Senior DevSecOps Engineer
PSDC (Public Safety Delivery Center) requires the services of a Senior DevSecOps Engineer to act as consultant with the PSDC Solutions Management group.
Role summary
Hands-on security automation for AWS delivery. Build secure-by-default CDK constructs and CloudFormation templates, wire them into CI/CD, and enforce compliance checks that map to CJIS and NIST. Azure support is a future consideration, not a core day-one duty.
Scope boundaries
- Does not own enterprise AWS Organizations or SCP operations.
- Designs and builds reference guardrails and enforcement patterns that can be deployed by enterprise teams.
- Focuses on preventive controls and compliance automation , not incident response.
What you will deliver
First 90 days
- Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates.
- Compliance as code in reference accounts: AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with exceptions workflow documented.
- IaC reference modules using AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; Terraform equivalents provided where teams require them.
- Evidence exports tying checks to control IDs and producing auditor-ready artifacts.
Ongoing
- Harden CDK/CFT modules and pipeline templates as compliance needs evolve.
- Coach pilot teams to adopt templates.
- Raise gaps to enterprise teams for org-level enforcement.
Day-to-day responsibilities
- Author and maintain AWS CDK constructs and CloudFormation templates ; provide Terraform versions as secondary.
- Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
- Wire scanning in CI/CD for app code, containers, and IaC.
- Create reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
- Generate posture and evidence reports mapped to CJIS and NIST controls.
Required skills
- 5+ years AWS security automation and DevOps.
- Strong with AWS CDK and CloudFormation ; working proficiency in Terraform .
- CI/CD authoring in GitHub Actions and Azure DevOps .
- Proficient in Python and Bash , with PowerShell for Windows automation.
- Able to read Java and C# to integrate and tune SAST/SCA.
- Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence.
Nice to have
- EKS/ECS/Lambda hardening patterns.
- OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent.
- Basic Azure security automation for future phases.
Decision rights
Independent on design and build within standards; proposes guardrails and reference patterns; escalates enterprise-wide changes.
Requirements
Skill
Required / Desired
5+ years AWS security automation and DevOps
Required
Strong with AWS CDK and CloudFormation; working proficiency in Terraform
Required
CI/CD authoring in GitHub Actions and Azure DevOps
Required
Proficient in Python and Bash, with PowerShell for Windows automation
Required
Able to read Java and C# to integrate and tune SAST/SCA
Required
Practical knowledge of CJIS and NIST 800-53 control families and how to automate checks and evidence
Required
EKS/ECS/Lambda hardening patterns
Nice to have
OPA/Conftest, Checkov, Trivy, Inspector, CodeQL or equivalent
Nice to have
Basic Azure security automation for future phases
Nice to have
Recommended Jobs
Coordinator, D2C & Tour Campaign Management - Philadelphia, 19109
Coordinator, D2C & Tour Campaign Management - Philadelphia, 19109, United States of America Famehouse, a division of UMG, is the preeminent leader in D2C solutions in music, defining & delivering th…
Field Service Technician - Pittsburgh
Job Description Job Description About Culligan Quench Culligan Quench’s purpose is to impact people’s lives and improve the earth by helping to eliminate the 500 million plastic bottles consum…
Electrical Engineer: Energy and Power (Philadelphia, PA or Northeast USA)35436
Energy At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems for th…
Bistro Server/ Bartender
Additional Information: This hotel is owned and operated by an independent franchisee, NewcrestImage Management. The franchisee is a separate company and a separate employer from Marriott Internat…
Commercial Sales Engineer, HVAC Solutions
Overview: CoolSys solves the most complex challenges in refrigeration, air conditioning, heating, engineering, and energy management. With over 3,700 associates nationwide, we deliver tailored soluti…
VP, Chief Accounting Officer
Summary: The Vice President – Chief Accounting Officer (CAO) is a senior accounting and tax leadership role in a high-growth, private health insurance company. This position is responsible for deliv…
Care Manager/Protective Services Worker
Aging Services, Inc. Care Manager/Protective Services Worker: Full-time position (37.50 hours weekly) that provides assessment for our in-home services; Investigates reports for older adults…
Sr Data Scientist (Machine Learning, Natural Language Processing, Java, Python, R, SAS, Github) in Philadelphia, PA
Sr Data Scientist (Machine Learning, Natural Language Processing, Java, Python, R, SAS, Github) in Philadelphia, PA Github, Java, Machine Learning, Natural Language Processing, Python, R, SAS Locati…
Construction Litigation Attorney
Cohen Seglias has an opening in our Philadelphia office for a construction litigation associate. Candidates must have six plus years of construction or commercial litigation background, strong academi…
Fabricator- 2nd shift
Fabricator – Stainless Steel Process Equipment Bradford, Pennsylvania | Full-Time | 2 nd Shift (4 Day Workweek-Enjoy a 3 Day Weekend) | Hands-On Role At Allegheny Bradford Corporation , we spec…