Position: DevSecOps Engineer - Tooling Implementation & Integration
Type :- Remote
Exp :- 6-8 Years
Position Overview
This is a hands-on build role at the center of a DevSecOps program. The engineer will deploy and operate DefectDojo Pro inside a FedRAMP-authorized AWS setting as the single source of truth for vulnerability findings.
The role involves integrating seven detection sources:
- Trivy
- Semgrep
- Qualys
- Tenable
- AWS Inspector
- CrowdStrike
- Dependabot
while retiring a legacy multi-hop pipeline (GHAS Splunk Email Jira).
The engineer will own all integration code, CI/CD wiring, and automation that moves findings from detection through evaluation to ticketing and reporting.
This position requires deep AWS expertise, strong Python development skills, Kubernetes operational fluency, and experience with security tooling in regulated environments.
Key Responsibilities
- Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS environment, including:
- IdP/SSO integration
- Security hardening
- Boundary-compliant configuration
- Build and maintain scanner integrations:
- API connectors
- Webhook pipelines
- CI jobs feeding findings from all detection sources into the aggregation platform
- Integrate container scanning into:
- GitHub CI pipelines
- Amazon ECR registry workflows (Trivy)
- Runtime container scanning for EKS/ECS workloads
- Build a runtime reconciliation loop matching scanned images to deployed workloads.
- Implement KEV/EPSS enrichment and internet-reachability tagging.