Senior Devsecops Engineer

heavy construction specialists

📍 Remote🌐 Remote🕐 26d ago🔗 devopsjobs

Job Description

**We are HCSS.** For the last **40 years,** we have been developing software to help construction companies streamline their operations. Based in Sugar Land, TX, our mission is helping customers achieve excellence through our proven customer-centric, end-to-end solutions and exceptionally helpful service, while providing a great life for our employees. With this mission at the core of everything we do, HCSS is a pioneer and leader in the construction software space and a consistently recognized employer. We have earned _Best Companies to Work for in Texas_ honors for **18** **consecutive years** and have been named a _USA Today Top Workplace_. HCSS has also been recognized by _Built In_ as a _Best Place to Work in Greater Houston_ and by _Construction Executive_ for our technology innovation, reflecting our strong culture, industry leadership, and commitment to excellence. **WHO WE NEED:**  As a **Senior DevOps Engineer specializing in DevSecOps and Application Security**, you will play a pivotal role in improving, securing, and standardizing software delivery practices across development teams. This role combines senior-level DevOps engineering experience with a strong focus on application security, secure SDLC practices, CI/CD security automation, vulnerability management, secrets management, cloud security, and developer enablement. This role is especially focused on **application security**, including SAST, DAST, SCA, secrets scanning, API security, secure coding practices, threat modeling, vulnerability triage, risk-based remediation, and security integration withinC I/CD pipelines. The successful candidate will serve as a technical leader and trusted advisor who helps development teams deliver secure software at scale. **Qualifications:** * **Experience:** Minimum of 5 years of experience in application security, DevSecOps, or a related field, with a deep focus on secure software development and security testing practices. * **Cloud Expertise:** Strong hands-on experience with securing applications deployed in Azure environments, including using Azure-native security tools such as Azure Key Vault, Azure Security Center, Azure DevOps, and others. * **Security Tools & Practices:** Expertise in security tools such as SAST, DAST, software composition analysis (SCA), and secrets management solutions (e.g., HashiCorp Vault, Azure Key Vault). Experience with integrating these tools into CI/CD pipelines. * **Secure Development Lifecycle:** In-depth understanding of the secure development lifecycle (SDLC) and DevSecOps best practices, with experience embedding security into every phase of software development. * **Vulnerability Management:** Experience with vulnerability management practices, including the use of security scanning tools, risk assessment, and remediation. * **Compliance Knowledge:** Familiarity with security and compliance frameworks such as OWASP, NIST, CIS, * SOC 2, ISO 27001, PCI DSS, GDPR, or similar. * **Collaboration & Communication:** Excellent communication skills with the ability to articulate security concepts to both technical and non-technical stakeholders. Experience collaborating cross-functionally with development, security, and operations teams. **Preferred Qualifications:** * **Security Certifications:** Certified in cloud security (e.g., Microsoft Certified: Azure Security Engineer, CISSP, Certified Cloud Security Professional (CCSP), or equivalent). * **Threat Modeling**: Experience with threat modeling techniques and frameworks to assess and address potential security risks early in the design process. * **Experience with Microservices & APIs**: Strong understanding of microservices architecture and API security practices. * **Security Tools:** Experience with tools such as SonarQube, Veracode, Checkmarx, Snyk, Black Duck, Mend, GitHub Advanced Security, Semgrep, Burp Suite, OWASP ZAP, Wiz, Prisma Cloud, Aqua, or similar. **Role Responsibilities:** * **DevSecOps Integration:** Embed security into the entire software development lifecycle (SDLC) by implementing security practices, tools, and automation to support continuous integration/continuous delivery (CI/CD) pipelines. * **Application Security Expertise:** Lead efforts in identifying, prioritizing, and mitigating security risks and vulnerabilities in both new and existing applications. Provide subject-matter expertise on application security best practices, secure coding, and threat modeling. * **Azure Cloud Security:** Utilize Azure Cloud services to ensure secure infrastructure deployment and configuration. Implement best practices for securing Azure environments, leveraging services like Azure Key Vault, Azure Security Center, and more. * **Static and Dynamic Application Security Testing:** Lead efforts around Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate vulnerabilities in both the codebase and runtime environments. * **Secrets Management:** Implement, manage, and continuously improve secrets management solutions (e.g. Azure Key Vault) to protect sensitive information across multiple environments. * **Software Composition Analysis (SCA):** Oversee software composition analysis to identify and manage vulnerabilities in third-party libraries and dependencies, ensuring compliance with security policies. * **Automation and Infrastructure as Code:** Develop and maintain infrastructure as code (IaC) practices using tools like Terraform to automate the provisioning and management of secure cloud environments. * **Security Policies & Compliance:** Ensure compliance with industry security standards (e.g., OWASP, NIST, CIS) and regulatory requirements. Create and enforce security policies related to application security and cloud infrastructure. * **Collaboration & Mentorship:** Collaborate with cross-functional teams to ensure security is prioritized across development, operations, and product teams. Mentor junior engineers on DevSecOps best practices and tools. **Travel Requirements:** * Occasional travel to our office may be requested up to once or twice a year **BENEFITS & PERKS:** Part of our mission is to provide a great life for our employees. We believe that when our people are happy, they do their best work. Some of the benefits and perks we offer include: * Flexibility to work Remotely * Medical, dental, and vision coverage with **company-paid** and employee-paid options * Paid holidays, sick days, and personal time off * Employee Resource Groups (**ERGs**) that foster connection and inclusion * On-site amenities including a covered basketball court, soccer field, track, pickleball/tennis courts, gym, etc. * Dog-friendly campus and WiFi-accessible courtyards * 401(k) with a **5%** company match * Coverage for employee professional development and wellness * And more!