1

Devsecops Jobs in Colorado (NOW HIRING)

Senior DevSecOps Engineer

Denver, CO · On-site

$117K - $161K/yr

As a Sr DevSecOps Engineer you will be responsible for; • Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build ...

DevSecOps Engineer

Aurora, CO · On-site +1

$69K - $141K/yr

DevSecOps Engineer Job Category: Engineering Time Type: Full time Minimum Clearance Required to Start: TS/SCI with Polygraph Employee Type: Regular Percentage of Travel Required: Up to 10% Type of ...

Senior DevSecOps Engineer

Denver, CO

$117K - $161K/yr

As a Sr DevSecOps Engineer you will be responsible for; · Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build ...

Parsons is looking for a professional, energetic DevSecOps Engineer who can develop and deploy applications within tactical edge environments and hardware. In this role, your knowledge of application ...

As our DevSecOps Engineer , you'll help design, implement, and maintain the security controls, compliance processes, and automation capabilities that protect our SaaS applications and cloud ...

DevSecOps Engineer The Opportunity: Seeking a DevSecOps Engineer tomanage CI/CD pipeline and infrastructure in an Agile design, development, integration and deployment of a mission management ...

DevSecOps Engineer

Broomfield, CO · On-site

$116 - $145/hr

DevSecOps Engineer Secure the systems that keep innovation moving. At Gogo, security, reliability, and compliance are foundational to delivering exceptional connectivity experiences for business ...

DevSecOps Engineer

Denver, CO · On-site

$103K - $181K/yr

Parsons is looking for a professional, energetic DevSecOps Engineer who can develop and deploy applications within tactical edge environments and hardware. In this role, your knowledge of application ...

Parsons is looking for a professional, energetic DevSecOps Engineer who can develop and deploy applications within tactical edge environments and hardware. In this role, your knowledge of application ...

DevSecOps Engineer The Opportunity: Seeking a DevSecOps Engineer tomanage CI/CD pipeline and infrastructure in an Agile design, development, integration and deployment of a mission management ...

Showing results 41-60

Devsecops information

See Colorado salary details

$34.2K

$86.7K

$129.9K

How much do devsecops jobs pay per year?

As of Sep 5, 2026, the average yearly pay for devsecops in Colorado is $86,661.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,000.00 and $102,500.00 per year, depending on experience, location, and employer.

What is a DevSecOps?

A DevSecOps job focuses on integrating security into the software development and operations process. Professionals in this role work to automate security measures, ensure compliance, and identify vulnerabilities throughout the development lifecycle. They collaborate with development, operations, and security teams to embed security best practices into CI/CD pipelines. The goal is to create secure software efficiently without slowing down development and deployment.

What are the key skills and qualifications needed to thrive in the DevSecOps position?

To thrive as a DevSecOps professional, you need expertise in secure software development, CI/CD pipelines, cloud infrastructure, automation, and strong knowledge of cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools such as Jenkins, Docker, Kubernetes, Terraform, and security certifications like CISSP or AWS Certified Security are typically required. Strong problem-solving abilities, effective communication, and a collaborative mindset are valuable soft skills. These are essential to ensuring security is integrated throughout the development lifecycle while enabling efficient deployment and cross-team collaboration.

What are some common challenges DevSecOps professionals face on the job?

DevSecOps professionals often navigate the challenge of balancing rapid development cycles with the need for robust security, which requires both technical adaptability and continuous vigilance. They may encounter resistance to adopting new security practices within development teams, making communication and advocacy skills crucial. Additionally, staying updated with evolving security threats and ensuring compliance with industry standards can be demanding. These challenges offer opportunities to make a significant impact on organizational security and to develop expertise in both security and automation, leading to diverse career advancement possibilities.

Is DevSecOps a good career?

DevSecOps is a growing field that combines development, security, and operations to improve software security and deployment efficiency. It requires skills in automation, cloud platforms, and security tools, making it a valuable and in-demand career path with strong job prospects.

