Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Gifthealth

DevSecOps Engineer

Gifthealth

. Integrate security controls into the software development lifecycle .

Posted 9/18/2026full-timeRemote • Ohio • United StatesMid-LevelSenior💰 $115,000 - $165,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in integrating security controls within the software development lifecycle, with a strong focus on secure coding practices, vulnerability remediation, and automated security testing in CI/CD pipelines. Proficient in application security, API security, and infrastructure security, ensuring compliance with organizational data handling requirements.

Highest-signal resume keywords
DevSecOps ExperienceCI/CD Pipeline ImplementationApplication Security ExpertiseScripting with Python, Go, or JavaScriptTerraform and Kubernetes Familiarity

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecurityAPI SecurityVulnerability RemediationAutomated Security TestingInfrastructure-as-CodeSAST ImplementationSecrets ManagementDependency Vulnerability DetectionThreat ModelingGitHub Advanced Security
Soft Skills
Effective CommunicationCollaboration with Engineering TeamsProblem-Solving
Tools & Technologies
CI/CD SystemsTerraformKubernetesCloud Security ServicesBrakemanBundler-AuditDependabot
Industry Keywords
Secure Development StandardsSecurity AutomationCloud-Native SecurityRegulated Environment ExperienceOWASP Top 10

Tech Stack

Tools & technologies
CloudHerokuJavaScriptKubernetesPythonRubyRuby on RailsTerraformGo

About the role

Key responsibilities & impact
  • Integrate security controls into the software development lifecycle
  • Establish practical secure development standards with engineering teams
  • Help developers identify and remediate application security vulnerabilities
  • Provide technical guidance on secure coding practices and common vulnerability classes
  • Support security reviews for applications, services, APIs, and major architectural changes
  • Design and implement automated security testing within CI/CD pipelines
  • Implement SAST, SCA, secret scanning, container image scanning, IaC scanning, and dependency vulnerability detection
  • Develop security gates for build and deployment pipelines
  • Correlate and de-duplicate vulnerability signals across Dependabot, Vanta, and Tenable
  • Evaluate applications and APIs for security weaknesses
  • Establish secure API authentication and authorization patterns
  • Support threat modeling and remediation of application security findings
  • Review Terraform, CloudFormation, Kubernetes manifests, and infrastructure definitions for security risks
  • Develop automated controls, secure infrastructure patterns, guardrails, and security automation
  • Support container image security, workload configuration, secrets management, and runtime security
  • Support the planned migration from Heroku to Render.com
  • Design synthetic or de-identified data seeding for DAST in staging without exposing PHI
  • Participate in architecture and design reviews
  • Work with Cloud Security, Security Operations, and engineering teams to improve security visibility and resolve findings
  • Track security findings, remediation times, vulnerability trends, security coverage, and secure-development adoption
  • Replace manual reviews with automated preventative controls

Requirements

What you’ll need
  • 3+ years of experience in DevOps, DevSecOps, application security, platform engineering, software engineering, or security engineering
  • Experience with modern CI/CD systems and software delivery practices
  • Experience with modern application hosting platforms
  • Working knowledge of application security, API security, GitHub Advanced Security/CodeQL, dependency and vulnerability alert triage, CI/CD pipelines, Infrastructure-as-Code, secrets management, and software supply chain security
  • Experience with scripting or programming using Python, Go, JavaScript, PowerShell, or Bash
  • Experience with Git-based development workflows and working directly with developers and engineering teams
  • Demonstrated application of the listed qualifications
  • Ability to work at a computer for extended periods
  • Ability to communicate effectively, verbally and in writing, with engineering and security stakeholders
  • Ability to handle and access sensitive security and system data in compliance with organizational data handling requirements
  • Ability to respond to critical security or deployment issues outside standard working hours when required
  • Education not specified as a requirement; demonstrated hands-on experience evaluated
  • Licensure/certification not required
  • Preferred: Terraform, Kubernetes, or container orchestration experience
  • Preferred: Rails security tooling such as Brakeman, bundler-audit, or Dependabot
  • Preferred: SAST, SCA, secrets scanning, or IaC security tool implementation
  • Preferred: OWASP Top 10, cloud-native security services, and threat modeling familiarity
  • Preferred: identity, authentication, authorization, secrets management, and regulated-environment experience
  • Ruby experience is a strong plus

Benefits

Comp & perks
  • Full-time employment
  • Standard business hours
  • Flexible schedule for security-critical deployment reviews or urgent remediation timelines
  • Equal employment opportunity and inclusive work environment