DevSecOps Engineer
$115k - $165kGifthealth
About At Gifthealth, we're revolutionizing the way people experience healthcare by simplifying the process of managing prescriptions and health services. Our mission is to provide a seamless, personalized, and efficient healthcare experience for all our customers. We're a dynamic, innovative, and customer-centric company dedicated to making a positive impact on people's lives. Position Summary We are seeking a DevSecOps Engineer to integrate security into the organization's software development and delivery processes. This position plays a key role in supporting the Information Security department and reports to the Director of Security, ensuring alignment with organizational goals, operational excellence, and compliance standards. This role partners closely with Software Engineering, Platform Engineering, DevOps, and Security teams to build security controls directly into CI/CD pipelines, development workflows, infrastructure-as-code, container environments, and application delivery processes. Rather than operating as a final security checkpoint, the DevSecOps Engineer helps engineering teams identify and address security issues earlier in the development lifecycle while building scalable security automation that allows teams to move quickly without sacrificing security. Key Responsibilities Secure Software Development:
Employment Classification Status: Full-time
FLSA: Exempt
Equal Employment Opportunity (EEO) Statement Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.
We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply! Disclaimer This job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time. Salary Description
$115,000-$165,000
- Integrate security controls into the software development lifecycle.
- Partner with engineering teams to establish practical secure development standards.
- Help developers identify and remediate application security vulnerabilities.
- Provide technical guidance on secure coding practices and common vulnerability classes.
- Support security reviews for new applications, services, APIs, and major architectural changes.
- Design and implement automated security testing within CI/CD pipelines.
- Implement and manage capabilities such as:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Secret scanning
- Container image scanning
- Infrastructure-as-Code scanning
- Dependency and package vulnerability detection
- Develop appropriate security gates for build and deployment pipelines.
- Reduce alert fatigue by correlating and de-duplicating vulnerability signals across Dependabot, Vanta, and Tenable, escalating only when standard remediation timelines are at risk of being missed.
- Work with engineering teams to ensure security controls minimize unnecessary friction.
- Evaluate applications and APIs for common security weaknesses.
- Help establish secure API authentication and authorization patterns.
- Support threat modeling for applications and new engineering initiatives.
- Assist engineering teams with remediation of application security findings.
- Identify systemic security issues that can be addressed through reusable controls or engineering patterns.
- Review Terraform, CloudFormation, Kubernetes manifests, and similar infrastructure definitions for security risks.
- Develop automated controls that detect insecure infrastructure configurations before deployment.
- Create reusable secure infrastructure patterns and guardrails.
- Build security automation using scripting, APIs, and cloud-native services.
- Help establish security standards for containers and Kubernetes environments.
- Support container image security, workload configuration, secrets management, and runtime security.
- Identify insecure deployment patterns and help engineering teams adopt safer alternatives.
- Support the security review of the planned migration from Heroku to Render.com, including secrets handling, network posture, and changes to the deployment model.
- Design a synthetic or de-identified data seeding strategy to enable Dynamic Application Security Testing (DAST) in staging without exposing PHI, currently a gap given the application's PHI-heavy data model.
- Participate in architecture and design reviews.
- Translate security requirements into technical controls engineering teams can implement.
- Work with Cloud Security and Security Operations to improve visibility into applications and workloads.
- Help engineering teams understand and address security findings without becoming a bottleneck to delivery.
- Metrics and Continuous Improvement:
- Track application and pipeline security findings through remediation.
- Measure vulnerability trends, remediation times, security coverage, and adoption of secure development practices.
- Identify opportunities to replace manual reviews with automated preventative controls.
- Experience with modern CI/CD systems and software delivery practices. Gifthealth's core application is a GitHub-hosted Rails repo using trunk-based development, with GitHub Advanced Security/CodeQL and Dependabot integrated into CI.
- Experience with modern application hosting platforms. Gifthealth's core application runs on Heroku (migrating to Render.com), with Crunchy Data for managed Postgres and a Redis instance hosted in AWS. Direct AWS/Kubernetes experience is a plus but not the primary environment today.
- Working knowledge of application security, API security, GitHub Advanced Security/CodeQL, dependency and vulnerability alert triage (e.g., Dependabot), CI/CD pipelines, Infrastructure-as-Code, secrets management, and software supply chain security.
- Experience with scripting or programming using languages such as Python, Go, JavaScript, PowerShell, or Bash. Ruby experience is a strong plus, since GifthealthOS, the core application, is built on Ruby on Rails.
