MeridianLink Logo

MeridianLink

DevSecOps Engineer

Posted 10 Days Ago
Remote
Hiring Remotely in US
Mid level
Remote
Hiring Remotely in US
Mid level
The DevSecOps Engineer ensures information security and compliance by managing security programs, reviewing application security, and automating deployment processes.
The summary above was generated by AI

Position Summary:

The DevSecOps Engineer is a member of the organization's operational, compliance, and application security programs to safeguard internal company data and client data. The DevSecOps Engineer role will review and assess the security of applications and infrastructure to enhance MeridianLink's overall security. This role will work cross-functionally with development, engineering, and product teams to solve real problems in ways that meet our security requirements. This is a highly technical, hands-on role; the individual will be responsible for assessing and securing MeridianLink’s systems and applications at multiple layers of the technology stack. The DevSecOps Engineer will think like an adversary and identify how applications and systems must evolve as the threat landscape changes. Security and trust are the foundation of MeridianLink’s commitment to our customers. This individual will support and drive a security-by-design architecture.

Expected Duties:

  • The DevSecOps Engineer will assist with user issues while working with SR. DevSecOps Engineers or other security personnel as needed.

  • Participate in and support application security reviews and threat modeling, including code review and static/dynamic testing.

  • Responsible for understanding and interpreting both business and technical requirements for creating secure applications and infrastructure.

  • Responsible for the design and implementation of application security solutions that enforce security consistently across all applications and products

  • Conduct infrastructure assessments of cloud, network, and data services that support MeridianLink’s products.

  • Design, develop, test, document, deploy, monitor, and support existing and new AppSec and SecOps tooling.

  • Automate security testing and vulnerability management procedures where reasonable.

  • Promote a proactive approach to addressing the changing threat landscape by recommending and implementing architectural improvements to security infrastructure.

  • Collaborate with developers on secure code development best practices and strategies while implementing them into the SDLC.

  • Collaborate cross-functionally to architect, develop, implement, and support automated static/dynamic testing within MeridianLink’s CI/CD pipelines.

  • Act as the security team’s primary liaison to the development/software engineering teams and partner with them to remediate any identified risks, threats, or vulnerabilities.

  • Perform automated and manual vulnerability assessments as needed and/or on a regular cadence, leveraging a wide variety of industry-standard tools, to identify and validate vulnerabilities in MeridianLink’s applications, cloud infrastructure, and endpoints.

  • Assess new/proposed applications and provide guidance and subject matter expertise regarding any insecure architecture/design principles.

  • Support and provide guidance in regulatory and compliance efforts/requirements as necessary

  • Act as a subject matter expert for secure coding practices, penetration testing, and all aspects of application and product security

  • Participate in the internal CSIRT on-call rotation and incident response as needed.

Qualifications: Knowledge, Skills, and Abilities

The DevSecOps Engineer position will perform simple to moderately difficult, yet impactful aspects of the role independently, and the position will support peers and management on difficult to complex aspects of the role. The individual will develop professional expertise in the subject area and will apply MeridianLink’s policies and procedures to resolve a variety of issues.

  • Bachelor’s degree and 2-4 years of related experience or equivalent work experience

  • 1+ years of hands-on experience in implementing/maintaining CI/CD, security, and data pipelines

  • Hands-on experience in designing, securing, and delivering cloud applications and solutions within AWS, Azure, and GCP cloud platforms

  • Must have a solid understanding of DevSecOps pipelines and CI/CD integration, proven expertise in securing cloud infrastructure environments

  • Experience with threat modeling and deep understanding of application security vulnerabilities (SANS, OWASP Top 10)

  • Experience performing threat modeling and design reviews to assess security implications and requirements for new technologies

  • Someone who has worked in a DevSecOps environment preferred, with a thorough understanding of SDLC methodologies and experience securing APIs and web services

  • Experience with industry standard application and information security testing tools such as Kali Linux, Metasploit, Burp Suite, and WebInspect

  • Experience and understanding of infrastructure as code, automation, container security architecture, and orchestration tools

  • Experience in languages such as Python, C#, Java, PowerShell, and an understanding of modern web technologies and relationships between them

  • Experience performing static and dynamic code analysis (SAST/DSAT)

  • Expertise with strong knowledge of CI/CD pipelines covering source control, integration, and deployment

  • Experience securing cloud deployment and containers

  • Strong analytical/problem-solving skills and cross-functional knowledge across multiple development and security disciplines

  • Ability to communicate security-related concepts to a broad range of technical and non-technical staff

Top Skills

Artifactory
C++
Dns
Docker
Gitlab
Java
Linux
Nginx
Powershell
Python
Tls

Similar Jobs

Yesterday
Remote
USA
106K-118K Annually
Mid level
106K-118K Annually
Mid level
Information Technology • Consulting
The DevSecOps Engineer designs and maintains CI/CD pipelines, manages Docker and Kubernetes environments, integrates security controls and automated testing, and ensures compliance in cloud platforms.
Top Skills: AWSCi/CdDockerGitlabIacKubernetesObservability StacksRmfSecurity AutomationStigsZero Trust
8 Days Ago
Easy Apply
Remote
US
Easy Apply
Senior level
Senior level
Artificial Intelligence • Big Data • Cloud • Cybersecurity • Defense
As a Senior DevSecOps Engineer, you'll lead the lifecycle management of applications, ensure security, implement CI/CD pipelines, and collaborate with clients on innovative solutions.
Top Skills: AppgateAWSGitlabInfrastructure As CodeIstioPalo Alto Firewall
5 Days Ago
Remote
United States
105K-198K Annually
Senior level
105K-198K Annually
Senior level
Aerospace • Information Technology • Cybersecurity • Defense • Manufacturing
The Software Engineer - DevSecOps will develop and maintain processes for CI/CD environments, automate software development activities, and enhance system security while collaborating with cross-functional teams.
Top Skills: ArtifactoryAWSAzureBambooDockerGCPGradleJavaJenkinsKubernetesLdraLinuxMatlabMavenPythonSonarqubeWindows

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account