processing - Error handling and monitoring - Data synchronization and reconciliation - Solution Design & Governance - Review and guide solution designs across projects and systems - Establish and enforce architecture standards and best practices - Ensure consistency, scalability, and reusability across solutions - M&A / System Onboarding - Architect integration of newly acquired businesses into the enterprise application landscape - Define repeatable patterns for: - Application integration - Data migration - System rationalization - Data & Application Ecosystem Alignment - Define and oversee data flows across systems - Partner with data and analytics teams to ensure: - Clear system-of-record ownership - Data consistency and integrity - Scalable reporting and analytics architecture - Technology & Tooling Strategy - Evaluate and guide usage of enterprise applications, ERP platforms, hosting platforms like Azure, and integration tools - Identify opportunities for simplification, standardization, and optimization across the application landscape - Cross-Functional Collaboration - Partner with application leads, integration teams, and business stakeholders across Finance, Operations, HR, and other functions - Act as a trusted technical advisor for enterprise application decisions Qualifications - 8–12+ years of experience in enterprise applications, solution architecture, or related roles - Strong experience with: - ERP systems (e.g., Deltek, Microsoft Dynamics 365, SAP, Oracle) - Integration platforms (e.g., Workato, MuleSoft, Boomi, APIs) - Hosting platforms (e.g. Azure) - SaaS application experience - Proven ability to design end-to-end solutions across multiple systems - Experience in integration-heavy environments and complex system landscapes - Strong understanding of data architecture, system integration, and security models - Ability to balance strategic thinking with hands-on problem solving Benefits - Competitive compensation - Rich benefits programs - Family-like culture - Opportunities for personal and professional development through Ardurra Academy and Leadership program - Support for career development with multiple career paths - Tools and resources for success and satisfaction in work - Positive benefits, time-off programs, and flexibility for work-life balance Company Description Ardurra is a multidisciplinary civil engineering services firm which provides broad-based solutions tailored to the specific needs of the public and private sector. We leverage the depth of our professional and technical expertise, as well as our integrated structure, to deliver practical, innovative solutions for our clients.




