DevSecOps Engineer W2 role only Position Available In Mecklenburg, North Carolina
Tallo's Job Summary: The DevSecOps Engineer W2 role, located in Iselin NJ or Charlotte NC, is a 6+ month opportunity for USC-GC candidates only. Responsibilities include managing security automation tools, collaborating with internal teams, providing security training, and conducting adversarial security analysis. Required qualifications include 5+ years of Information Security Engineering experience and 5+ years of experience as an Application Security and DevSecOps engineer. Desired qualifications include automation scripting skills, CI/CD pipeline experience, and certification in information security. This position offers a hybrid work schedule.
Job Description
DevSecOps Engineer W2 role only
Position:
DevSecOps Engineer
Location:
Iselin NJ OR Charlotte NC
Duration :
6+
Months Need USC-GC- Only Overview:
Role Description:
This role is part of application security engineering team responsible for scanning code following the Wells Fargo established guidelines, secure development policies and procedures. This role will focus heavily on building and enhancing Software Composition Analysis (SCA) practice, help software developers at various Wells Fargo CIO teams to build faster, more securely, fine-tuning the tools, leveraging AI where possible to improve processes and services for optimal developer experience.
Key Responsibilities:
Managing security automation tools with main focus on SCA (i.e. Checkmarx One, BlackDuck) and other tools in the ecosystem along with supporting operational management with regularly scheduled upgrade of the tools.
Interface with various internal teams ServiceNow AVR, DevOps and vulnerability operations team to make sure SCA vulnerabilities are identified and recorded per the application security policies and guidance.
Collaborate with security architecture teams to design vulnerability management workflow, establish best practices and design guidance to optimize experience for developers
Security training and outreach as needed for internal development teams
Adversarial security analysis on various application security requirements as requested from various CIO teams, research and recommend cutting-edge tools and industry best practices.
Work with application security governance teams, risk & compliance partners on audits (e.g., SOC 2, PCI-DSS) and recommending relevant policies.
Collaborate with CTO pipeline teams to improve code quality and vulnerability detection on OpenSource, code signing and SBOM creation
Analyze, enhance, architect and support container security tools and platforms
Design and build advanced security solutions to strengthen open source software supply chains for effective automation and management.
Required Qualifications:
5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
5+ years of experience as Application Security and DevSecOps engineer, collaborating with developers to adopt and mature secure development
3+ years experience in one or more of programming languages, .Net, C#, Java, RUST, C++
Desired Qualifications:
Ability to write automation scripts in Python, PowerShell to support internal projects
Experience with CI/CD pipelines and related technologies (e.g., GitHub, Jenkins, Maven, Artifactory, Harness, Xray, Curation)
Good understanding of Secure Software development lifecycle
Strong knowledge of OWASP Top 10 or CWE
Detailed oriented must be able to create documentation on different SCA procedures and tool configuration
Familiarity and experience with AI tools supporting false positives reduction, auto code remediation, open-source threat intelligence would be preferred.
Experience with Jira/Confluence
Strong problem-solving and analytical skills
Certification in information security (CISSP, CISM, CEH, etc.)
Experience with container security working with technologies like k8s and container technologies such as Openshift
Experience generating Software Bill of Materials (SBOMs) using CycloneDX or SPDX, managing or utilizing dependency track
Job Expectations:
This position offers a hybrid work schedule
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job
Dice Id:
91166607
Position Id:
8649719