Apex Systems logo
Apex Systems

Apex Systems, an IT staffing and workforce solutions firm, provides recruiting and staffing services to large and small companies alike. Founded in 1995 by thre

DevSecOps Engineer

Location

North Carolina

Posted

3 days ago

Salary

$70 - $95 / hour

Seniority

Senior

No structured requirement data.

Job Description

DevSecOps Engineer

Apex Systems

Title: DevSecOps Engineer Employee Type: Contract Location: Greensboro, NC, US Pay Range: $90 - $95 per hour Job#: 3036531 Job Description: Hey, Pat from Everforth Apex here again. Have a Devsecops opportunities that is focused on actual app dev development and OWASP. Looking for people in the North Carolina area or able to relocate to it from anywhere on the east coast. I can pay anywhere from 70-80/hr. My ai assistant riley will call you, but if your a perfect fit, please send your email to pkopczynski@apexsystems.com so that you have a direct line to me DevSecOps Engineer Location: Greensboro, North Carolina (Partial Remote) Role Overview Our organization is seeking two DevSecOps Engineers for the Technology Risk Office’s Application Security team. This role is responsible for conducting security assessments across applications, including web, mobile, and APIs. The position functions as a consultative partner to developers, focusing on explaining security issues, guiding remediation, and integrating security tools within the CI/CD pipeline. This is a contract-to-hire opportunity. Key Responsibilities - Review vulnerabilities identified by security tools and work directly with development teams to explain issues and guide remediation efforts. - Engage in hands-on development and scripting to create and maintain tool integrations within the security ecosystem. - Support end-to-end application security services, including intake, assessment scoping, and application team engagement. - Conduct SAST, SCA, DAST, API security, and mobile security assessment activities, including onboarding, validation, reporting, and remediation guidance. - Assist in reducing the application security backlog and improve vulnerability management by working with application teams on findings and closure. - Enable stronger security throughout the software development lifecycle through automated, developer-friendly security tools and processes. Required Qualifications Education: Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or equivalent related experience. Experience: A strong development background is critical. Roles are available for candidates with 3+ years and 6+ years of relevant experience in application security, DevSecOps, or software development. An understanding of OWASP Top 10-level concepts is expected. Technical Skills: - Demonstrated ability to code and communicate at a developer level, preferably with experience in Java or Python. - Experience with Application Security, secure SDLC, and DevSecOps principles within CI/CD pipelines. - Knowledge of security testing (SAST, SCA/OSCA, DAST), API security, and vulnerability validation. - Familiarity with tools such as GitHub, Jira, and Jenkins. - Understanding of cloud security concepts and REST/SOAP APIs. - Strong communication skills to explain vulnerabilities, risk, and remediation clearly to developers and stakeholders. Preferred Qualifications - A Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Security, or a related field. - Experience with tools such as Checkmarx, Sonatype Nexus IQ, Black Duck, or Noname API Security. - Knowledge of Docker, Kubernetes, AWS, or Azure. - Relevant certifications such as CISSP, CSSLP, GIAC, Security+, AWS Security, or Azure Security. Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico. Everforth Apex uses a virtual recruiter as part of the application process. Click here for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at https://www.apexsystems.com/privacy-policy Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide. Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you require an accommodation under the Americans with Disabilities Act to participate in an interview with a virtual recruiter or to use our website for a search or application, UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex Systems.

