The Weather Company, LLC

Headquartered in Brookhaven, Georgia, The Weather Company, LLC, founded in 1980, is a leading provider of weather data and forecasting services, reaching over 4

SkillBridge - DevSecOps Engineer

Location

United States

Posted

107 days ago

Salary

$0

Seniority

Senior

Job Description

SkillBridge - DevSecOps Engineer

The Weather Company, LLC

About The Weather Company: The Weather Company is the world’s leading weather provider, helping people and businesses make more informed decisions and take action in the face of weather. Together with advanced technology and AI, The Weather Company’s high-volume weather data, insights, advertising, and media solutions across the open web help people, businesses, and brands around the world prepare for and harness the power of weather in a scalable, privacy-forward way. The world’s most accurate forecaster globally, the company reaches hundreds of enterprise clients and more than 360 million monthly active users via its digital properties from The Weather Channel (weather.com) and Weather Underground (wunderground.com). Job brief: The DevSecOps Engineer will play a key role, working with the core application engineering team and the cybersecurity lead to ensure that all DROP Platform offerings meet security and compliance goals. This position is part of the Department of Defense (DoD) SkillBridge Program. SkillBridge provides active-duty service members the opportunity to gain civilian work experience during their last 180 days of service. Applicants must be active-duty military, within 180 days of separation, and receive approval from their command to participate. The impact you'll make: Set up and automate regular system patching Set up and automate static and dynamic code scanning Set up and automate vulnerability scanning Automate the creation of tickets and the production of evidence from scanning tasks Automate change management processes Build security and compliance dashboards and reports Perform security reviews on build environments and ensure all systems are maintained with the latest patches, and that security best practices are being followed Participate in agile/scrum processes to help ensure that security deliverables are triaged, prioritized, and slipstreamed into product delivery processes Collaborate and coordinate with 3rd party security consultants. Manage audit processes and triage results with the team. What you've accomplished: 5+ years of professional experience as a DevSecOps engineer Deep understanding of build automation processes and tools (GitHub Actions, Vercel, Jenkins, TravisCI) Expertise with container technologies (Docker, Kubernetes, Helm) Experience with different compliance standards (SOC2, CMMC, NIST, ISO) Familiarity with the Department of Defense (DoD) Impact Level 6 Ability to script/code in at least two of the following languages: bash, perl, python, ruby, groovy, JavaScript, PHP Solid understanding and experience with APIs (REST, XML, JSON) Extensive experience with at least one cloud provider (AWS, Azure) Experience with security tooling (Checkmarx, OWASP Zap, Skyk, Dependabot) Familiarity with issue tracking systems, especially JIRA Good communication and organizational skills Self-starter, open to learning new skills and accepting new challenges SkillBridge Eligibility: Active-duty service member within 180 days of separation. Able to obtain command approval to participate. Meets basic qualifications for the role

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 10,001+Since 1954H1B Sponsor

• Conducting and coordinating security reviews and audits of federal and non-federal data exchange partners • Providing security engineering support to the Security Team • Assisting OCSE staff in preparing audit responses and providing documentation for audits • Participating in routine and on-demand vulnerability scanning • Documenting and tracking internal POAMs for DFS systems • Assisting in the development and delivery of Security Awareness Training • Supporting incident response activities and ensuring proper collection of digital evidence • Developing policies and procedures for information systems reliability and security

United States
$102K - $138K / year
Job Closed
GuidePoint Security logo

Senior Security Consultant – Threat & Attack Simulation

GuidePoint Security

Founded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security solutions to help cl

Security Engineer107 days ago

• Lead and execute assessments including red team operations, purple team exercises, external and internal network penetration tests, cloud penetration tests, application and API security assessments, Active Directory security reviews, wireless security assessments, social engineering campaigns, and custom engagements — with minimal technical oversight • Map assessment activities to the MITRE ATT&CK framework and align engagements with industry methodologies such as PTES, OWASP, and NIST guidelines • Perform reconnaissance, exploitation, post-exploitation, lateral movement, and privilege escalation across enterprise environments including on-premises infrastructure, cloud platforms (AWS, Azure, GCP), and hybrid architectures • Assess cloud-native environments including IAM configurations, serverless functions, container orchestration, and Infrastructure-as-Code deployments • Conduct application and API penetration testing targeting OWASP Top 10 vulnerabilities, business logic flaws, and authentication/authorization weaknesses • Evade defensive controls including EDR, NDR, email security gateways, and network segmentation during red team operations • Author comprehensive assessment deliverables tailored to both technical and executive audiences that fully detail technical execution, root-cause deficiencies, business impact, and realistic remediation strategies • Communicate findings confidently to both technical teams and non-technical leadership, translating complex attack chains into clear business risk • Contribute to marketing and thought leadership through publishing research, speaking at industry conferences, authoring blog articles and whitepapers, hosting webinars, and developing security tools • Build automation, orchestration, and scripting solutions to reduce manual processes, improve efficiency, and enable new capabilities for evolving client needs • Develop and improve offensive tooling, custom implants, and C2 infrastructure to support assessment operations • Assist with practice development including improving existing service offerings, creating new offerings, and identifying emerging assessment areas such as AI/LLM security testing • Mentor junior and mid-level team members through regular one-on-one and group technical sessions, knowledge sharing, and hands-on guidance during engagements • Build strong client relationships by providing interactive, collaborative support and guidance that maximizes the value of every engagement • Represent GuidePoint professionally during pre-sales calls, scoping discussions, and client debriefs

United States
Job Closed
Scratch Financial logo

Senior Security Investigator

Scratch Financial

Scratch Financial is the world's simplest patient financing solution.

Security Engineer107 days ago
OtherRemoteTeam 11-50Since 1912H1B Sponsor

• Lead comprehensive, organized retail crime investigations • Conduct targeted investigations into Xfinity Mobile fraud • Analyze POS data, activation logs, account activity, surveillance footage • Partner with law enforcement agencies to build cases • Prepare investigative reports for senior management and stakeholders • Conduct investigative interviews • Collect, document, store, and maintain evidence according to guidelines • Participate in fraud awareness and training programs • Assist in compliance efforts by ensuring adherence to laws and regulations

California + 10 moreAll locations: California | Colorado | Hawaii | Illinois | New Jersey | New York | Maryland | Massachusetts | Minnesota | Vermont | Washington
$53.5K - $125.4K / year
Job Closed
Quisitive logo

Senior Security Consultant

Quisitive

Quisitive is a technology company helping customers generate transformational impact with immense value through cloud and payment solutions. A global company, Quisitive is proud to

Security Engineer107 days ago

• Partner with Security Coaches and Customer Success Managers (CSMs) to assess, harden, and continuously improve customer security postures across Microsoft 365 and Azure. • Own delivery for complex initiatives such as Zero Trust, threat detection/response, compliance programs. • Participate in technical workshops and solution alignment sessions. • Emphasize measurable outcomes, clear roadmaps, and repeatable implementation patterns • Design and tune Sentinel analytics rules, UEBA, data connectors, and KQL queries; implement playbooks for triage and automated response. • Lead Information Protection implementations: sensitivity labels, automatic/manual labeling, policy scoping. • Deploy Purview DLP for Exchange/SharePoint/OneDrive/Endpoints and establish data lifecycle and retention policies.

United States
Job Closed