‹ Back
WWAYPOINT

DevSecOps Engineer

Support StaffFull timePosted Sep 30Job JR2026-105973
✓Requirements
Certifications
Security, cloud, or software security certifications such as Security+, CSSLP, GWEB, GCSA, AWS Security Specialty, Azure Security Engineer, CCSP, CISSP, or similar. preferred
Education
✓Bachelor’s degree in computer science, information technology, cybersecurity, software engineering, data engineering, or a related field, or equivalent experience.
Qualifications
✓Seven or more years of professional IT experience with five or more years in DevSecOps, application security, cloud security, software engineering, infrastructure engineering, security engineering, or a related technical role.
✓Working knowledge of secure software development lifecycle practices, application security principles, cloud security concepts, CI/CD security, and vulnerability management.
✓Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or similar tools.
✓Experience with cloud platforms such as Microsoft Azure, AWS, or similar environments.
✓Familiarity with application security and software supply chain security capabilities such as SAST, SCA, secrets scanning, dependency analysis, container scanning, and Infrastructure as Code scanning.
✓Experience with scripting, automation, source control, code review processes, and development workflows using tools and languages such as Git, Python, PowerShell, Bash, JavaScript, or similar.
✓Ability to assess technical environments, identify security gaps, evaluate risk, and recommend practical remediation activities.
✓Strong written and verbal communication skills, including the ability to explain technical security concepts to developers, engineers, security teams, and non-technical stakeholders.
✓Excellent analytical, problem-solving, troubleshooting, organizational, and prioritization skills.
✓Ability to connect security requirements to practical software development, cloud deployment, and engineering outcomes.
✓Ability to automate, standardize, and improve repeatable application security, cloud security, and DevSecOps processes.
✓Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
✓Ability to collaborate effectively with application development, data and analytics, infrastructure, cloud, architecture, cybersecurity, compliance, and business stakeholders.
✓Ability to produce professional-level documentation, reports, diagrams, runbooks, standards, and technical guidance.
✓Ability to think critically, make independent decisions, and recommend practical solutions.
✓Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
✓Ability to communicate application security risks, control gaps, remediation needs, and technical recommendations clearly to both technical and non-technical audiences.
✓Ability to support a positive cybersecurity culture by promoting secure development practices, accountability, and continuous improvement.
✓Non-Discrimination Policy
Experience with tools such as Snyk, Wiz, Sysdig, Tenable, GitHub Advanced Security, GitHub Dependabot, or similar security platforms. preferred
Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, CloudFormation, Bicep, Open Policy Agent, YAML, JSON, or similar. preferred
Experience securing containers, Kubernetes, container registries, cloud-native workloads, APIs, secrets, and microservices architectures. preferred
Experience building security automation, integrations, dashboards, reporting, and developer self-service capabilities. preferred
Experience working with data and analytics platforms, data pipelines, APIs, reporting platforms, or related engineering teams. preferred
Experience supporting audit readiness, compliance activities, control testing, or automated evidence collection in a regulated environment. preferred
Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, OWASP Top 10, MITRE ATT&CK, HIPAA, HITRUST, ISO 27001, SOC 2, or similar. preferred
Experience in healthcare or another highly regulated environment. preferred
Pay for this position
Employer-posted
$132k – $202k/yr
Apply to Hospital for
Questions about pay or the unit? Ask a Waypoint recruiter.
✓You’ll need
Certifications
Security, cloud, or software security certifications such as Security+, CSSLP, GWEB, GCSA, AWS Security Specialty, Azure Security Engineer, CCSP, CISSP, or similar. preferred
Education
✓Bachelor’s degree in computer science, information technology, cybersecurity, software engineering, data engineering, or a related field, or equivalent experience.
Qualifications
✓Seven or more years of professional IT experience with five or more years in DevSecOps, application security, cloud security, software engineering, infrastructure engineering, security engineering, or a related technical role.
✓Working knowledge of secure software development lifecycle practices, application security principles, cloud security concepts, CI/CD security, and vulnerability management.
✓Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or similar tools.
✓Experience with cloud platforms such as Microsoft Azure, AWS, or similar environments.
✓Familiarity with application security and software supply chain security capabilities such as SAST, SCA, secrets scanning, dependency analysis, container scanning, and Infrastructure as Code scanning.
✓Experience with scripting, automation, source control, code review processes, and development workflows using tools and languages such as Git, Python, PowerShell, Bash, JavaScript, or similar.
✓Ability to assess technical environments, identify security gaps, evaluate risk, and recommend practical remediation activities.
✓Strong written and verbal communication skills, including the ability to explain technical security concepts to developers, engineers, security teams, and non-technical stakeholders.
✓Excellent analytical, problem-solving, troubleshooting, organizational, and prioritization skills.
✓Ability to connect security requirements to practical software development, cloud deployment, and engineering outcomes.
✓Ability to automate, standardize, and improve repeatable application security, cloud security, and DevSecOps processes.
✓Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
✓Ability to collaborate effectively with application development, data and analytics, infrastructure, cloud, architecture, cybersecurity, compliance, and business stakeholders.
✓Ability to produce professional-level documentation, reports, diagrams, runbooks, standards, and technical guidance.
✓Ability to think critically, make independent decisions, and recommend practical solutions.
✓Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
✓Ability to communicate application security risks, control gaps, remediation needs, and technical recommendations clearly to both technical and non-technical audiences.
✓Ability to support a positive cybersecurity culture by promoting secure development practices, accountability, and continuous improvement.
✓Non-Discrimination Policy
Experience with tools such as Snyk, Wiz, Sysdig, Tenable, GitHub Advanced Security, GitHub Dependabot, or similar security platforms. preferred
Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, CloudFormation, Bicep, Open Policy Agent, YAML, JSON, or similar. preferred
Experience securing containers, Kubernetes, container registries, cloud-native workloads, APIs, secrets, and microservices architectures. preferred
Experience building security automation, integrations, dashboards, reporting, and developer self-service capabilities. preferred
Experience working with data and analytics platforms, data pipelines, APIs, reporting platforms, or related engineering teams. preferred
Experience supporting audit readiness, compliance activities, control testing, or automated evidence collection in a regulated environment. preferred
Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, OWASP Top 10, MITRE ATT&CK, HIPAA, HITRUST, ISO 27001, SOC 2, or similar. preferred
Experience in healthcare or another highly regulated environment. preferred

More support jobs near New York, NYMore support jobs nearby

All 976 in New York →All 976 →

Highest-paying support roles in New York

Employer-posted ranges only
All NY support jobs →
Want the next support job in New York by email?
Weekly, free, unsubscribe with one click.

About the role

Now more than ever, our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximize the abundant opportunities for growth and success.