- Experience with Git-based development workflows and the ability to work directly with developers and engineering teams.
- Demonstrated application of the above Qualification
- Preferred: experience with Terraform, Kubernetes, or container orchestration. Gifthealth's core application runs on Heroku today (migrating to Render.com), not Kubernetes.
- Preferred: experience with Rails-specific security tooling such as Brakeman for SAST and bundler-audit or Dependabot for dependency scanning, given GifthealthOS's Ruby on Rails stack.
- Preferred: experience implementing SAST, SCA, secrets scanning, or IaC security tools. Gifthealth uses GitHub Advanced Security/CodeQL for SAST and Dependabot for dependency scanning.
- Preferred: familiarity with the OWASP Top 10 and common application vulnerability classes, cloud-native security services, and threat modeling methodologies.
- Preferred: understanding of identity, authentication, authorization, and secrets management, and experience working within regulated environments.
- Security testing becomes consistently integrated into engineering pipelines.
- Security vulnerabilities are identified earlier in the development lifecycle.
- Engineering teams have clear, usable guidance for resolving security findings.
- Reusable security controls reduce reliance on manual security reviews.
- Critical security issues can prevent unsafe deployments without creating excessive development friction.
- Application and software supply chain risks are measurable and actively managed.
- Secure development practices become part of normal engineering workflows.
- Must be able to work at a computer for extended periods
- Must be able to communicate effectively, verbally and in writing, with engineering and security stakeholders
- Must be able to handle and access sensitive security and system data in compliance with organizational data handling requirements
- Must be able to respond to critical security or deployment issues outside standard working hours when required
Employment Classification Status: Full-time
FLSA: Exempt
Equal Employment Opportunity (EEO) Statement Gifthealth is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. All employment decisions are made without regard to race, color, religion, sex, sexual orientation, gender identity, transgender status, national origin, age, disability, veteran status, or any other legally protected status.
We celebrate diversity and are committed to creating an inclusive environment for all employees. If you do not meet every requirement but still feel you would be a great fit for this role, we encourage you to apply! Disclaimer This job description is intended to describe the general nature and level of work being performed. It is not intended to be an exhaustive list of all responsibilities, duties, or skills required of personnel. Gifthealth reserves the right to modify job duties or descriptions at any time. Salary Description
$115,000-$165,000
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the DevSecOps Engineer in Columbus, OH vacancy
- ...Devsecops Engineer Kimball Midwest, a national distributor of maintenance, repair, and operation products, is searching for a DevSecOps Engineer for our Columbus, Ohio location. As a Kimball Midwest associate, you'll be part of a company built on long-term growth...SuggestedFull timeContract workWork experience placementWork at officeLocal areaFlexible hours
$116.2k - $229.1k
Position Summary AI & Engineering/EaaS - DevOps Engineer IIIBuild and scale modern DevOps capabilities that help clients accelerate... ...in the future.Preferred:4+ years of experience supporting DevSecOps practices, including security scanning and policy enforcement...SuggestedLocal area$96.8k - $145.2k
Senior Software Engineer - IE08CE We’re determined to make a difference and are proud to be an insurance company that goes well beyond... ...environments. Partner with security teams to implement DevSecOps practices including vulnerability management, secrets management...SuggestedTemporary workWork at office3 days per week- ...or a related field (or equivalent experience). - Minimum of 5 years of experience1 in CI/CD administration or DevOps engineering. - Proven experience with GitHub, Jenkins, Azure DevOps, and XebiaLabs. - Strong knowledge of Atlassian tools (Jira, Confluence...SuggestedContract work
$105.4k - $207.8k
Position Summary Our Deloitte AI & Engineering team works to transform technology platforms, drive innovation, and help make a significant... ...or content management system frameworksExperience applying DevSecOps practicesExperience with scripting and automation for cloud...SuggestedLocal area$61k - $101k
...Salary: $61,000 - 101,000 per year Requirements: We require formal training or certification in software engineering concepts, along with 3+ years of applied experience. We need hands-on experience with AWS and container platforms such as EKS and/or ECS. We expect...Full time- ...trusted to deliver transparency, cost savings, and peace of mind. What We’re Looking For VPL is looking for a hands-on DevOps Engineer to help operate and improve our Azure cloud environments and container-based application platform. This is a growth role for...
- ...platforms, applying strong experience in Ansible, continuous integration and continuous delivery practices, DevOps and Site Reliability Engineering to design, automate, and optimize geospatial data services.Partner with cross functional teams to ensure reliable map based...
