{"schemaVersion":"jobsearcher.job.v1","id":"19589f2fdffea2ead6ea4278","url":"https://jobsearcher.com/jobs/19589f2fdffea2ead6ea4278","canonicalUrl":"https://jobsearcher.com/jobs/19589f2fdffea2ead6ea4278","title":"DevSecOps Security Engineer","description":"Your Role at a Glance\nThe DevSecOps Security Engineer is responsible for securing and governing Mastercam's cloud-native application platforms, AI-enabled solutions, and supporting infrastructure. This role integrates security throughout the software development lifecycle, including CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads.\nWorking closely with Software Engineering, Platform Engineering, Infrastructure, and IT Operations teams, the DevSecOps Security Engineer designs, implements, and maintains security controls that protect applications, infrastructure, data, and AI services while supporting the efficient delivery of business solutions. The role helps establish security standards, improve risk management practices, and promote secure-by-design principles across development and operational processes.\nThis position requires expertise in cloud-native technologies, Kubernetes, container security, CI/CD environments, and modern application security practices, along with the ability to contribute to emerging AI and platform security initiatives. The role serves as a key technical resource in advancing the organization's security posture while enabling innovation and operational scalability.\nHow You'll Drive Success\nPlatform Security\n\nSecure Kubernetes-based platforms and containerized workloads.\nImplement and maintain Kubernetes security controls including RBAC, Network Policies, Pod Security Standards, and namespace segmentation.\nPerform security reviews of platform architecture and application deployments.\nDevelop infrastructure hardening standards and security baselines.\n\nDevSecOps\n\nIntegrate security controls into CI/CD pipelines.\nImplement automated vulnerability scanning, code analysis, and compliance checks.\nEstablish secure software supply chain processes.\nPartner with development teams to remediate vulnerabilities and improve secure coding practices.\nDevelop and maintain security guardrails within GitOps workflows.\n\nIdentity & Access Management\n\nSecure authentication and authorization systems.\nImplement least-privilege access controls across applications and infrastructure.\nSupport identity federation, Single Sign-On (SSO), OAuth2, OpenID Connect, and Multi-Factor Authentication (MFA).\nReview systems for access governance and privileged access risks.\n\nSecret Management\n\nImplement secure management of secrets, certificates, encryption keys, and service credentials.\nSupport automated secret rotation and certificate lifecycle management.\nEnsure secure application integration with centralized secrets management platforms.\n\nAPI & Service Security\n\nSecure API gateways and service-to-service communications.\nReview API implementations against OWASP API Security standards.\nImplement authentication, authorization, rate limiting, and API threat protection controls.\nSupport Zero Trust networking initiatives.\n\nSecurity Monitoring & Detection\n\nCreate dashboards and alerts for security events.\nDevelop security metrics and monitoring capabilities.\nCollaborate with operations teams during security investigations and incident response activities.\nAnalyze platform telemetry and audit logs to identify threats and control gaps.\n\nAI & Emerging Technology Security\n\nSupport security reviews for AI and machine learning workloads.\nAssist with implementing controls to protect against prompt injection, sensitive data exposure, and model misuse.\nParticipate in AI governance and risk assessment activities.\nEvaluate emerging risks associated with Large Language Models (LLMs), vector databases, and AI platforms.\n\nThe Talents We're Seeking\nEducation & Experience\n\nBachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required; equivalent combinations of education, military service, and relevant professional experience will also be considered.\n4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering.\n1+ year of hands‑on experience supporting Kubernetes or containerized application environments.