MeridianLink Logo

MeridianLink

DevSecOps Engineer

Reposted 17 Days Ago
Remote
Hiring Remotely in US
99K-135K Annually
Mid level
Remote
Hiring Remotely in US
99K-135K Annually
Mid level
The DevSecOps Engineer ensures information security and compliance by managing security programs, reviewing application security, and automating deployment processes.
The summary above was generated by AI

Position Summary:

The DevSecOps Engineer is a member of the organization's operational, compliance, and application security programs to safeguard internal company data and client data. The DevSecOps Engineer role will review and assess the security of applications and infrastructure to enhance MeridianLink's overall security. This role will work cross-functionally with development, engineering, and product teams to solve real problems in ways that meet our security requirements. This is a highly technical, hands-on role; the individual will be responsible for assessing and securing MeridianLink’s systems and applications at multiple layers of the technology stack. The DevSecOps Engineer will think like an adversary and identify how applications and systems must evolve as the threat landscape changes. Security and trust are the foundation of MeridianLink’s commitment to our customers. This individual will support and drive a security-by-design architecture.

Expected Duties:

  • The DevSecOps Engineer will assist with user issues while working with SR. DevSecOps Engineers or other security personnel as needed.

  • Participate in and support application security reviews and threat modeling, including code review and static/dynamic testing.

  • Responsible for understanding and interpreting both business and technical requirements for creating secure applications and infrastructure.

  • Responsible for the design and implementation of application security solutions that enforce security consistently across all applications and products

  • Conduct infrastructure assessments of cloud, network, and data services that support MeridianLink’s products.

  • Design, develop, test, document, deploy, monitor, and support existing and new AppSec and SecOps tooling.

  • Automate security testing and vulnerability management procedures where reasonable.

  • Promote a proactive approach to addressing the changing threat landscape by recommending and implementing architectural improvements to security infrastructure.

  • Collaborate with developers on secure code development best practices and strategies while implementing them into the SDLC.

  • Collaborate cross-functionally to architect, develop, implement, and support automated static/dynamic testing within MeridianLink’s CI/CD pipelines.

  • Act as the security team’s primary liaison to the development/software engineering teams and partner with them to remediate any identified risks, threats, or vulnerabilities.

  • Perform automated and manual vulnerability assessments as needed and/or on a regular cadence, leveraging a wide variety of industry-standard tools, to identify and validate vulnerabilities in MeridianLink’s applications, cloud infrastructure, and endpoints.

  • Assess new/proposed applications and provide guidance and subject matter expertise regarding any insecure architecture/design principles.

  • Support and provide guidance in regulatory and compliance efforts/requirements as necessary

  • Act as a subject matter expert for secure coding practices, penetration testing, and all aspects of application and product security

  • Participate in the internal CSIRT on-call rotation and incident response as needed.

Qualifications: Knowledge, Skills, and Abilities

The DevSecOps Engineer position will perform simple to moderately difficult, yet impactful aspects of the role independently, and the position will support peers and management on difficult to complex aspects of the role. The individual will develop professional expertise in the subject area and will apply MeridianLink’s policies and procedures to resolve a variety of issues.

  • Bachelor’s degree and 2-4 years of related experience or equivalent work experience

  • 1+ years of hands-on experience in implementing/maintaining CI/CD, security, and data pipelines

  • Hands-on experience in designing, securing, and delivering cloud applications and solutions within AWS, Azure, and GCP cloud platforms

  • Must have a solid understanding of DevSecOps pipelines and CI/CD integration, proven expertise in securing cloud infrastructure environments

  • Experience with threat modeling and deep understanding of application security vulnerabilities (SANS, OWASP Top 10)

  • Experience performing threat modeling and design reviews to assess security implications and requirements for new technologies

  • Someone who has worked in a DevSecOps environment preferred, with a thorough understanding of SDLC methodologies and experience securing APIs and web services

  • Experience with industry standard application and information security testing tools such as Kali Linux, Metasploit, Burp Suite, and WebInspect

  • Experience and understanding of infrastructure as code, automation, container security architecture, and orchestration tools

  • Experience in languages such as Python, C#, Java, PowerShell, and an understanding of modern web technologies and relationships between them

  • Experience performing static and dynamic code analysis (SAST/DSAT)

  • Expertise with strong knowledge of CI/CD pipelines covering source control, integration, and deployment

  • Experience securing cloud deployment and containers

  • Strong analytical/problem-solving skills and cross-functional knowledge across multiple development and security disciplines

  • Ability to communicate security-related concepts to a broad range of technical and non-technical staff

Top Skills

Artifactory
C++
Dns
Docker
Gitlab
Java
Linux
Nginx
Powershell
Python
Tls

Similar Jobs

8 Days Ago
Remote
United States
Expert/Leader
Expert/Leader
Edtech • Fintech • Payments • Social Impact • Financial Services • Big Data Analytics
The Senior DevSecOps Engineer will architect security posture, drive compliance, enhance system hardening, and ensure robust security across platforms in collaboration with DevOps and Engineering teams.
Top Skills: AlienvaultAWSAws Security HubCi/CdDatadog SecurityNode.jsSoc2 Type 2Splunk
4 Days Ago
Remote
USA
Senior level
Senior level
Insurance
Design and implement CI/CD pipelines and security practices in cloud environments. Collaborate with teams to enhance DevSecOps tooling. Troubleshoot production issues and document processes.
Top Skills: AnsibleAzureC#Ci/CdDockerGithub ActionsJavaJfrogKubernetesPythonSonarcloudTerraform
5 Days Ago
In-Office or Remote
18 Locations
118K-148K Annually
Senior level
118K-148K Annually
Senior level
Hospitality
The DevSecOps Engineer will manage cloud infrastructure, enhance developer experience, ensure security, and collaborate across teams to improve system reliability.
Top Skills: Ci/CdCloudwatchDatadogGoGrafanaJavaJavaScriptKotlinKubernetesPrometheusPythonReactReact NativeRuby On RailsSplunkSQLSumologicSwiftTerraformTypescript

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account