1

Secret Cleared Devsecops Engineer Jobs in New York

Rumble Cloud is seeking a DevSecOps Engineer to embed security throughout the software development ... DAST, SCA, secret scanning, container scanning, and dependency analysis. * Implement secure ...

Senior DevSecOps Engineer

New York, NY · On-site

$125K - $171K/yr

Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY · Hybrid

$125K - $171K/yr

Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

DevOps Engineer

Manhattan, NY · On-site

$58.25 - $79.75/hr

Integrate automated testing, security scanning, dependency scanning, secret detection, container ... Champion DevSecOps best practices across the software development lifecycle. Required ...

DevOps Engineer

Manhattan, NY · On-site

$58.25 - $79.75/hr

Integrate automated testing, security scanning, dependency scanning, secret detection, container ... Champion DevSecOps best practices across the software development lifecycle. Required ...

Strong software development lifecycle (SDLC) and DevSecOps experience * Experience with enterprise ... Active TS/SCI clearance - or eligibility to get one (meaning at least an active Top Secret)

Strong software development lifecycle (SDLC) and DevSecOps experience * Experience with enterprise ... Active TS/SCI clearance - or eligibility to get one (meaning at least an active Top Secret)

Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their ... DevSecOps: Design and implement secret management within Kubernetes clusters, including encryption ...

next page

Showing results 1-20

Secret Cleared Devsecops Engineer information

Are Secret Cleared DevSecOps engineers in demand?

Secret Cleared DevSecOps engineers are in high demand due to the increasing need for secure software development in government and defense sectors. Their expertise in integrating security into development pipelines, along with security clearances, makes them valuable for organizations handling sensitive information, leading to strong job growth and competitive salaries.

What is a Secret Cleared DevSecOps Engineer?

A Secret Cleared DevSecOps Engineer is an IT professional who integrates security practices into the software development and operations (DevOps) process while holding a 'Secret' level security clearance, typically required for working on sensitive government or defense projects. These engineers are responsible for automating security measures, ensuring compliance with security policies, and maintaining secure development pipelines. Their clearance allows them to access classified information necessary for their work, making them essential for secure government or defense software development environments.

What are the key skills and qualifications needed to thrive as a Secret Cleared DevSecOps Engineer?

To thrive as a Secret Cleared DevSecOps Engineer, you need expertise in software development, security best practices, automation, and experience with cloud infrastructure, typically supported by a relevant degree and an active Secret security clearance. Proficiency with CI/CD tools like Jenkins, Kubernetes, Docker, security scanning tools, and configuration management systems such as Ansible or Terraform is essential. Strong problem-solving, collaboration, and communication skills are crucial for integrating security seamlessly into development and operations processes. These skills ensure the delivery of secure, reliable systems that meet stringent government standards and safeguard sensitive information.

Does a secret cleared Devsecops engineer help get a job?

Having a secret clearance can enhance a DevSecOps engineer’s job prospects by demonstrating trustworthiness and security clearance eligibility, which are often required for government or defense-related projects. Additionally, skills in automation, security tools, and cloud platforms increase employability in this field.

What are some common challenges faced by Secret Cleared DevSecOps Engineers when integrating security into CI/CD pipelines?

Secret Cleared DevSecOps Engineers often encounter challenges such as balancing rapid deployment with stringent security controls, ensuring compliance with government regulations, and managing sensitive data securely within automated pipelines. They must collaborate closely with development, operations, and security teams to identify vulnerabilities early and automate security testing without slowing down delivery. Additionally, maintaining security documentation and audit trails for classified projects adds another layer of complexity to the role.

What is the difference between Secret Cleared Devsecops Engineer vs Cybersecurity Analyst?

AspectSecret Cleared Devsecops EngineerCybersecurity Analyst
CertificationsSecurity+, CISSP, DevSecOps certificationsSecurity+, CEH, CISSP
Work EnvironmentDevOps teams, software development, cloud platformsSecurity operations centers, threat analysis, incident response
Employer & Industry UsageGovernment agencies, defense contractors, tech firmsCorporations, government agencies, consulting firms

The Secret Cleared Devsecops Engineer focuses on integrating security into the development and deployment processes within DevOps environments, often requiring security clearances. In contrast, a Cybersecurity Analyst primarily monitors and responds to security threats, with less emphasis on development processes. Both roles require security certifications and may work in similar industries, but their core responsibilities and daily tasks differ significantly.

What are popular job titles related to Secret Cleared Devsecops Engineer jobs in New York? For Secret Cleared Devsecops Engineer jobs in New York, the most frequently searched job titles are:
What job categories do people searching Secret Cleared Devsecops Engineer jobs in New York look for? The top searched job categories for Secret Cleared Devsecops Engineer jobs in New York are:
What cities in New York are hiring for Secret Cleared Devsecops Engineer jobs? Cities in New York with the most Secret Cleared Devsecops Engineer job openings:
Infographic showing various Secret Cleared Devsecops Engineer job openings in New York as of August 2026, with employment types broken down into 90% Full Time, and 10% Part Time. Highlights an 70% In-person, and 30% Remote job distribution.

DevSecOps Engineer

Rumble

New York, NY • On-site

Full-time

Re-posted 17 days ago


Job description

About RUM Group Inc.

RUM Group Inc. is an AI infrastructure and video company. Its Quake AI business delivers AI compute as a service, operating AI data centers including GPU and CPU compute, storage, and networking at scale. Rumble, RUM Group's video business and the original tenant of Quake AI, provides creators and enterprises a full suite of video technologies, unlocking reach, scale, and monetization. RUM Group is building the rails of the agentic-first enterprise: the AI compute, cloud infrastructure, and trust layer for the agentic AI future, advancing RUM Group's mission to maximize the power of human imagination. For more information visit www.rum.group.

