Senior DevSecOps Engineer
SoTalent · Milwaukee, WI
Apply & track with Apply EdgeSenior DevSecOps Engineer📍 Location: Milwaukee, WI, US🏢 Industry: Financial services 💼 Work Setting: HybridAre you passionate about securing cloud-native applications, automating security processes, and empowering engineering teams to build secure-by-design solutions?We are seeking an experienced Application & Cloud Security Engineer to strengthen application and cloud security capabilities across modern development environments. This role focuses on security automation, DevSecOps, vulnerability management, cloud security governance, and secure software development practices while collaborating closely with engineering, infrastructure, and product teams to reduce risk and enhance organizational security posture.Key ResponsibilitiesDesign and implement automated security solutions that reduce manual effort and improve operational efficiency.Partner with development, infrastructure, and engineering teams to embed security throughout the software development lifecycle.Provide expert guidance on application security, cloud security, and secure architecture best practices.Manage and support security tools integrated into CI/CD pipelines and development workflows.Conduct security assessments, code reviews, vulnerability analysis, and penetration testing activities.Implement and maintain security controls for cloud infrastructure, applications, and deployment pipelines.Monitor emerging threats, vulnerabilities, and industry trends to proactively identify and mitigate risks.Lead remediation efforts and work with stakeholders to address identified security findings.Establish and improve secure-by-default development standards, frameworks, and processes.Support compliance, regulatory, privacy, and governance requirements across technology environments.Develop security metrics, reporting, and continuous improvement initiatives.Mentor team members and promote security awareness and best practices throughout the organization.Required QualificationsBachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, MIS, or a related field, or equivalent professional experience.5+ years of experience in cybersecurity, software development, infrastructure engineering, DevOps, or related disciplines.4+ years of experience working with cloud platforms and CI/CD technologies.Strong knowledge of cloud security principles and secure application development practices.Hands-on experience with AWS, Kubernetes, GitLab CI, or similar cloud-native technologies.Proficiency in Python, JavaScript, or comparable scripting and automation languages.Experience implementing and managing DevSecOps processes and security automation.Experience conducting security testing such as:Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Software Composition Analysis (SCA)Vulnerability AssessmentsPenetration TestingStrong understanding of security risks, threat modeling, and vulnerability management practices.Excellent analytical, communication, and problem-solving skills.Preferred QualificationsExperience designing secure-by-default architectures and cloud-native security solutions.Knowledge of Infrastructure as Code (IaC) security and automated deployment pipelines.Experience integrating security tools into CI/CD workflows and developer platforms.Familiarity with cloud security posture management and infrastructure vulnerability scanning tools.Industry certifications such as CISSP, CSSLP, GSEC, GCIH, GPEN, GIAC, ISC(2), or equivalent.Experience mentoring engineers and leading security improvement initiatives.Key SkillsApplication SecurityCloud SecurityDevSecOpsAWSKubernetesCI/CD PipelinesGitLab CIPythonJavaScriptSecurity AutomationVulnerability ManagementPenetration TestingSASTDASTSoftware Composition Analysis (SCA)Secure Software Development Lifecycle (SSDLC)Threat ModelingSecurity ArchitectureInfrastructure as Code (IaC)Risk Assessment & Compliance