$51 - $61 per hour
...onsite at the project, significantly reducing and/or eliminating the demands to travel. Key Responsibilities: As a Release Train Engineer, you will be responsible for facilitating Agile Release Train events and processes including communicating with stakeholders escalating...Hourly payLive inWork at officeLocal areaImmediate startFlexible hoursShift work- Company DescriptionEROS Technologies was founded with a simple motive of offering the clients exactly what they want, how they want and when they want it. By leveraging for its clients its technological edge and right-sourcing advantage, EROS in a short period of time has...
$116.8k - $160k
...Design (BOD) and Programmatic Design Change Management (PDCM) programs. This role requires deep technical expertise across multiple engineering disciplines and the ability to evaluate complex design changes across 300+ in-flight projects. As a Design Change Manager, you...Flexible hours- ImagineX Consulting in Columbus, OH is seeking a Senior Engineering Leader to drive CI/CD, observability, and high‑performing software delivery across complex enterprise solutions. You will lead DevOps and SRE teams, scale delivery, and bridge technical execution with executive...Permanent employment
- ...an opportunity to impact your career and provide an adventure where you can push the limits of what's possible. As a Lead Software Engineer at JPMorganChase within the Consumer & Community Banking Platform Engineering team, you are an integral part of an agile team that...
- ...ready to gain the skills and experience needed to grow within your role and advance your career - and we have the perfect software engineering opportunity for you. As a Lead Software Engineer at JPMorgan Chase, within the Employee Platforms, Workforce Experience Tech...
- Accenture is seeking a Release Train Engineer to facilitate Agile Release Train events and coordinate cross-team work. You will work with Product and Solution Management, stakeholders, and multiple teams to ensure strategy aligns with execution and to drive continuous...
$61k - $101k
...Salary: $61,000 - 101,000 per year Requirements: We expect formal software engineering training or certification, plus 5+ years of practical experience. We look for hands-on experience in system design, application development, testing, and operational reliability...Full time- Ohio Department of Developmental Disabilities in Columbus seeks an Information Technology Supervisor 3 to lead a multidisciplinary IT operations team. You will oversee DevOps, Tier 1 support, ServiceNow administration, and cybersecurity activities to ensure reliable production...Full time
- State of Ohio in Columbus seeks an Information Technology Supervisor 3 to lead a multidisciplinary IT operations team responsible for DevOps deployments, tier‑one support, and cybersecurity operations. Responsibilities include overseeing day‑to‑day IT activities, ServiceNow...
- ...Join a fast-paced cloud infrastructure team responsible for AWS cloud infrastructure and minimal on-premises systems. As DevOps Engineer II, you will independently own complex platform work and drive measurable reliability and delivery improvements. You will influence...Flexible hours
$61k - $101k
...Salary: $61,000 - 101,000 per year Requirements: We require formal training or certification in security engineering concepts, along with 5+ years of hands-on experience. We need practical experience with AWS services, including compute, networking, storage, identity...Full time- Lead Security Engineer Take on a pivotal role where your expertise in cloud security and platform engineering will directly protect one of the world's largest financial institutions. As a Lead Security Engineer on the Digital Forensics Platform Engineering team, you will...Worldwide
- Location: Bergkirchen near Munich or Munich Type: Full-time, permanent Working model: Hybrid What awaits you - Your responsibilities: Administer and maintain AzureDevOps, including access rights, repositories, build pipelines, test infrastructure, and test automation ...Permanent employmentFull timeContract workWork at officeWork from homeFlexible hours
- ...visits with the client 5 days a week. Core Focus Areas: CI/CD Pipelines & Code Quality: Spearhead pipeline automation, release engineering, and deployment strategies while ensuring engineering teams adhere to proper coding standards, maintain clean architecture, and implement...Permanent employmentFull time
$100k - $150k
...to join an established and well-respected organization offering tremendous career growth potential. Job Title DevOps & SRE Engineer Location 100% Remote (U.S.) Position Type Full-time, Direct W2 Salary Range $100,000–$150,000 Annually Experience...Full timeH1bLocal areaRemote work- Position Summary: Title: Developer Standard III Location: Washington, DC Duration: 6+ Months Long Term Hybrid Onsite: 4 days per week from Day 1, with a full transition to 100% onsite anticipated soon. Job Details: Overall professional experience of 15+ years...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to DevSecOps Engineer. Be the first to apply!
Related searches