Rumble Cloud is seeking a DevSecOps Engineer to embed security throughout the software development lifecycle for our cloud platform and customer-facing services. This is a hands-on engineering role that owns our Secure Software Development Lifecycle (SSDLC) end to end: you'll design it, operate it, partner with engineering teams to remediate vulnerabilities, and continuously harden the CI/CD pipelines that ship Rumble Cloud to production.

Our platform is built on OpenStack and Ceph, and this role sits at the intersection of application security, platform engineering, and developer enablement. You should be comfortable reviewing pipeline configurations, triaging SAST, DAST, SCA, and container scanning findings with developers, and driving practical security improvements across Python, Go, and TypeScript codebases without becoming a bottleneck to delivery.

You'll work closely with application, platform, and infrastructure teams, with architectural guidance from our Software Architect, to make security a core part of how we build and ship software. That includes defining secure coding standards, integrating automated security tooling into CI/CD, improving software supply chain integrity, supporting audit readiness, and helping engineers make sound, scalable security decisions in a fast-moving cloud environment.

Responsibilities
  • Own the SSDLC end to end, including secure coding standards, threat modeling, security gates, policy-as-code, and documentation suitable for audits, in partnership with the Software Architect in an advisory capacity.
  • Drive vulnerability identification, triage, and remediation across Python, Go, and TypeScript/React codebases, partnering directly with engineers to prioritize and fix issues effectively.
  • Design, harden, and optimize CI/CD pipelines using tools such as GitHub Actions, GitLab CI, Jenkins, or similar systems, ensuring security controls are integrated cleanly into developer workflows.
  • Integrate and operate security tooling across the software delivery lifecycle, including SAST, DAST, SCA, secret scanning, container scanning, and dependency analysis.
  • Implement secure software supply chain practices such as signed artifacts, SBOM generation, provenance controls, and related guardrails for build and release processes.
  • Manage secrets, credentials, and signing keys used by build and deployment pipelines, applying least-privilege access, rotation, and secure storage practices.
  • Partner with engineering teams to review code, assess risk, and recommend practical remediation approaches that improve security without unnecessarily slowing delivery.
  • Support security incident response and post-incident follow-up for application and platform issues, helping identify root causes and drive durable fixes.
  • Contribute to audit readiness and evidence collection for frameworks such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, especially where CI/CD controls and engineering practices are in scope.
  • Mentor engineers on secure development practices and help establish a culture where security is built into design, implementation, and release processes from the start.
Qualifications
  • Experience in a DevSecOps, application security, or product security role, including designing and operating a Secure Software Development Lifecycle (SSDLC).
  • Hands-on experience with CI/CD systems such as GitHub Actions, GitLab CI, Jenkins, or similar, including pipeline design, optimization, and hardening.
  • Strong knowledge of application security tooling including SAST, DAST, SCA, and container scanning, along with a practical understanding of the OWASP Top 10.
  • Ability to read and review code in at least one of Python, Go, or TypeScript and to work directly with developers on remediation.
  • Experience with Docker and Kubernetes, secrets management systems such as Vault, and authentication patterns such as OAuth2 and OpenID Connect.
  • Strong communication and collaboration skills, with the ability to influence engineering teams and drive secure practices without direct authority.
Preferred Qualifications
  • Security certifications such as CSSLP, OSCP, GWAPT, CISSP, or equivalent.
  • Experience with software supply chain security practices and tooling, including SLSA, Sigstore/cosign, and SBOM generation or validation.
  • Familiarity with OpenStack, Ceph, or other large-scale open-source infrastructure platforms.
  • Experience supporting audits or compliance initiatives such as ISO 27001, SOC 2, PCI DSS, or FedRAMP, including evidence collection tied to CI/CD and engineering controls.
  • Experience with threat modeling methodologies such as STRIDE or PASTA, and with IaC security scanning across Terraform, Ansible, and Kubernetes manifests.
  • Familiarity with multi-tenant SaaS or public cloud environments, and experience operating Rocky Linux or Ubuntu in production.

Annual Compensation Range:

$165,000 - $195,000 USD base + benefits + equity (If based in the United States)

$122,000 - $158,000 CAD base + benefits + equity (If based in Canada)

Note: The salary range listed for this position is a good faith estimate based on experience, qualifications, and internal compensation structure. The actual salary offered varies depending on the candidate's skill level and experience. This posting refers to an active vacancy within the organization.

Why Our Team Loves Working Here:

  • We are making a significant financial impact for our video creator community; we're proud of their success stories
  • We enjoy challenging the status quo and going head-to-head against Big Tech
  • We aren't afraid to try new things; we act fast and want to win
  • We pay competitive salaries and provide great benefits

EEO Statement:
Rumble is an equal opportunity employer.  We promote an equal playing field where everyone has the same opportunities regardless of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability status, or any other applicable characteristics protected by law. Rumble is an active participant in the e-verify program.

Physical demands of the position:
While performing the duties of this job, the employee is regularly required to sit for prolonged periods of time while using a computer and/or keyboard. The employee is required to communicate verbally and hear. The employee may be required to walk, reach with hands and arms, balance, and stoop or kneel. The employee may occasionally be required to lift and/or move up to 15 pounds. Specific vision abilities required by this job include clarity of vision at approximately 20 inches or less (i.e., working with small objects or reading small print), including the use of computers.