\nExperience securing cloud-native applications and services.\nExperience implementing vulnerability management and application security programs.\nExperience working with software development teams and CI/CD pipelines.\nExperience supporting cloud environments such as AWS, Azure, or Google Cloud.\n\nRequired Skills\nKubernetes\nKnowledge of:\n\nKubernetes architecture\nPods, Deployments, Services, and Ingresses\nRBAC\nNetwork Policies\nContainer security\nWorkload isolation\nCluster security fundamentals\n\nContainers\nExperience with:\n\nDocker\nContainer image security\nImage scanning\nVulnerability remediation\nSecure image lifecycle management\n\nDevSecOps\nExperience with:\n\nCI/CD pipelines\nSource code management platforms\nGit workflows\nAutomation and scripting\n\nUnderstanding of:\n\nSAST\nDAST\nDependency scanning\nSecret scanning\nInfrastructure-as-Code security\n\nIdentity Management\nKnowledge of:\n\nOAuth2\nOpenID Connect\nSAML\nMFA\nRole-Based Access Control\n\nSecurity Operations\nExperience with:\n\nVulnerability management\nThreat detection\nSecurity monitoring\nIncident response support\nRisk assessments\n\nScripting\nAbility to automate security processes using:\n\nPython\nBash\nPowerShell\n\nPreferred Skills\nExperience with any of the following technologies is highly desirable:\nPlatform Technologies\n\nKubernetes\nIstio\nFluxCD\nAPISIX\nOpenTelemetry\nGrafana\n\nIdentity & Security Technologies\n\nKeycloak\nOpenBao\nHashiCorp Vault\nAzure Entra ID\nAWS IAM\n\nData & Messaging Platforms\n\nPostgreSQL\nRabbitMQ\nQdrant\n\nAI Platforms\n\nAmazon Bedrock\nGenerative AI applications\nRetrieval Augmented Generation (RAG)\nVector databases\nLLM Security\n\nPreferred Security Knowledge\nKnowledge of:\n\nOWASP Top 10\nOWASP API Security Top 10\nOWASP Top 10 for LLM Applications\nNIST Cybersecurity Framework\nCIS Benchmarks\nZero Trust Architecture\nSecure Software Development Lifecycle (SSDLC)\n\nPreferred Certifications\nOne or more of:\n\nSecurity+\nCertified Kubernetes Administrator (CKA)\nCertified Kubernetes Security Specialist (CKS)\nAWS Certified Security Specialty\nCISSP\nCCSP\nGIAC Certifications\n\nWho We Are\nAt Mastercam, we do not just keep pace with manufacturing—we set the pace. For over 40 years, we have been the name behind the breakthroughs, the partner for those who refuse to settle. When the industry says \"too complex,\" we say, \"challenge accepted.\"\nWe are more than software. We are a movement of makers, innovators, and problem-solvers driving transformation across the globe.\nBacked by a network of 400 Channel Partners and a thriving developer community, Mastercam delivers the tools and expertise to turn ambitious ideas into flawless reality. From aerospace to automotive, medical to education, we empower manufacturers to push boundaries and redefine what is possible.\nAs part of Intelligent Manufacturing and the Sandvik Group, we are leading the charge in digital transformation. Our team of 500+ professionals is united by a single mission: to help achieve precision, productivity, and performance without compromise.\nOur Core Values? They are not just words. They are how we win:\n\nWinning Together: Collaboration is not optional—it is the engine that drives us.\nCuriosity: We question, we explore, we innovate. Every day.\nResponsibility: Safety, integrity, and sustainability aren't boxes to check—they are the foundation of trust.\nCustomer-Focused: We listen. We adapt. We deliver. Always.\n\nInnovation. Collaboration. Growth. That is the Mastercam way. Explore more atwww.mastercam.com, connect onLinkedIn, and join the conversation with #mastercam.\nThe next big challenge is waiting—are you ready to accept?\nIt is the policy of the company to provide equal employment opportunities to all employees and employment applicants without regard to race, color, religion, sex, or national origin or any other classification protected by applicable local or state laws.\nEOE/M/F/Vet/Disabled are encouraged to apply.\nWe are an E-Verify Employer.