1

Secret Cleared Devsecops Engineer Jobs in New York

DevSecOps Engineer

Manhattan, NY ยท On-site

$140 - $195/hr

As a DevSecOps Engineer, you will sit at the intersection of development, security, and operations ... Embed SAST, DAST, SCA, and secret scanning into automated build pipelines -- ensuring ...

Senior DevSecOps Engineer

Manhattan, NY ยท On-site

$170 - $230/hr

Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY ยท Hybrid

$125K - $171K/yr

Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY ยท On-site

$125K - $171K/yr

Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

DevSecOps Engineer

New York, NY ยท On-site

$180K - $200K/yr

We're hiring a DevSecOps engineer to own security architecture and practice across our AI and data ... and secret scanning) built into how we ship, not added on after. * Monitoring, detection, and ...

... Cog Kit BGV must be cleared to start What are the top 3 skills required for this role ... Secure SDLC / DevSecOps * SAST, DAST, IAST, SCA * Web, Mobile & API Security Testing * Manual ...

Department of Defense (DoD) to issue a Secret Clearance, which includes US Citizenship. The Senior DevSecOps Software Engineer is responsible for the following areas: * Design, implement, and ...

DevOps Engineer

Manhattan, NY ยท On-site

$58.25 - $79.75/hr

Integrate automated testing, security scanning, dependency scanning, secret detection, container ... Champion DevSecOps best practices across the software development lifecycle. Required ...

Senior Security Engineer, IAM

Manhattan, NY ยท On-site

$126K - $173K/yr

AI DevSecOps & Collaboration * Design identity controls embedded in AI-augmented CI/CD pipelines ... secret scanning, IaC identity policy, workload identity) with AI-generated fix recommendations ...

Senior Security Engineer, IAM

Newark, NJ ยท On-site

$119K - $164K/yr

AI DevSecOps & Collaboration * Design identity controls embedded in AI-augmented CI/CD pipelines ... secret scanning, IaC identity policy, workload identity) with AI-generated fix recommendations ...

Strong software development lifecycle (SDLC) and DevSecOps experience * Experience with enterprise ... Active TS/SCI clearance - or eligibility to get one (meaning at least an active Top Secret)

next page

Showing results 1-20

Secret Cleared Devsecops Engineer information

What is a Secret Cleared DevSecOps Engineer?

A Secret Cleared DevSecOps Engineer is an IT professional who integrates security practices into the software development and operations (DevOps) process while holding a 'Secret' level security clearance, typically required for working on sensitive government or defense projects. These engineers are responsible for automating security measures, ensuring compliance with security policies, and maintaining secure development pipelines. Their clearance allows them to access classified information necessary for their work, making them essential for secure government or defense software development environments.

What are the key skills and qualifications needed to thrive as a Secret Cleared DevSecOps Engineer?

To thrive as a Secret Cleared DevSecOps Engineer, you need expertise in software development, security best practices, automation, and experience with cloud infrastructure, typically supported by a relevant degree and an active Secret security clearance. Proficiency with CI/CD tools like Jenkins, Kubernetes, Docker, security scanning tools, and configuration management systems such as Ansible or Terraform is essential. Strong problem-solving, collaboration, and communication skills are crucial for integrating security seamlessly into development and operations processes. These skills ensure the delivery of secure, reliable systems that meet stringent government standards and safeguard sensitive information.

What are some common challenges faced by Secret Cleared DevSecOps Engineers when integrating security into CI/CD pipelines?

Secret Cleared DevSecOps Engineers often encounter challenges such as balancing rapid deployment with stringent security controls, ensuring compliance with government regulations, and managing sensitive data securely within automated pipelines. They must collaborate closely with development, operations, and security teams to identify vulnerabilities early and automate security testing without slowing down delivery. Additionally, maintaining security documentation and audit trails for classified projects adds another layer of complexity to the role.

What is the difference between Secret Cleared Devsecops Engineer vs Cybersecurity Analyst?

