JOBSEARCHER

Senior Security Engineer - DevSecOps

We are CirrusLabs. Our vision is to become the world's most sought-after niche digital transformation company that helps customers realize value through innovation. Our mission is to co-create success with our customers, partners and community. Our goal is to enable employees to dream, grow and make things happen. We are committed to excellence. We are a dependable partner organization that delivers on commitments. We strive to maintain integrity with our employees and customers. Every action we take is driven by value. The core of who we are is through our well-knit teams and employees. You are the core of a values driven organization.You have an entrepreneurial spirit. You enjoy working as a part of well-knit teams. You value the team over the individual. You welcome diversity at work and within the greater community. You aren't afraid to take risks. You appreciate a growth path with your leadership team that journeys how you can grow inside and outside of the organization. You thrive upon continuing education programs that your company sponsors to strengthen your skills and for you to become a thought leader ahead of the industry curve.You are excited about creating change because your skills can help the greater good of every customer, industry and community. We are hiring a talented to join our team. If you're excited to be part of a winning team, CirrusLabs (http://www.cirruslabs.io) is a great place to grow your career.About the OpportunityWe are a leading technology consultancy supporting a Fortune 50 enterprise IT organization in delivering security-focused engineering initiatives. As part of a critical enterprise-wide program, we are seeking a Senior Security Engineer to support DevSecOps enablement, source code security, and secret hygiene.This role is ideal for a hands-on cybersecurity professional with experience in DevSecOps, GitHub Enterprise, and secret management practices. You'll work closely with cross-functional teams to improve enterprise security posture using modern tooling, automation, and best practices.This is a remote role with limited travel, which may be requested but is not required.Role SummaryAs a Senior Security Engineer - DevSecOps, you will contribute to strengthening the security of source code repositories across the enterprise. Your initial focus will be on the detection and remediation of plaintext secrets exposed in GitHub repositories. You will help build scalable remediation workflows, support governance enforcement, and enable compliance with secure development standards.You will also work with tools like GitGuardian and ServiceNow, supporting continuous monitoring and automation efforts across DevSecOps pipelines.Key ResponsibilitiesSupport the implementation of secure source code practices, focusing on remediating exposed secrets in GitHub repositoriesIdentify and mitigate plaintext credentials, tokens, and secrets in enterprise codebasesApply governance policies related to secrets, PATs, SSH keys, and unauthorized repositoriesAssist in the integration and management of GitGuardian for automated secret scanning and alertingParticipate in building remediation workflows and resolution tracking via ServiceNowContribute to the development of repeatable, automated compliance processes for repository hygieneGenerate dashboards and metrics to track remediation progress and security postureSupport security awareness efforts and help document secure coding practicesExplore AI/GenAI capabilities for improving detection and remediation efficiency (preferred) Required Qualifications8+ years of experience in security engineering, DevSecOps, or application security within enterprise environmentsStrong hands-on experience with GitHub Enterprise, particularly in secret scanning and repository managementFamiliarity with identifying and remediating secrets embedded in codeExperience using GitGuardian or similar secret detection toolsWorking knowledge of ServiceNow or equivalent platforms for issue tracking and triageUnderstanding of secure development governance and compliance frameworksStrong collaboration and communication skills to work effectively across technical and non-technical teamsComfortable using collaboration tools like Microsoft Teams and Outlook Preferred QualificationsExperience in global consultancies, Big 4 firms, or enterprise IT organizationsFamiliarity with AI/GenAI use cases for security operationsExposure to secure SDLC and DevSecOps pipeline integrationsKnowledge of GRC standards such as NIST, CIS Controls, or ISO 27001Experience working in distributed and cross-functional teams Why Join Us?Be part of a high-impact DevSecOps initiative within a global enterpriseCollaborate with a world-class consultancy on modern security tooling and best practicesWork hands-on with GitHub Enterprise, GitGuardian, and ServiceNowSupport AI-assisted remediation and automation strategiesEnjoy a remote-first, long-term engagement with significant technical influence