What are the most commonly searched types of Devsecops jobs in Colorado?

The most popular types of Devsecops jobs in Colorado are:

What are popular job titles related to Devsecops jobs in Colorado?

For Devsecops jobs in Colorado, the most frequently searched job titles are:

What cities in Colorado are hiring for Devsecops jobs?

Cities in Colorado with the most Devsecops job openings:

Infographic showing various Devsecops job openings in Colorado as of August 2026, with employment types broken down into 91% Full Time, 3% Part Time, 1% Temporary, and 5% Contract. Highlights an 73% Physical, 9% Hybrid, and 18% Remote job distribution, with an average salary of $86,661 per year, or $41.7 per hour.

Senior DevSecOps Engineer

ALTEN Technology USA

Denver, CO • On-site

$117K - $161K/yr

Full-time

Posted 20 days ago


Job description

We're ALTEN Technology USA, an engineering company helping clients bring groundbreaking ideas to life-from advancing space exploration and life-saving medical devices to building autonomous electric vehicles. With 3,000+ experts across North America, we partner with leading companies in aerospace, medical devices, robotics, automotive, commercial vehicles, EVs, rail, and more.
As part of the global ALTEN Group-57,000+ engineers in 30 countries-we deliver across the entire product development cycle, from consulting to full project outsourcing.
When you join ALTEN Technology USA, you'll collaborate on some of the world's toughest engineering challenges, supported by mentorship, career growth opportunities, and comprehensive benefits. We take pride in fostering a culture where employees feel valued, supported, and inspired to grow.
As a Sr DevSecOps Engineer you will be responsible for;
• Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.
• Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.
• Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.
• Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.
• Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.
• Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.
• Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.
• Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.
• Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.
• Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.
• Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.
• Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.
• Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.
• Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.
• Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.
• Technologies & Tools
• AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS
• Yocto-based embedded Linux package development
• Embedded hypervisors, Linux device drivers, BSPs, and boot flows
• Custom build systems and CI/CD pipelines
• Docker, Snyk, SonarQube, and software composition analysis tools
• Static analysis, software composition analysis, artifact signing, and vulnerability management tools
• Python, Bash, and Go
• Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence
• GitHub and GitLab
• Networking security, secure boot, firmware signing, and secure update technologies
Qualifications;
• Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.
• Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.
• Experience with Yocto, BSPs, OS layers, kernel configuration, boot flows, device drivers, and embedded platform security.
• Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.
• Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.
• Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.
• Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.
• Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.
• Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.
• Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.
• Experience defining reusable platform practices across multiple products, programs, hardware variants, or software release branches.
• Strong debugging, problem-solving, and root-cause analysis skills.
• Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.
Salary Range: $125k-$150k
The actual salary offered is dependent on various factors including, but not limited to, location, the candidate's combination of job-related knowledge, qualifications, skills, education, training, and experience
MANDATORY FOR ALL REMOTE/HYBRID AND/OR CALIFORNIA, DISTRICT OF COLUMBIA, HAWAII, COLORADO, MARYLAND, CONNECTICUT, ILLINOIS, MINNESOTA, VERMONT, MASSACHUSETTS, NEVADA, NEW YORK, RHODE ISLAND, WASHINGTON STATE & CINCINNATI, OHIO, JERSEY CITY, NEW JERSEY, TOLEDO, OHIO BASED ROLES.
Note: Due to the nature of the work, only US Persons (citizens or permanent residents) need apply for this position. - OPTIONAL
All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, age, genetic information, or pregnancy.
Please beware of job seeker scams and see this important notice on our careers page for more information about our recruiting process.
Compliance Notice: Alten USA is a federal contractor subject to the requirements of the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA) and Executive Order 11246. We are an Equal Opportunity Employer and consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
Drug Screening Requirement: As a federal contractor, Alten USA maintains a drug-free workplace. All candidates selected for employment will be required to successfully complete a pre-employment drug screening as a condition of hire.