Related Categories

Related Job Pages

More DevOps Engineer Jobs

Mastercard logo

Lead, SRE Engineer

Mastercard

Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma

DevOps Engineer3 days ago
Full TimeRemoteTeam 38,800Since 1966

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Lead, SRE Engineer Lead SRE Engineer, Site Reliability Engineering Our Purpose: Mastercard powers economies and empowers people across more than 200 countries and territories worldwide. We are committed to building an inclusive, digital economy that benefits everyone, everywhere-by making transactions safe, simple, smart, and accessible. Through secure data, trusted networks, strong partnerships, and relentless innovation, we help individuals, financial institutions, governments, and businesses unlock their greatest potential. About the Role: Mastercard's Program aligned Site Reliability Engineering (SRE) teams are dedicated to delivering a seamless experience for our customers. We achieve this by maintaining every aspect of our Programs infrastructure and technology ecosystem to the highest standards, ensuring compliance with rigorous security requirements. Within Mastercard, SRE focuses on the reliability and performance of core infrastructure, networks, and foundational services that power our applications. Our mission is to ensure these components operate with excellence, enabling applications to deliver an outstanding customer experience. In this role, you will join our Payments Network SRE team and take ownership of continuously assessing and elevating the end to end service quality of our platform. You will leverage data to drive root cause analysis and deliver strategic insights to key stakeholders on resource utilization, capacity forecasting, and performance trends-ensuring the availability, scalability, and resilience of our network. Key Responsibilities: Lead continuous assessments of the application infrastructure supporting critical Mastercard applications, focusing on health, performance, monitoring and alerting, and capacity analysis. Collaborate with Product and Development teams to forecast growth requirements and ensure scalability and resiliency. Champion observability as a core principle for infrastructure services by assessing environments and technologies to uncover gaps in monitoring and alerting. Design and implement strategies to close these gaps, ensuring all infrastructure telemetry is integrated into a unified, single-pane-of-glass view. Build custom dashboards to investigate and perform root cause analysis on complex issues. Lead regular incident reviews with internal support teams to ensure root causes are identified. When patterns of failure or compatibility issues between software and infrastructure emerge, develop and implement strategies to remediate or mitigate risks. Leverage automation and AI technologies to enhance proactive issue detection, enable self-healing capabilities, reducing Mean Time to Detect (MTTD) and Mean Time to Mitigate (MTTM). Develop testing and validation plans for new environment builds, disaster recovery exercises and post-maintenance activities to certify environment readiness before customer traffic is routed to it. Champion continuous learning, development, and knowledge sharing across networking and other infrastructure disciplines to strengthen multi-disciplinary SRE team capabilities. Lead training initiatives for team members and Product and Development on networking aspects of the platforms. Evaluate vendor hardware, firmware, and software upgrade roadmaps, and conduct proof-of-concept (POC) testing to identify potential risks and opportunities for improvement in upcoming releases. All about you: • 5-10 years of experience in an SRE or SRE related operations role, including 3+ years supporting e commerce, financial services, or large scale SaaS platforms. • Excellent infrastructure troubleshooting and analytical problem solving skills. • Strong hands on experience with observability and monitoring tools such as Splunk, Dynatrace, or equivalent, with a proven ability to triage and investigate complex issues. • Familiarity with network telemetry tools such as SolarWinds and NetScout. • Proficiency in packet level debugging, including capturing traffic with tools like tcpdump and analyzing packets using Wireshark. • Broad understanding of end to end infrastructure supporting payment platforms-spanning platform services, networking, databases, and storage. • Experience with automation and Infrastructure as Code tools such as Chef, Ansible, and Terraform, as well as structured data formats (JSON/YAML). • Excellent communication skills with the ability to coordinate cross functional troubleshooting efforts and lead RCA processes to closure. • Demonstrated ability to troubleshoot complex production issues, perform root cause analysis, and drive long term corrective actions. • Experience partnering with development teams to shape architecture, define SLIs/SLOs, and embed reliability into services from design through operation. • Strong understanding of monitoring and observability ecosystems, including Prometheus, Grafana, ELK/EFK, Splunk, and OpenTelemetry. • Effective incident management skills with a structured, analytical approach to problem solving. The Payments Network SRE team is responsible for the runtime availability of some of Mastercard's most critical core payment systems, which support national infrastructure and operate 24/7 year-round. As a result, this role will include periodic on-call responsibilities when required. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: • Abide by Mastercard's security policies and practices;• Ensure the confidentiality and integrity of the information being accessed;• Report any suspected information security violation or breach, and• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Ireland

Principal DevSecOps Infrastructure Engineer

ASRC Federal

ASRC Federal, a wholly owned subsidiary of Alaska’s largest Alaskan-owned and operated company, the Arctic Slope Regional Corporation (ASRC), is a leading pro

