Position: DevSecOps Engineer Tooling Implementation Integration
Type :- Remote
Position Overview
This is a hands-on build role at the center of a DevSecOps program. The engineer will deploy and operate DefectDojo Pro inside a FedRAMP-authorized AWS environment as the single source of truth for vulnerability findings.
The role involves integrating seven detection sources:
- Trivy
- Semgrep
- Qualys
- Tenable
- AWS Inspector
- CrowdStrike
- Dependabot
while retiring a legacy multi-hop pipeline (GHAS Splunk Email Jira).
The engineer will own all integration code, CI/CD wiring, and automation that moves findings from detection through evaluation to ticketing and reporting.
This position requires deep AWS expertise, strong Python development skills, Kubernetes operational fluency, and experience with security tooling in regulated environments.
Key Responsibilities
- Deploy and operate DefectDojo Pro within a FedRAMP-authorized AWS setting, including:
- IdP/SSO integration
- Security hardening
- Boundary-compliant configuration
- Build and maintain scanner integrations:
- API connectors
- Webhook pipelines
- CI jobs feeding findings from all detection sources into the aggregation platform
- Integrate container scanning into:
- GitHub CI pipelines
- Amazon ECR registry workflows (Trivy)
- Runtime container scanning for EKS/ECS workloads
- Build a runtime reconciliation loop matching scanned images to deployed workloads.
- Implement KEV/EPSS enrichment and internet-reachability tagging.
- Experience with DefectDojo (especially DefectDojo Pro) or similar ASPM/vulnerability management platforms.
- Experience with:
- Trivy
- Grype
- AWS Inspector
- CrowdStrike Falcon Cloud Security
- Semgrep
- Qualys APIs
- Tenable APIs
- Experience operating security tooling within a FedRAMP or other regulated environment.
- Understanding of:
- ATO scope
- Hardening baselines
- Change control
- Familiarity with SBOM formats (CycloneDX).
- Familiarity with VEX, KEV, and EPSS data sources.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.