Salary: $130,000 - $140,000 annually + MyShare Equity Program
Job Purpose:
The Senior DevSecOps Engineer is an individual contributor responsible for designing, implementing, and operating security controls across the software development lifecycle (SDLC). This role partners closely with Engineering teams, IT Operations, and the Manager of Cyber Security to embed security directly into development workflows, CI/CD pipelines, and cloud platforms. The core function of this role is active, hands-on partnership with Engineering teams to build secure-by-default patterns, improve secure design and delivery practices, and implement security controls within existing development and operational workflows. While the role maintains awareness of governance and compliance requirements, the primary focus is practical engineering execution that results in scalable, auditable, and repeatable security outcomes.
Essential Duties and Responsibilities:
Secure SDLC Implementation & Governance Awareness
Architecture & Design Security
Perform application risk profiling and threat modeling for new and materially changed systems
Review application, API, and platform architectures from a security and risk perspective, providing guidance on required security controls and integration patterns
Design and implement security architecture components, guardrails, and shared controls supporting:
Azure PaaS resources and identity integrations (Entra ID, Azure B2C/External ID)
Web applications hosted on IIS and Node.js
APIs and externally exposed services
Data platforms including Microsoft SQL, Oracle SQL, CosmosDB, Databricks, and Microsoft Fabric
Partner with architects and engineers to ensure alignment with approved security patterns and baselines, without owning application code or business logic
CI/CD, Pipeline & Tooling Security
Verification, Testing & Defect Management
Operations, Incident Support & Continuous Improvement
Qualifications:
Bachelor's degree in Computer Science, Information Security, Information Systems or a related field
Minimum 5 years of experience in DevSecOps, application security, or secure platform engineering
Demonstrated experience implementing and operating security controls across CI/CD, cloud, and SDLC environments
Strong foundational knowledge across DevOps and platform engineering, including:
Core networking concepts (VPC/VNet, DNS, TCP/IP, TLS, load balancing, proxies, firewall/NSG)
Windows and Linux systems (processes, permissions, filesystems, networking, troubleshooting)
Git-based workflows (branching strategies, pull requests, releases)
Scripting and automation (PowerShell, Bash, and/or Python)
Strong hands-on experience implementing DevSecOps security controls, including:
Secure SDLC practices and OWASP guidance (from a control, tooling, and risk perspective)
Azure cloud security and identity services (Entra ID, Azure B2C/External ID)
CI/CD pipelines, Git-based workflows, and build/deploy automation
Containers and orchestration fundamentals (Docker, Kubernetes) and Infrastructure as Code (Terraform, Ansible)
Vulnerability management tooling (SAST, DAST, SCA, image scanning)
Preferred Qualifications - Security Certifications
Education and/or Experience Required:
Language Skills Sets:
Mathematical Skills:
Reasoning Ability:
Computer Skills:
Physical Demands:
Employer Rights:
This job description is intended to provide general information about the Senior DevSecOps Engineer position. The above does not constitute an exhaustive list of the job duties to be performed by an associate holding the position of Senior DevSecOps Engineer, nor are the lists of the physical requirements and environmental conditions exhaustive. You may be asked by your supervisor or managers to perform other duties. Your performance will be evaluated in part based upon your performance of the job duties listed in this job description, as well as any job duties not specifically listed above that you may be asked from time to time to perform. As with all positions, the duties and responsibilities are subject to change at any time as needs arise and at the discretion of the RJW Transport, Inc. The Company has the right to revise this job description at any time.
Employment-At-Will:
It is the Company's policy that all associates, other than those covered by a written individual employment or labor agreement with the Company that has been authorized in writing by the Company's Chief Executive Officer or Board of Directors, are not employed for any fixed term and are employed at the will of the Company for an indefinite period. Just as our associate's, reserve the right to resign their employment at any time for any reason the Company reserves its right to terminate an associate any time for any reason either with or without cause.
Neither this Job Description nor any of its individual terms constitutes commitments between the Company and its associates as to the terms, conditions or duration of employment, nor does it modify the prevailing Employment-At-Will relationship.
Benefits:
401(k) matching
Medical/Dental/Vision insurance
Employee discount
Flexible spending account
Health savings account
Paid time off
Sick Days
Long-term Disability Insurance
Short-term Disability Insurance
Accidental Insurance
Critical Illness Insurance
MyShare program