Request ID: 108989-1
Title: Senior DevSecOps Engineer
Locations: Onsite: Bellevue, WA - Onsite
Duration: 6 Months
Pay rate: $40-$53/hr on W2/C2C
Skills: Python & Java Solutions, DevSecOps, OSS Security Engineering, Open-Source Software Security; Client - Vulnerability Management; Secure coding Practices; DevOps Continuous Integration and Continuous Delivery (CI/CD); Security automation; Security Tooling Integration, Terraform; CodeQL; GitHub Advanced Security; Cloud Security; Security Engineering
Experience Required: 8-10
Role Descriptions:- We are seeking a highly skilled and security-focused Senior DevSecOps Engineer to join the Akrites OSS Security Engineering team. This role is responsible for securing the open-source software ecosystem by analyzing| validating| and remediating vulnerabilities identified across critical OSS components and services.
- The engineer will work at the intersection of software engineering| security engineering| and cloud operations to strengthen software supply chain security and improve the security posture of open-source technologies.
- The ideal candidate possesses strong expertise in Java| Python| DevSecOps practices| vulnerability management| automation engineering| and cloud-native platforms| with a passion for driving secure development and operational excellence.
- This position will collaborate closely with Client security engineering teams| open-source maintainers| and cross-functional product engineering groups to deliver scalable security solutions and sustainable remediation strategies.
Key Responsibilities- OSS Vulnerability Analysis and Remediation
- Analyze| triage| validate| and prioritize Open Source Software (OSS) vulnerabilities identified through security scanning platforms| Software Composition Analysis (SCA) tools| and vulnerability intelligence feeds.
- Perform technical investigations to determine exploitability| business impact| attack vectors| and remediation requirements.
- Develop and implement vulnerability fixes across OSS components using Java and Python| ensuring secure coding practices and compliance with security standards.
- Conduct root cause analysis for recurring vulnerabilities and recommend long-term mitigation strategies.
- Validate remediation effectiveness through code reviews| testing| proof-of-concept verification| and security assessment techniques.
- Secure Software Supply Chain Engineering
- Strengthen software supply chain security through dependency management| secure package validation| and vulnerability governance practices.
- Partner with engineering teams to evaluate and remediate risks associated with third-party libraries| frameworks| and open-source dependencies.
- Support coordinated vulnerability disclosure and remediation workflows while maintaining confidentiality and security compliance.
- Contribute to vulnerability response activities from intake and validation through patch development| testing| and coordinated release processes.
- DevSecOps Platform Engineering Design| implement| and optimize DevSecOps workflows within the Akrites platform deployed on Google Cloud Platform (GCP).Integrate security controls into CI/CD pipelines| enabling automated vulnerability detection| policy enforcement| and remediation tracking.
- Enhance platform reliability| observability| and security through automation| infrastructure monitoring| logging| and operational analytics.
- Collaborate with development teams to embed security practices throughout the Software Development Lifecycle (SDLC).
- Essential Skills: Digital: Terraform; CodeQL; GitHub Advanced Security; Digital: Cloud Security; Security Engineering
Company Benefits & Culture
" Inclusive and diverse work environment
" Opportunities for professional growth and development
" Comprehensive health and wellness benefits