Public Partnerships
AppSec & DevSecOps Engineer
US Remote
Sponsorship not specified$53k-$800kDetected 30 days ago
Code ReviewAWSGCPAzureCloud PlatformsDockerKubernetesTerraformCI/CDCybersecurityPenetration TestingComplianceAgileHIPAACollaborationCISSP
About the role
- We are seeking an experienced and proactive Application Security (AppSec) and DevSecOps Engineer to embed security throughout the software development lifecycle and CI/CD pipelines.
Responsibilities
- Collaborate with engineering and product teams in Agile/Scrum environments to prioritize, track, and remediate security issues during sprint cycles.
- Develop and maintain threat models and perform design reviews. Lead threat modeling sessions and conduct in-depth security architecture reviews.
- Actively support the organization's secure software development lifecycle (SDLC) initiatives by integrating security controls, processes, and testing into development workflows and CI/CD pipelines.
- Perform and manage vulnerability assessments, code reviews, and penetration testing.
- Lead application-level penetration testing efforts, both internally and with external vendors.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
- 5+ years of experience in AppSec, DevSecOps, or related roles
- Education:
- Certifications:
- Working Conditions:
- Office and Remote work.
Nice to have
- 7+ years experience in related field
- OSCP, CISSP, CSSLP, CEH, or similar.
- Experience with cloud-native security in Azure, AWS, and GCP.
- Hands-on experience with NIST, HIPAA, and SOC 2 application security compliance, including security assessments and control implementation.
- Experience leading penetration testing engagements and managing remediation in collaboration with development teams.
- Experience with bug bounty programs or working with security researchers.
- Experience implementing or supporting a security champions program is a plus.
- Preferred Attributes:
Skills
- Integrate security at every phase of the software development lifecycle.
- Educate development teams on secure coding practices.
- Contribute to secure backlog grooming and definition of security-related user stories and acceptance criteria.
- Integrate security testing tools (SAST, DAST, SCA, IaC scanning) into CI/CD pipelines.
- Automate security checks to ensure continuous compliance and early detection.
- Ensure integration of security scanning outputs into ticketing systems and development workflows for traceable remediation.
- Remediate findings by working closely with developers and product teams.
- Monitor and manage third-party/open-source dependencies for known vulnerabilities.
- Conduct security code reviews using both automated and manual analysis techniques.
- Secure containerized environments (Docker, Kubernetes).
- Ensure cloud infrastructure security (AWS/GCP/Azure) using infrastructure-as-code (IaC) tools like Terraform or CloudFormation.
- Contribute to security policies, standards, and compliance efforts (e.g., ISO 27001, SOC 2, NIST 800-53, GDPR).
Compensation
- $120,000-$135,000
- At PPL, all aspects of employment regarding recruitment, hiring, training, promotion, compensation, benefits, transfers, layoffs, return from layoff, company-sponsored training, education, and social and recreational programs are based on merit, business needs, job requirements, and individual qualifications.
Benefits
- 401k Retirement Plan
- Medical, Dental and Vision insurance on first day of employment
- Generous Paid Time Off
- PPL believes in health, equality, and prosperity for everyone so we can succeed in changing the ways the public sector, including health, education, technology and human services industries, work.
Equal opportunity
- Public Partnerships is an Equal Opportunity Employer dedicated to celebrating diversity and intentionally creating a culture of inclusion.
Visa & Work Authorization
- disability, sexual orientation, marital, civil union, or domestic partnership status, past or present military service, citizenship status, family medical history or genetic information, family or parental status, or any
Apply directly at Public Partnerships →Create a free account for alerts like thisView Public Partnerships immigration profile
This listing is sourced directly from Public Partnerships's careers page and normalized into a canonical job model.