\nPI287342547\n#J-18808-Ljbffr","company":"Cnc Software","rawCompany":"cnc software","city":"Tolland","state":"CT","isRemote":false,"isActive":false,"createdAt":"2026-10-03T03:27:53.386Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Security Engineer","description":"Your Role at a Glance\nThe DevSecOps Security Engineer is responsible for securing and governing Mastercam's cloud-native application platforms, AI-enabled solutions, and supporting infrastructure. This role integrates security throughout the software development lifecycle, including CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads.\nWorking closely with Software Engineering, Platform Engineering, Infrastructure, and IT Operations teams, the DevSecOps Security Engineer designs, implements, and maintains security controls that protect applications, infrastructure, data, and AI services while supporting the efficient delivery of business solutions. The role helps establish security standards, improve risk management practices, and promote secure-by-design principles across development and operational processes.\nThis position requires expertise in cloud-native technologies, Kubernetes, container security, CI/CD environments, and modern application security practices, along with the ability to contribute to emerging AI and platform security initiatives. The role serves as a key technical resource in advancing the organization's security posture while enabling innovation and operational scalability.\nHow You'll Drive Success\nPlatform Security\n\nSecure Kubernetes-based platforms and containerized workloads.\nImplement and maintain Kubernetes security controls including RBAC, Network Policies, Pod Security Standards, and namespace segmentation.\nPerform security reviews of platform architecture and application deployments.\nDevelop infrastructure hardening standards and security baselines.\n\nDevSecOps\n\nIntegrate security controls into CI/CD pipelines.\nImplement automated vulnerability scanning, code analysis, and compliance checks.\nEstablish secure software supply chain processes.\nPartner with development teams to remediate vulnerabilities and improve secure coding practices.\nDevelop and maintain security guardrails within GitOps workflows.\n\nIdentity & Access Management\n\nSecure authentication and authorization systems.\nImplement least-privilege access controls across applications and infrastructure.\nSupport identity federation, Single Sign-On (SSO), OAuth2, OpenID Connect, and Multi-Factor Authentication (MFA).\nReview systems for access governance and privileged access risks.\n\nSecret Management\n\nImplement secure management of secrets, certificates, encryption keys, and service credentials.\nSupport automated secret rotation and certificate lifecycle management.\nEnsure secure application integration with centralized secrets management platforms.\n\nAPI & Service Security\n\nSecure API gateways and service-to-service communications.\nReview API implementations against OWASP API Security standards.\nImplement authentication, authorization, rate limiting, and API threat protection controls.\nSupport Zero Trust networking initiatives.\n\nSecurity Monitoring & Detection\n\nCreate dashboards and alerts for security events.\nDevelop security metrics and monitoring capabilities.\nCollaborate with operations teams during security investigations and incident response activities.\nAnalyze platform telemetry and audit logs to identify threats and control gaps.\n\nAI & Emerging Technology Security\n\nSupport security reviews for AI and machine learning workloads.\nAssist with implementing controls to protect against prompt injection, sensitive data exposure, and model misuse.\nParticipate in AI governance and risk assessment activities.\nEvaluate emerging risks associated with Large Language Models (LLMs), vector databases, and AI platforms.\n\nThe Talents We're Seeking\nEducation & Experience\n\nBachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required; equivalent combinations of education, military service, and relevant professional experience will also be considered.\n4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering.\n1+ year of hands‑on experience supporting Kubernetes or containerized application environments.\nExperience securing cloud-native applications and services.\nExperience implementing vulnerability management and application security programs.\nExperience working with software development teams and CI/CD pipelines.