{"schemaVersion":"jobsearcher.job.v1","id":"5e6f6427fa4a4baf20b4e7cb","url":"https://jobsearcher.com/jobs/5e6f6427fa4a4baf20b4e7cb","canonicalUrl":"https://jobsearcher.com/jobs/5e6f6427fa4a4baf20b4e7cb","title":"DevSecOps Engineer","description":"We have an immediate Openings with Our Direct Client for a Long-term contract position\n\nLocation: Irving TX\n\nSBOM / CBOM Inventory, Vulnerability Scanning & AI Auto-Remediation\n\nWe are looking for a hands‑on Senior DevSecOps Platform Engineer to help build an internal security automation platform for SBOM/CBOM inventory, vulnerability scanning, and Claude-based auto‑remediation.\n\nThis is not a traditional full‑stack developer role. The right candidate should be able to build applications, design CI/CD pipelines, integrate security scanning tools, understand cryptography inventory, and automate remediation safely.\n\nKey Responsibilities\n\nDesign and build a centralized platform for SBOM and CBOM inventory.\n\nScan applications, repositories, containers, dependencies, certificates, keys, crypto algorithms, TLS configurations, and runtime components.\n\nIntegrate SBOM/CBOM and vulnerability scanning into Jenkins/GitLab CI/CD pipelines.\n\nIdentify vulnerable dependencies, CVEs, weak cryptography, expired certificates, insecure TLS versions, hardcoded secrets, and non‑compliant libraries.\n\nBuild automation workflows to support remediation using Claude or similar AI coding agents.\n\nAutomate safe fixes such as dependency upgrades, base image updates, configuration changes, and pull request creation.\n\nEnsure all AI‑assisted remediations are validated through build, test, scan, approval, and audit workflows before merge or deployment.\n\nBuild dashboards and reports for application inventory, vulnerability posture, crypto posture, remediation status, and SLA tracking.\n\nWork closely with application, security, DevOps, and platform teams.\n\nRequired Skills\n\nHands‑on experience with Jenkins and/or GitLab CI/CD.\n\nStrong understanding of SBOM, dependency scanning, transitive dependencies, CVEs, and container image scanning.\n\nExperience with tools such as Syft, Grype, CycloneDX, SPDX, JFrog Xray, Sonatype, Checkmarx, Fortify, or Veracode.\n\nGood understanding of CBOM and cryptography inventory, including TLS/HTTPS, certificates, keys, cipher suites, encryption algorithms, hashing algorithms, signing algorithms, keystores, truststores, and secrets.\n\nAbility to identify weak crypto such as MD5, SHA‑1, DES/3DES, RC4, RSA‑1024, TLS 1.0/TLS 1.1, and disabled certificate validation.\n\nHands‑on AWS experience with services such as Lambda, API Gateway, S3, DynamoDB, IAM, ECS/EKS, CloudWatch, X‑Ray, Secrets Manager, and KMS.\n\nExperience with observability tools such as Splunk, ELK/Kibana, CloudWatch, and X‑Ray.\n\nStrong hands‑on experience with Java/Spring Boot.\n\nExperience with at least one additional language such as Node.js, Python, or Go.\n\nExperience building REST APIs, microservices, batch jobs, and platform integrations.\n\nStrong troubleshooting skills across application, pipeline, cloud, and security issues.\n\nThe candidate should understand how to use Claude or similar AI tools in a controlled engineering workflow.\n\nPreferred Skills\n\nExperience building internal developer platforms or security automation platforms.\n\nExperience with vulnerability management and remediation workflows.\n\nExperience with policy engines such as OPA or custom rule engines.\n\nKnowledge of post‑quantum cryptography readiness and crypto‑agility.\n\nExperience with certificate lifecycle management, secrets management, and cloud security controls.\n\nFrontend experience with Angular or React for dashboards and reporting.\n\nMinimum Qualifications\n\n8+ years of software engineering experience.\n\n3+ years of DevOps, DevSecOps, platform engineering, or security automation experience.\n\nStrong Java/Spring Boot background.\n\nHands‑on CI/CD and cloud experience.\n\nPractical experience with security scanning and vulnerability remediation.\n\nStrong communication skills and ability to work across security, platform, DevOps, and application teams.