DevOps Engineer3 days ago

Role Description ASRC Federal is seeking a Principal DevSecOps Infrastructure Engineer to support DSOP enterprise platform sustainment, modernization, and cloud operations across Army environments. This role provides engineering expertise across Linux/Windows systems, cloud-native infrastructure, Kubernetes orchestration, and observability stacks. - Perform day-to-day operations of cloud and on-premise infrastructure supporting DSOP - Manage compute, storage, networking, and automation tools - Configure, deploy, and maintain platform components in containerized environments - Implement monitoring, alerting, and logging solutions for operational visibility - Troubleshoot complex system issues across distributed environments - Maintain Infrastructure-as-Code (IaC) pipelines for consistent deployments - Support system security compliance, patching, and RMF requirements - Coordinate with DevSecOps, cybersecurity, and platform engineering teams Qualifications - A Bachelor’s Degree in Computer Science, Electronics Engineering or other Engineering or Technical discipline is required. An advanced degree is desirable. - 9+ years of DevSecOps Infrastructure Engineer experience - Expertise with Kubernetes, Docker, cloud services (AWS, Azure), and Linux administration - Experience with Terraform, Ansible, GitLab CI/CD, or similar IaC tools - Familiarity with DoD cyber compliance frameworks - Strong troubleshooting and automation skills Benefits - Competitive pay and benefits packages - Health care, dental, vision, life insurance - 401(k) - Education assistance - Paid time off including PTO, holidays, and any other paid leave required by law EEO Statement ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.

United States
Full TimeRemoteTeam 10,001+Since 1954H1B Sponsor

• Design, build, troubleshoot, and maintain automation and integration capabilities for mission-focused cloud and software delivery environments • Develop automation that improves consistency, reliability, and delivery speed • Support secure software delivery, operational sustainment, and compliance-driven engineering activities • Help convert engineering needs into practical scripts, tools, pipelines, documentation, and repeatable processes • Create and maintain documentation, standard operating procedures, troubleshooting guides, and evidence artifacts • Support secure configuration management, vulnerability remediation, scan integration, and compliance support activities • Troubleshoot complex issues across application, operating system, infrastructure, cloud, network, identity, and CI/CD boundaries • Coach and provide guidance to less experienced professionals; may serve as a task lead

Rhode Island
$149.5K - $201.3K / year
Stord, Inc. logo

Staff Site Reliability Engineer, Security

Stord, Inc.

Stord, Inc. is a global leader in cloud supply chain technology and expertise. The company is committed to improving supply chains by relying on the cloud to he

DevOps Engineer4 days ago

Role Description We are seeking a scrappy, high-ownership Staff Site Reliability Engineer (SRE) to join our lean, fast-moving SRE team. This is a security-focused engineering role rather than a policy or audit one. You'll write code, build automation, integrate scanners into CI/CD, ship Terraform modules the rest of the team can adopt, and drive Dependabot triage with engineering teams. Together, you'll define what "secure by default" actually looks like in our GCP environment and GitHub organization, then make it operational. What You'll Build - Cloud Security Posture Management - Assess and harden Stord's GCP footprint (GKE, IAM, Cloud Armor), and codify the baseline in Terraform and policy-as-code where it makes sense. - Build continuous posture monitoring against that baseline, with a published gap list and remediation schedule. - Drive the evaluation, integration, and rollout of new security tooling as the program matures. - Vulnerability and Dependency Management - Establish and automate the vulnerability and dependency remediation workflow across engineering teams. - Own Dependabot configuration and triage workflows across our GitHub organization. - Build supply-chain controls into CI/CD. - Wire container image scanning and DAST/network scanning programs into the same workflow. - Security Solutions Engineering - Build security capabilities that the broader SRE team can run as part of their normal operating model. - Ship documentation, runbooks, and self-service tooling that make your designs portable to the rest of the team. - Set the engineering bar for security work inside SRE. - Partner cross-functionally with engineering teams on app security questions. Qualifications - Deep GCP and GKE security experience. - Dependabot and secret scanning at scale. - CI/CD supply chain hardening. - Cloud security posture management in practice. - Infrastructure-as-code and automation fluency. - Systems-level technical fluency. - Track record of designing for operability. Required Soft Skills - Ownership & Accountability. - Strong Communication. - Collaborative Approach. - Production Mindset. - Learning Agility. - Directed AI-Assisted Development. Strongly Preferred - Container and image scanning. - DAST and network scanning programs. - Cloudflare edge security. - Detection engineering on GCP. Nice to Have - Prior experience standing up a security program inside an SRE or platform team. - Familiarity with the current supply-chain threat landscape and recent CISA guidance. - Contributions to open-source security tooling or published security research. What Success Looks Like - 30 days: You've ramped on Stord's GCP footprint, GitHub configuration, and existing security tooling. - 90 days: The vulnerability and dependency remediation workflow is live with at least one engineering team as a pilot. - 6–12 months: The remediation workflow is rolled out across engineering.

United States