\nExperience supporting cloud environments such as AWS, Azure, or Google Cloud.\n\nRequired Skills\nKubernetes\nKnowledge of:\n\nKubernetes architecture\nPods, Deployments, Services, and Ingresses\nRBAC\nNetwork Policies\nContainer security\nWorkload isolation\nCluster security fundamentals\n\nContainers\nExperience with:\n\nDocker\nContainer image security\nImage scanning\nVulnerability remediation\nSecure image lifecycle management\n\nDevSecOps\nExperience with:\n\nCI/CD pipelines\nSource code management platforms\nGit workflows\nAutomation and scripting\n\nUnderstanding of:\n\nSAST\nDAST\nDependency scanning\nSecret scanning\nInfrastructure-as-Code security\n\nIdentity Management\nKnowledge of:\n\nOAuth2\nOpenID Connect\nSAML\nMFA\nRole-Based Access Control\n\nSecurity Operations\nExperience with:\n\nVulnerability management\nThreat detection\nSecurity monitoring\nIncident response support\nRisk assessments\n\nScripting\nAbility to automate security processes using:\n\nPython\nBash\nPowerShell\n\nPreferred Skills\nExperience with any of the following technologies is highly desirable:\nPlatform Technologies\n\nKubernetes\nIstio\nFluxCD\nAPISIX\nOpenTelemetry\nGrafana\n\nIdentity & Security Technologies\n\nKeycloak\nOpenBao\nHashiCorp Vault\nAzure Entra ID\nAWS IAM\n\nData & Messaging Platforms\n\nPostgreSQL\nRabbitMQ\nQdrant\n\nAI Platforms\n\nAmazon Bedrock\nGenerative AI applications\nRetrieval Augmented Generation (RAG)\nVector databases\nLLM Security\n\nPreferred Security Knowledge\nKnowledge of:\n\nOWASP Top 10\nOWASP API Security Top 10\nOWASP Top 10 for LLM Applications\nNIST Cybersecurity Framework\nCIS Benchmarks\nZero Trust Architecture\nSecure Software Development Lifecycle (SSDLC)\n\nPreferred Certifications\nOne or more of:\n\nSecurity+\nCertified Kubernetes Administrator (CKA)\nCertified Kubernetes Security Specialist (CKS)\nAWS Certified Security Specialty\nCISSP\nCCSP\nGIAC Certifications\n\nWho We Are\nAt Mastercam, we do not just keep pace with manufacturing—we set the pace. For over 40 years, we have been the name behind the breakthroughs, the partner for those who refuse to settle. When the industry says \"too complex,\" we say, \"challenge accepted.\"\nWe are more than software. We are a movement of makers, innovators, and problem-solvers driving transformation across the globe.\nBacked by a network of 400 Channel Partners and a thriving developer community, Mastercam delivers the tools and expertise to turn ambitious ideas into flawless reality. From aerospace to automotive, medical to education, we empower manufacturers to push boundaries and redefine what is possible.\nAs part of Intelligent Manufacturing and the Sandvik Group, we are leading the charge in digital transformation. Our team of 500+ professionals is united by a single mission: to help achieve precision, productivity, and performance without compromise.\nOur Core Values? They are not just words. They are how we win:\n\nWinning Together: Collaboration is not optional—it is the engine that drives us.\nCuriosity: We question, we explore, we innovate. Every day.\nResponsibility: Safety, integrity, and sustainability aren't boxes to check—they are the foundation of trust.\nCustomer-Focused: We listen. We adapt. We deliver. Always.\n\nInnovation. Collaboration. Growth. That is the Mastercam way. Explore more atwww.mastercam.com, connect onLinkedIn, and join the conversation with #mastercam.\nThe next big challenge is waiting—are you ready to accept?\nIt is the policy of the company to provide equal employment opportunities to all employees and employment applicants without regard to race, color, religion, sex, or national origin or any other classification protected by applicable local or state laws.\nEOE/M/F/Vet/Disabled are encouraged to apply.\nWe are an E-Verify Employer.\nPI287342547\n#J-18808-Ljbffr","datePosted":"2026-10-03T03:27:53.386Z","dateModified":"2026-10-03T03:27:53.386Z","hiringOrganization":{"@type":"Organization","name":"Cnc Software","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Tolland","addressRegion":"CT","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"19589f2fdffea2ead6ea4278"},"url":"https://jobsearcher.com/jobs/19589f2fdffea2ead6ea4278"}}