DevSecOps/Vulnerability Management Lead

7 Minutes ago • 5 Years + • $150,000 PA - $170,000 PA
Cyber Security

Job Description

A financial firm is seeking a DevSecOps/Vulnerability Management Lead in Iselin, NJ. This role involves establishing and managing a comprehensive vulnerability management program, leading the design of secure CI/CD pipelines, and defining DevSecOps strategy. The lead will embed security controls, automate security testing, evaluate tools, and drive secure configuration management. Responsibilities also include supporting audits and mentoring on secure coding and cloud security best practices.
Must Have:
  • Currently working in vulnerability management
  • Strong DevSecOps experience
  • Python proficiency
  • Finance industry experience
  • SAST/DAST/SCA knowledge
  • Strong documentation skills
  • 5 years of hands-on experience in DevOps, Security Engineering, or DevSecOps
  • Experience designing and managing vulnerability management workflows
  • Familiarity with vulnerability scanning tools (Snyk, Tenable, Qualys, Trivy, Clair)
  • Proficient in implementing CI/CD pipelines (GitLab CI, GitHub Actions, Jenkins, CircleCI)
  • Deep understanding of cloud platforms (AWS, Azure, GCP) and cloud-native security controls
  • Expertise in scripting (Python, Bash) and infrastructure-as-code (Terraform, Ansible)
  • In-depth knowledge of application and infrastructure security, secure SDLC, and DevSecOps tooling
  • Strong knowledge of compliance and security frameworks (OWASP, NIST, CIS Benchmarks, ISO 27001)

Add these skills to join the top 1% applicants for this job

cross-functional
communication
risk-management
github
game-texts
software-development-lifecycle-sdlc
security-testing
gitlab
aws
azure
ansible
terraform
circleci
cloud-security
ci-cd
python
github-actions
bash
jenkins

Responsibilities:

  • Establish and manage a comprehensive vulnerability management program, including:
  • Integration of scanning tools across source code, dependencies, containers, and infrastructure.
  • Continuous discovery, prioritization, and tracking of vulnerabilities.
  • Coordinating with development and infrastructure teams for timely remediation.
  • Root cause analysis and reporting on trends and recurring issues.
  • Lead the design and implementation of secure, automated CI/CD pipelines.
  • Define and drive DevSecOps strategy in alignment with business goals and compliance standards.
  • Embed security controls and tooling (SAST, DAST, SCA, IaC scanning, etc.) into the software development lifecycle.
  • Collaborate closely with engineering, platform, and security teams to ensure scalable security architecture.
  • Automate security testing and compliance checks within CI/CD workflows.
  • Evaluate and implement security tools and platforms that support proactive risk management.
  • Drive secure configuration management and enforcement through IaC and policy-as-code.
  • Maintain awareness of emerging threats, vulnerabilities, and regulatory changes.
  • Support internal and external audits, ensuring alignment with compliance frameworks (e.g., ISO 27001, SOC 2, GDPR).
  • Provide technical mentoring and guidance on secure coding, cloud security, and DevSecOps best practices.

Qualifications:

  • 5 years of hands-on experience in DevOps, Security Engineering, or DevSecOps.
  • Strong experience designing and managing vulnerability management workflows, ideally across multi-cloud and containerized environments.
  • Familiarity with vulnerability scanning tools and platforms (e.g., Snyk, Tenable, Qualys, Trivy, Clair, etc.).
  • Proficient in implementing CI/CD pipelines with tools such as GitLab CI, GitHub Actions, Jenkins, CircleCI.
  • Deep understanding of cloud platforms (AWS, Azure, or GCP) and cloud-native security controls.
  • Expertise in scripting (e.g., Python, Bash) and infrastructure-as-code (Terraform, Ansible).
  • In-depth knowledge of application and infrastructure security, secure SDLC, and DevSecOps tooling.
  • Strong knowledge of compliance and security frameworks: OWASP, NIST, CIS Benchmarks, ISO 27001.
  • Excellent communication skills and ability to work across technical and non-technical stakeholders.
  • Proven ability to lead cross-functional security initiatives and mentor engineers.

Set alerts for more jobs like DevSecOps/Vulnerability Management Lead
Set alerts for new jobs by Open Systems Technologies
Set alerts for new Cyber Security jobs in United States
Set alerts for new jobs in United States
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