JobBobsReal-time global job discoveryLive

Senior DevSecOps Engineer

Cayuse · Remote · 2026-07-01

executiveRemote
Apply on the employer's site

About this role

<div class="content-intro"><p><span style="font-weight: 400;">The exciting world of scientific research is fueled by people with a passion for solving complex problems. At Cayuse, we are committed to our customers’ success by empowering organizations to conduct globally connected research that advances their impact on science, discovery and society. We build on that commitment with proven, integrated and easy-to-use technology that delivers exceptional value, and world class service and support that accelerates outcomes.</span></p> <p><span style="font-weight: 400;">But we are more than just an empowering platform powered by advanced technologies. We are a collaboration of exceptional, highly skilled people with multi-disciplinary expertise, and are building our team to support our ambitious growth plans. Cayuse’s foundational strength comes from our customer and employee focused values and commitment to industry-leading solutions. It’s an exciting time to become a key member of our growing team.</span></p></div><p>As a Senior DevSecOps Engineer, you will be a key technical leader driving the security, reliability, and integrity of our cloud-based infrastructure and SaaS products. This role embeds security throughout the software delivery lifecycle — shifting vulnerability detection left into the pipeline while operationalizing continuous monitoring and remediation in production. You will own our application and cloud vulnerability management program, leveraging tools like Snyk, SonarQube, and AWS Inspector to find, prioritize, and drive remediation of risk across a multi-product, multi-environment AWS platform.</p> <p>This is an AI-native role. We expect you to work fluently with AI engineering tools — Claude Code, GitHub Copilot, Atlassian Rovo, and similar — to accelerate triage, remediation, automation, and documentation, and to help the team build AI-augmented workflows into how we detect and fix risk. We're looking for someone who treats these tools as a force multiplier and applies sound judgment about where AI fits and where human review is non-negotiable, especially in a security context.</p> <p>This role combines deep technical expertise with a passion for mentoring. You will pair hands-on engineering with guiding colleagues in secure development and operational practices, and contribute to the overall maturity of our DevSecOps capability — with a strong emphasis on automation using Terraform and Bitbucket Pipelines.</p> <h2> </h2> <h2><strong>Responsibilities</strong></h2> <h3><strong>Vulnerability Management and Remediation</strong></h3> <ul> <li>Assist in the end-to-end vulnerability management lifecycle: discovery, triage, prioritization, remediation tracking, and reporting across applications, containers, and cloud infrastructure.</li> <li>Administer and tune <strong>Snyk</strong> (SCA, container, and IaC scanning), <strong>SonarQube</strong> (SAST and code quality gates), and <strong>AWS Inspector</strong> (EC2, ECR, and Lambda vulnerability scanning) to maximize signal and reduce false positives.</li> <li>Aggregate and normalize findings across scanners into a single prioritized backlog, using severity, exploitability, and asset criticality to drive risk-based remediation.</li> <li>Partner with product engineering teams to remediate findings, providing concrete guidance and tracking SLAs to closure rather than just reporting on counts.</li> <li>Establish and enforce policy-as-code and quality/security gates in CI so vulnerabilities are caught before merge and deployment.</li> <li>Drive container and base-image hygiene across EKS workloads, including image scanning, patching cadence, and remediation of vulnerable dependencies.</li> </ul> <h3><strong>Secure Pipelines and Automation</strong></h3> <ul> <li>Design, build, and maintain secure CI/CD pipelines using <strong>Bitbucket Pipelines</strong>, integrating Snyk, SonarQube, and other security scanning natively into the build and deploy flow.</li> <li>Build and maintain secure, scalable infrastructure using <strong>Terraform</strong>, applying IaC scanning and guardrails to prevent misconfiguration.</li> <li>Automate vulnerability discovery, ticket creation, and remediation workflows (e.g., auto-filing Jira tickets from scanner findings) to reduce toil and accelerate response.</li> <li>Develop and maintain automation tools and scripts (Python, Bash) to integrate security tooling, enrich findings, and report on posture.</li> <li>Manage cloud security posture across the AWS estate (managed through <strong>DuploCloud</strong>), including IAM, Security Groups, encryption, and configuration baselines.</li> </ul> <h3><strong>AI-Augmented Engineering</strong></h3> <ul> <li>Work AI-native: use tools like <strong>Claude Code</strong>, <strong>GitHub Copilot</strong>, and <strong>Atlassian Rovo</strong> to accelerate code, automation, triage, and documentation in day-to-day engineering.</li> <li>Build AI into security and remediation workflows — for example, using AI to summarize and enrich scanner findings, draft remediation guidance, generate and review Terraform and pipeline changes, and auto-populate Jira tickets from vulnerability data.</li> <li>Apply sound judgment about where AI fits and where human review is mandatory, treating all AI output in a security context as needing verification before it reaches production or a security decision.</li> <li>Help establish and share…

Skills asked for

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.