AspectSecret Cleared Devsecops EngineerCybersecurity Analyst
CertificationsSecurity+, CISSP, DevSecOps certificationsSecurity+, CEH, CISSP
Work EnvironmentDevOps teams, software development, cloud platformsSecurity operations centers, threat analysis, incident response
Employer & Industry UsageGovernment agencies, defense contractors, tech firmsCorporations, government agencies, consulting firms

The Secret Cleared Devsecops Engineer focuses on integrating security into the development and deployment processes within DevOps environments, often requiring security clearances. In contrast, a Cybersecurity Analyst primarily monitors and responds to security threats, with less emphasis on development processes. Both roles require security certifications and may work in similar industries, but their core responsibilities and daily tasks differ significantly.

What are popular job titles related to Secret Cleared Devsecops Engineer jobs in New York?

For Secret Cleared Devsecops Engineer jobs in New York, the most frequently searched job titles are:

What cities in New York are hiring for Secret Cleared Devsecops Engineer jobs?

Cities in New York with the most Secret Cleared Devsecops Engineer job openings:

Infographic showing various Secret Cleared Devsecops Engineer job openings in New York as of August 2026, with employment types broken down into 90% Full Time, and 10% Part Time. Highlights an 70% In-person, and 30% Remote job distribution.

DevSecOps Engineer

Lockedinai

Manhattan, NY โ€ข On-site

$140 - $195/hr

Other

Posted 16 days ago


Job description

Job TitleDevSecOps EngineerCompensation$140,000 โ€“ $195,000 USD / yr## Role OverviewWe are looking for a security-minded, automation-first DevSecOps Engineer to embed security into every stage of LockedIn AIโ€™s software development and deployment lifecycle. This is a shift-left security role โ€” you will ensure that security is not an afterthought bolted on at the end, but a fundamental part of how code is written, tested, built, deployed, and operated across a platform serving over 1 million users.As a DevSecOps Engineer, you will sit at the intersection of development, security, and operations. Your scope spans the entire software delivery pipeline โ€” from secure coding practices and automated security testing in CI/CD pipelines, to infrastructure hardening and container security, to runtime monitoring and incident response.The ideal DevSecOps Engineer combines strong software engineering and DevOps skills with deep security expertise. You automate everything โ€” from static and dynamic analysis in the build pipeline to vulnerability scanning in production. You understand that security at startup speed means building automated systems that protect without slowing anyone down.## Key Responsibilities### Secure CI/CD Pipeline Engineering* Design, implement, and maintain security-integrated CI/CD pipelines that automate security testing at every stage โ€” from code commit through build, test, staging, and production deployment* Embed SAST, DAST, SCA, and secret scanning into automated build pipelines โ€” ensuring vulnerabilities are caught before code reaches production* Implement container image scanning, infrastructure-as-code security validation, and dependency vulnerability checks as mandatory gates in the deployment pipeline* Build automated policy enforcement that blocks deployments failing security thresholds while providing developers with clear, actionable remediation guidance### Application Security & Secure Development Practices* Champion shift-left security practices โ€” working directly with development teams to integrate secure coding standards, threat modeling, and security reviews early in the development process* Conduct security code reviews, architecture reviews, and threat modeling sessions for new features and services โ€” identifying risks and recommending mitigations before code is written* Develop and maintain secure coding guidelines, security patterns, and reusable security libraries that make it easy for developers to build secure features by default* Track and remediate application vulnerabilities โ€” managing the vulnerability lifecycle from discovery through prioritization, remediation, and verification### Infrastructure Security & Cloud Hardening* Implement infrastructure security best practices across cloud environments (AWS, GCP, or Azure) โ€” including network segmentation, least-privilege IAM policies, encryption at rest and in transit, and security group management* Secure containerized environments โ€” hardening Docker images, configuring Kubernetes security policies (network policies, pod security standards, RBAC), and implementing runtime container security monitoring* Manage Infrastructure