{"schemaVersion":"jobsearcher.job.v1","id":"d5ed6ee645ee1ae1bb024055","url":"https://jobsearcher.com/jobs/d5ed6ee645ee1ae1bb024055","canonicalUrl":"https://jobsearcher.com/jobs/d5ed6ee645ee1ae1bb024055","title":"Lead DevSecOps Engineer","description":"Job Title: Lead DevSecOps Engineer\n\nLocation: Dallas, Texas\nResponsibilities\nLead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design engineering approach across cloud and application platforms.\nBuild and lead the DevSecOps engineering practice across all three execution crews: Platform & Infra, Application/Data/Middleware, and Container & TRC.\nOwn the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements.\nCoach offshore engineers on PNC-specific practices including Bitbucket branching standards, Jenkins pipeline security gates, PAC enforcement, and container security policies.\nManage the security and reliability of Jenkins pipelines used for vulnerability remediation automation, including implementing and maintaining security gates and reusable pipeline components.\nOwn Bitbucket repository structure, branching standards, and manage workflow configurations to enforce quality and security standards.\nImplement and maintain client PAC policy rules governing vulnerability automation, ensuring compliance with security policies before execution.\nDevelop Ansible playbooks and Terraform modules for infrastructure remediations, ensuring automated compliance evidence generation for audits.\nOwn operations and health of vulnerability tools (Archer, Tanium, Sysdig, SecurityCenter, Imperva), maintaining integrations and ensuring correct alert processing and scan coverage.\nManage secrets via CyberArk, ensuring least-privilege access and integrating secrets management within pipelines.\nBuild and maintain a unified vulnerability SLA dashboard in Archer with real-time vulnerability data, along with automated weekly SLA reports.\nDrive shift-left security practices within client application teams by embedding PAC checks and container security scans in the development pipeline.\nIdentify automation improvements to increase efficiency and contribute operational insights to improve AI/ML triage engines.\nRequirements\n7+ years of hands-on DevSecOps or security automation engineering experience in enterprise environments.\nDeep experience with Jenkins: shared libraries, pipeline-as-code, credential management, plugin administration, troubleshooting.\nProficiency with Bitbucket: branch permissions, PR workflows, webhook automation, Jenkins integration.\nStrong knowledge of Artifactory: dependency management, artifact promotion, repository configuration, security scanning.\nAdvanced Python skills: REST API integrations, automation scripting, data pipeline code.\nExpertise in Ansible: playbook creation for OS and middleware remediations on Linux and Windows.\nExperience with Terraform: module writing, state management, change governance.\nFamiliarity with policy-as-code tools like OPA/Conftest and runtime enforcement.\nREST API integrations with Archer GRC, ServiceNow, Jira.\nContainer operations: Docker, OpenShift/OCP, image management, container security.\nPractical experience with vulnerability platforms: Archer GRC, Tanium, SecurityCenter.\nSecrets management expertise, specifically CyberArk.\nUnderstanding of banking/financial services environment, including CAB process, change windows, deployment governance, and audit requirements.\nPreferred Qualifications\nFamiliarity with Converge, Micron framework, CaaS/OCP configurations, or BTI retail/lending mnemonic structures.\nSysdig operational experience for container vulnerability scanning and alert management.\nTanium endpoint detection and vulnerability data extraction.\nAI/ML pipeline experience, including LangChain or similar AI agent integration.\nProduction-level Jira administration and Confluence documentation.\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n#M-\n\n#LI-\n\nRef: #404-IT Pittsburgh","company":"Systemone","rawCompany":"systemone","city":"Dallas","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-07-27T13:54:17.275Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead DevSecOps Engineer","description":"Job Title: Lead DevSecOps Engineer\n\nLocation: Dallas, Texas\nResponsibilities\nLead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design engineering approach across cloud and application platforms.\nBuild and lead the DevSecOps engineering practice across all three execution crews: Platform & Infra, Application/Data/Middleware, and Container & TRC.\nOwn the Definition of Done for vulnerability remediation across all 130 mnemonics, ensuring proper validation, closure, and compliance with Archer POAM closure requirements.\nCoach offshore engineers on PNC-specific practices including Bitbucket branching standards, Jenkins pipeline security gates, PAC enforcement, and container security policies.\nManage the security and reliability of Jenkins pipelines used for vulnerability remediation automation, including implementing and maintaining security gates and reusable pipeline components.\nOwn Bitbucket repository structure, branching standards, and manage workflow configurations to enforce quality and security standards.\nImplement and maintain client PAC policy rules governing vulnerability automation, ensuring compliance with security policies before execution.\nDevelop Ansible playbooks and Terraform modules for infrastructure remediations, ensuring automated compliance evidence generation for audits.\nOwn operations and health of vulnerability tools (Archer, Tanium, Sysdig, SecurityCenter, Imperva), maintaining integrations and ensuring correct alert processing and scan coverage.\nManage secrets via CyberArk, ensuring least-privilege access and integrating secrets management within pipelines.\nBuild and maintain a unified vulnerability SLA dashboard in Archer with real-time vulnerability data, along with automated weekly SLA reports.\nDrive shift-left security practices within client application teams by embedding PAC checks and container security scans in the development pipeline.\nIdentify automation improvements to increase efficiency and contribute operational insights to improve AI/ML triage engines.\nRequirements\n7+ years of hands-on DevSecOps or security automation engineering experience in enterprise environments.\nDeep experience with Jenkins: shared libraries, pipeline-as-code, credential management, plugin administration, troubleshooting.\nProficiency with Bitbucket: branch permissions, PR workflows, webhook automation, Jenkins integration.\nStrong knowledge of Artifactory: dependency management, artifact promotion, repository configuration, security scanning.\nAdvanced Python skills: REST API integrations, automation scripting, data pipeline code.\nExpertise in Ansible: playbook creation for OS and middleware remediations on Linux and Windows.\nExperience with Terraform: module writing, state management, change governance.\nFamiliarity with policy-as-code tools like OPA/Conftest and runtime enforcement.\nREST API integrations with Archer GRC, ServiceNow, Jira.\nContainer operations: Docker, OpenShift/OCP, image management, container security.\nPractical experience with vulnerability platforms: Archer GRC, Tanium, SecurityCenter.\nSecrets management expertise, specifically CyberArk.\nUnderstanding of banking/financial services environment, including CAB process, change windows, deployment governance, and audit requirements.\nPreferred Qualifications\nFamiliarity with Converge, Micron framework, CaaS/OCP configurations, or BTI retail/lending mnemonic structures.\nSysdig operational experience for container vulnerability scanning and alert management.\nTanium endpoint detection and vulnerability data extraction.\nAI/ML pipeline experience, including LangChain or similar AI agent integration.\nProduction-level Jira administration and Confluence documentation.\nSystem One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.\nSystem One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.\n#M-\n\n#LI-\n\nRef: #404-IT Pittsburgh","datePosted":"2026-07-27T13:54:17.275Z","dateModified":"2026-07-27T13:54:17.275Z","hiringOrganization":{"@type":"Organization","name":"Systemone","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dallas","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"d5ed6ee645ee1ae1bb024055"},"url":"https://jobsearcher.com/jobs/d5ed6ee645ee1ae1bb024055"}}