Associate DevSecOps Engineer, Platform and Tooling
Associate DevSecOps EngineerJoin our Information Security team as an Associate DevSecOps Engineer and be part of the core team building a global enterprise-grade Application Security program from the ground up. You will play a vital role in implementing security testing tools, integrating them into our CI/CD ecosystems, and delivering actionable findings to developers—enabling secure software delivery at scale. Together, we will make a remarkable impact on people's lives by protecting the systems that discover and deliver life-changing medicines to patients who need them.Responsibilities:Supporting or administering Application Security Testing (AST) tools (SAST, DAST, IAST, SCA, etc.) to identify vulnerabilities and configuration issues during the software development lifecycle.Supporting or administering tools such as Application Security Posture Management (ASPM) to centralize and deduplicate findings from multiple solutions and integrate reporting into software development workflows.Integrating security tooling with CI/CD pipelines.Writing custom scripts and code to automate workflows and integrate technologies.QualificationsRequired:Bachelor's Degree and 5 years of experience OR Master's Degree and 4 years of experience.2+ years' experience of hands-on technical experience in DevSecOps / DevOps / Site Reliability Engineering (SRE).Experience integrating application security tooling such as SAST/DAST/IAST/SCA into CI/CD pipelines.Experience configuring, supporting, or administering CI/CD pipelines (such as GitHub Actions and Azure DevOps) and helping integrate security testing solutions.Experience automating workflows and integrating platforms via programming languages such as Python.Preferred:Experience with commercial or in-house Application Security Posture Management (ASPM) tooling to facilitate risk visibility, finding management, and developer workflow integration.Experience implementing pre-deployment container and/or artifact security tooling (e.g., image scanning, dependency validation).Experience implementing container and artifact security solutions (e.g., Snyk, JFrog Artifactory), including image scanning, vulnerability assessment, and dependency validation in CI/CD pipelines.Experience administering Snyk in large enterprise environments.Pay Range:$ 84500 - 162000 USD