CronJobs

devops-sre jobs

Senior DevSecOps Engineer

Justworks · New York, New York

unknownsenior$188,000–$242,000Posted Oct 5, 2026AWSKubernetesTerraformGitHub ActionsGoPythonRubyCI/CD

Apply on the employer site

About this role

**Senior DevSecOps Engineer** **Who We Are** At Justworks, you’ll find a welcoming, casual environment with great benefits, wellness program offerings, company retreats, and the chance to learn from leaders in the startup community. We work hard and care deeply about our people. We help businesses get off the ground by enabling them to focus on running their business—solving HR issues with a data-driven mindset and continuous iteration. **Department** Engineering > Platform --- ## Who You Are You believe the secure path should be the easy path. You’ve seen that scanners nobody reads and gates nobody can pass don’t make software safer—they just cause engineers to route around them. So you build guardrails instead: pipelines that catch vulnerabilities before humans have to, “golden paths” with security baked in, and automation that turns “did we patch that?” into dashboards. You’re comfortable with CI/CD, AWS, and Kubernetes. You can distinguish real injection risk from scanner noise, and you’d rather fix the template that generated the bug than file dozens of tickets. This is a foundational role: you’ll be one of the first dedicated DevSecOps engineers supporting a Platform organization of 300+ engineers. You’ll work alongside Developer Experience and SRE, and partner closely with Security to shape how secure software is built—not just reviewed after the fact, including using AI to find and fix vulnerabilities before they reach production. Security discovers, prioritizes, and reports risk posture; Engineering remediates. This role sits at that seam—partnering with Digital Security on coverage and driving fixes through Engineering. Reports to Platform Engineering with a dotted line to Digital Security leadership. --- ## What You Will Work On - Own security automation across CI/CD pipelines (GitHub Actions): SAST, SCA, secrets detection, and fast container scanning that flags what’s worth fixing. - Build security into golden path templates for Go, Rails, and Vue.js services so new services start secure by default. - Harden the software supply chain: dependency management, artifact signing, SBOM generation, and provenance. - Implement and tune IaC scanning (Terraform) and Kubernetes policy enforcement to catch misconfigurations early. - Coordinate vulnerability exposure remediation across Engineering (code, infrastructure configuration, and patching). - Build vulnerability management automation that routes findings to owning teams with context, deduplicates noise, and tracks remediation without spreadsheets. - Own secrets management patterns and tooling; drive elimination of long-lived credentials in favor of short-lived, federated identity. - Partner with Security on cloud security posture across AWS environments and ensure Platform telemetry supports Detection & Response. - Support Security’s rollout of agentic penetration testing and build auto-remediation that turns findings into fixes before exploitation. - Explore and roll out AI-assisted security review of code changes with guardrails to keep signal high and false positives low. - Drive adoption through documentation and developer education. - Measure what matters: time-to-remediate, scan coverage, secrets findings, and mean time to patch. - Advocate for secure development practices and define how secure software is engineered. --- ## How You Will Do Your Work As a Senior DevSecOps Engineer, how results are achieved is key. You’ll demonstrate: - **Good judgement** (criti

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord