OpenLoop Logo

OpenLoop

DevSecOps Integration Engineer

Reposted 11 Days Ago
Easy Apply
Remote
Hiring Remotely in USA
Senior level
Easy Apply
Remote
Hiring Remotely in USA
Senior level
The DevSecOps Integration Engineer will oversee security integration in software engineering, manage security validations, support CI/CD practices, and guide on security issues through risk communication.
The summary above was generated by AI

About The Role

OpenLoop is looking for a DevSecOps Integration Engineer to join our team remotely or at our HQ in Des Moines, IA. 

In this role, you will be responsible for being our DevSecOps subject matter expert across the IT, software engineering and product teams.  The ideal candidate is someone who has the ability to provide strategic oversight, possesses a wide range of cybersecurity and software engineering technical acumen, and has the ability to think like an attacker to guide us through potential security issues.

What You’ll Do:

  • Build relationships with developers and stakeholders to incorporate security principles into engineering design and deployments.
  • Supervise validation in security controls and testing across projects, using SAST, DAST, IAST and RASP tools, documenting any security findings, outlining remediation options and overseeing mitigation.
  • Oversee implementation of defensive practices and countermeasures across infrastructure and applications.
  • Draft and uphold CI/CD security strategy and practices in tandem with other technical team leads.
  • Lead continuous product and application security reviews, focused on secure development practices, threat modeling, vulnerability management, architecture and application security design.
  • Ensure security principles and validations are consistently implemented throughout the CI/CD pipeline by embedding robust, security-focused practices into all automation processes.
  • Attend and participate in product meetings addressing security requirements for new and existing products.
  • Build services and tools to enable developers and engineers to use security components successfully
  • Simplify automation that applies security inter-workings with CI/CD pipelines.
  • Support the ability to “shift left” and incorporate security early on and throughout the development lifecycle.
  • Communicate vulnerability results to both technical and non-technical stakeholders, focused on risk tolerance and threat to the business,  in order to gain support through influential messaging.
  • Leverage vulnerability database sources to understand the weakness, probability and remediation options supplied by vendors
  • Join forces and provision security principles in architecture, infrastructure and code. 
  • Regularly research and learn new tactics, techniques and procedures (TTPs).
  • Partner with teams to define key performance indicators (KPIs) and metrics across business units.
  • Ensure regulatory compliance (e.g., PCI, HIPAA, HITRUST, NIST CSF) through effective security controls and processes.
  • Other duties as assigned.

Who You Are:

  • Bachelor's degree in computer science (preferred), information assurance, MIS or related field, or equivalent.
  • 7+ years of security and systems administration-related experience, to include 3+ years of related cloud and security engineering experience 
  • Experience with operations and security across Amazon Web Services (AWS) and/or Google Cloud Platform (GCP).
  • Experience with agile workflows, including Scrum and Kanban.
  • Understanding of containers (e.g., Docker) and container orchestration (e.g., Docker Swarm, Kubernetes).
  • Proficient in securing Windows and *nix operating systems, endpoint applications, networking protocols and devices.
  • Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface while performing rapid, continuous implementation.
  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and (SLDC).
  • Knowledge of Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO) requirements.
  • Self-starter mentality requiring minimal supervision.
  • Analytical and problem-solving abilities with a proactive, risk-based approach.
  • Highly organized and efficient.
  • Demonstrated strategic and tactical thinking, along with decision-making skills and business acumen.
  • Experience in healthcare or digital health is a plus.
  • Strong internal service minded, to provide support to all teams and leadership
  • Adaptability to handle dynamic and challenging environments.
  • Energetic, resourceful, and appropriate work intensity to get the work done.
  • Strong people acumen and relationship skills.

About OpenLoop

OpenLoop was co-founded by CEO, Dr. Jon Lensing, and COO, Christian Williams, with the vision to bring healing anywhere. Our tele-health support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states.

 

Our Company Culture

We have a relatively flat organizational structure here at OpenLoop. Everyone is encouraged to bring ideas to the table and make things happen. This fits in well with our core values of Autonomy, Competence and Belonging, as we want everyone to feel empowered and supported to do their best work.

Sound like a good fit? We’d love to meet you.

 

 

Top Skills

Amazon Web Services (Aws)
Dast
Docker
Google Cloud Platform (Gcp)
Iast
Kubernetes
Rasp
Sast

Similar Jobs

7 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
155K-190K Annually
Senior level
155K-190K Annually
Senior level
Aerospace
The Senior DevSecOps Integration Engineer will manage cloud security for multiple environments, design secure development practices, mentor others, and oversee infrastructure costs and vendor relationships.
Top Skills: AWSAzureBashGitGithub ActionsHelmJavaScriptKubernetesPythonTerraform
2 Hours Ago
Remote
United States
180K-230K Annually
Senior level
180K-230K Annually
Senior level
Software • Defense
The Senior Software Engineer will develop modern user interfaces, improve application performance, and mentor peers in a collaborative, async-first environment, focusing on best practices and user accessibility.
Top Skills: AWSCi/CdJavaScriptKubernetesNode.jsPlaywrightPostgresReactRedisTypescript
2 Hours Ago
Remote
USA
180K-240K Annually
Senior level
180K-240K Annually
Senior level
Software • Defense
Design, implement, and operate event-driven distributed systems and data pipelines; ensure reliability, observability, and security of data infrastructure.
Top Skills: AWSAzureBicepCloudFormationDelta LakeIcebergJavaKafkaNode.jsPostgresReactS3TerraformTypescript

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account