as Code (IaC) security โ€” scanning Terraform, Pulumi, or CloudFormation templates for misconfigurations, compliance violations, and security risks before deployment* Implement secrets management solutions (HashiCorp Vault, AWS Secrets Manager, or similar) that eliminate hardcoded credentials and enforce secure secret rotation and access controls### Security Monitoring, Detection & Incident Response* Build and maintain security monitoring and alerting systems โ€” implementing SIEM integration, log aggregation, and anomaly detection that provide real-time visibility into security events across the platform* Develop detection rules, correlation queries, and automated response playbooks that identify and respond to security incidents โ€” including unauthorized access, suspicious API activity, and infrastructure anomalies* Participate in on-call security rotations and lead security incident response โ€” coordinating investigation, containment, remediation, and post-incident review* Monitor for AI-specific security events โ€” including adversarial inputs to LLM systems, prompt injection attempts, and unauthorized model access### Vulnerability Management & Compliance* Own the vulnerability management lifecycle โ€” discovering, prioritizing, tracking, and driving remediation of vulnerabilities across applications, infrastructure, containers, and dependencies* Implement automated vulnerability scanning across the full stack โ€” including application code, third-party libraries, container images, cloud configurations, and AI model serving infrastructure* Ensure security controls and practices align with relevant compliance frameworks and industry best practices โ€” building toward formal compliance readiness as the company scales* Maintain security documentation โ€” including architecture diagrams, risk registers, security policies, and audit trails that support compliance and organizational knowledge sharing### Security Culture, Training & Cross-Functional Collaboration* Champion a โ€œsecurity as codeโ€ culture across the engineering organization โ€” making security practices automated, transparent, and developer-friendly* Develop and deliver security training and awareness programs for engineering teams โ€” including secure coding workshops, threat modeling sessions, and security tooling onboarding* Work closely with co-founders, engineering, product, and operations to align security priorities with business objectives and product roadmap* Stay current on the latest DevSecOps tools, security vulnerabilities, attack techniques, and industry best practices โ€” continuously improving LockedIn AIโ€™s security posture## Required Qualifications### Experience* 3+ years of experience in DevSecOps, application security, or a combined DevOps/security engineering role* Demonstrated experience integrating security tooling into CI/CD pipelines and automating security processes* Hands-on experience hardening cloud infrastructure, containerized environments, and software delivery pipelines* Experience working cross-functionally with engineering, security, and operations teams in a fast-moving environment* Startup or high-growth environment experience preferred โ€” comfort working in ambiguity, moving fast, and wearing multiple hats### Education* Bachelorโ€™s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field.* Relevant security certifications are a strong plus: CDP, OSCP, CKS, Security+, CISSP, or CEH โ€” we value demonstrated security engineering skill over credentials.### Technical Skills* Strong proficiency in Python, Bash, or Go with experience writing security automation, tooling, and infrastructure code* Deep experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins, ArgoCD, or similar) and integrating security scanning tools into automated pipelines* Hands-on expertise with containerization and orchestration security (Docker, Kubernetes) โ€” including image hardening, pod security, network policies, and runtime security monitoring* Experience with IaC tools (Terraform, Pulumi, CloudFormation) and IaC security scanning (Checkov, tfsec, or similar)* Proficiency with security scanning tools โ€” SAST (SonarQube, Semgrep), DAST (OWASP ZAP, Burp Suite), SCA (Snyk, Dependabot, Trivy), and secret scanning (GitLeaks, TruffleHog)* Experience with SIEM platforms, security monitoring, and log analysis (Splunk, Elastic, Datadog Security, or similar)### Strategic & Soft Skills* Security-first mindset with a developer-friendly approach: you build security systems that protect without creating friction โ€” making the secure path the easiest path for developers* Strong written and verbal communication โ€” you can write clear security policies, explain vulnerabilities to development #J-18808-Ljbffr