\n\n#J-18808-Ljbffr","company":"Infovision","rawCompany":"infovision","city":"Irving","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-07-16T03:44:48.424Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Engineer","description":"We have an immediate Openings with Our Direct Client for a Long-term contract position\n\nLocation: Irving TX\n\nSBOM / CBOM Inventory, Vulnerability Scanning & AI Auto-Remediation\n\nWe are looking for a hands‑on Senior DevSecOps Platform Engineer to help build an internal security automation platform for SBOM/CBOM inventory, vulnerability scanning, and Claude-based auto‑remediation.\n\nThis is not a traditional full‑stack developer role. The right candidate should be able to build applications, design CI/CD pipelines, integrate security scanning tools, understand cryptography inventory, and automate remediation safely.\n\nKey Responsibilities\n\nDesign and build a centralized platform for SBOM and CBOM inventory.\n\nScan applications, repositories, containers, dependencies, certificates, keys, crypto algorithms, TLS configurations, and runtime components.\n\nIntegrate SBOM/CBOM and vulnerability scanning into Jenkins/GitLab CI/CD pipelines.\n\nIdentify vulnerable dependencies, CVEs, weak cryptography, expired certificates, insecure TLS versions, hardcoded secrets, and non‑compliant libraries.\n\nBuild automation workflows to support remediation using Claude or similar AI coding agents.\n\nAutomate safe fixes such as dependency upgrades, base image updates, configuration changes, and pull request creation.\n\nEnsure all AI‑assisted remediations are validated through build, test, scan, approval, and audit workflows before merge or deployment.\n\nBuild dashboards and reports for application inventory, vulnerability posture, crypto posture, remediation status, and SLA tracking.\n\nWork closely with application, security, DevOps, and platform teams.\n\nRequired Skills\n\nHands‑on experience with Jenkins and/or GitLab CI/CD.\n\nStrong understanding of SBOM, dependency scanning, transitive dependencies, CVEs, and container image scanning.\n\nExperience with tools such as Syft, Grype, CycloneDX, SPDX, JFrog Xray, Sonatype, Checkmarx, Fortify, or Veracode.\n\nGood understanding of CBOM and cryptography inventory, including TLS/HTTPS, certificates, keys, cipher suites, encryption algorithms, hashing algorithms, signing algorithms, keystores, truststores, and secrets.\n\nAbility to identify weak crypto such as MD5, SHA‑1, DES/3DES, RC4, RSA‑1024, TLS 1.0/TLS 1.1, and disabled certificate validation.\n\nHands‑on AWS experience with services such as Lambda, API Gateway, S3, DynamoDB, IAM, ECS/EKS, CloudWatch, X‑Ray, Secrets Manager, and KMS.\n\nExperience with observability tools such as Splunk, ELK/Kibana, CloudWatch, and X‑Ray.\n\nStrong hands‑on experience with Java/Spring Boot.\n\nExperience with at least one additional language such as Node.js, Python, or Go.\n\nExperience building REST APIs, microservices, batch jobs, and platform integrations.\n\nStrong troubleshooting skills across application, pipeline, cloud, and security issues.\n\nThe candidate should understand how to use Claude or similar AI tools in a controlled engineering workflow.\n\nPreferred Skills\n\nExperience building internal developer platforms or security automation platforms.\n\nExperience with vulnerability management and remediation workflows.\n\nExperience with policy engines such as OPA or custom rule engines.\n\nKnowledge of post‑quantum cryptography readiness and crypto‑agility.\n\nExperience with certificate lifecycle management, secrets management, and cloud security controls.\n\nFrontend experience with Angular or React for dashboards and reporting.\n\nMinimum Qualifications\n\n8+ years of software engineering experience.\n\n3+ years of DevOps, DevSecOps, platform engineering, or security automation experience.\n\nStrong Java/Spring Boot background.\n\nHands‑on CI/CD and cloud experience.\n\nPractical experience with security scanning and vulnerability remediation.\n\nStrong communication skills and ability to work across security, platform, DevOps, and application teams.\n\n#J-18808-Ljbffr","datePosted":"2026-07-16T03:44:48.424Z","dateModified":"2026-07-16T03:44:48.424Z","hiringOrganization":{"@type":"Organization","name":"Infovision","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Irving","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5e6f6427fa4a4baf20b4e7cb"},"url":"https://jobsearcher.com/jobs/5e6f6427fa4a4baf20b4e7cb"}}