SlipstreamJobsFresh Startup & VC-Backed Jobs

DevSecOps Engineer

Divergent 3D - Torrance, CA, United States - In-office - posted 2026-09-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 115,843 - 180,977 / annual

Divergent 3D is seeking a DevSecOps Engineer to embed security into every stage of the software delivery lifecycle. The company builds and operates a digital manufacturing platform tightly coupling software, hardware, and physical production, serving as a Tier 1 supplier to global automotive OEMs and supporting leading U.S. aerospace and defense companies. In this role, you will own the automation that makes secure delivery the default rather than the exception. You will design, build, and maintain CI/CD pipelines with automated security gates including static analysis, software composition analysis, secrets detection, container image scanning, and infrastructure-as-code policy checks that fail fast and produce actionable findings. Key responsibilities include: - Provisioning and managing cloud infrastructure as code across Azure and AWS environments, enforcing configuration standards through policy-as-code rather than manual review - Hardening container and Kubernetes workloads, including base image lifecycle, admission control, runtime policy, network segmentation, and least-privilege workload identity - Owning secrets management and pipeline authentication through vaulted credentials, short-lived tokens, and federated identity, driving elimination of long-lived static keys - Triaging and prioritizing vulnerability findings across source code, third-party dependencies, container images, and cloud posture; partnering with engineering owners to drive remediation - Building and maintaining software supply chain controls, including dependency and lockfile hygiene, artifact signing and provenance, and software bill of materials generation - Instrumenting delivery and runtime environments for security observability by defining detections, dashboards, and alerting; participating in response for pipeline and infrastructure incidents - Automating cloud security posture assessment and remediation across accounts and subscriptions, covering identity, network, logging, and encryption baselines - Supporting control mapping and audit evidence collection for applicable frameworks, favoring automated evidence generation over manual attestation - Raising the security baseline of other engineers through reusable pipeline templates, documented golden paths, code review, and hands-on mentoring This is an individual contributor role with significant technical scope and mentoring responsibilities. You will partner with software, platform, and IT teams to reduce risk without slowing delivery, treating security controls as engineering problems to be solved with tooling. REQUIREMENTS: - Must be a U.S. Person as defined by ITAR (22 CFR §120.62) — U.S. citizen, lawful permanent resident, or other protected individual - 5–10 years of professional experience in DevOps, platform, site reliability, security, or software engineering, with at least 3 years of direct responsibility for securing CI/CD pipelines or cloud infrastructure - Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or related technical field, or equivalent demonstrated experience - Production experience with at least one major cloud provider (Azure or AWS), including identity and access management, networking, and logging services - Hands-on experience building and maintaining pipelines in modern CI/CD systems (GitHub Actions, GitLab CI, Azure Pipelines, or Jenkins) - Proficiency with infrastructure as code (Terraform, Bicep, CloudFormation, or Pulumi), with changes managed through version control and peer review - Working knowledge of containers and orchestration (Docker and Kubernetes), including image hardening and cluster access control - Automation and scripting ability in Python, Go, Bash, or PowerShell sufficient to build internal tooling and integrate vendor APIs - Practical experience integrating and operating application security tooling (Blackduck or Rapid7) — SAST, software composition analysis, secrets scanning, and image scanning — and triaging output - Solid grasp of core security concepts including least privilege, network segmentation, key management, authentication and authorization protocols (OAuth 2.0, OIDC, SAML), and common vulnerability classes (OWASP Top 10) - Experience with Git-based team workflows, code review, and branch protection - Clear written and verbal communication, with ability to explain security risk and engineering tradeoffs to technical and non-technical audiences PREFERRED: - Experience in export-controlled or regulated environments (ITAR/EAR, CMMC, NIST SP 800-171), or in aerospace, automotive, or advanced manufacturing - Contributions to internal developer platforms, golden-path templates, or open-source security tooling

Similar roles