IT Operations & Security

DevSecOps Engineer

SOC 15-1212.00 · ESCO 2519 · OSCA 271135

REA INV ART SOC ENT CON This role See your match →

Role snapshot

Overview

Embeds security checks directly into the software delivery pipeline, automating vulnerability scanning and compliance testing so code ships safely without slowing teams down. Writes tooling that catches risks early in the development process.

Ensures the continuous delivery of secure software by integrating security practices throughout the entire development lifecycle, protecting organizational assets and customer data from evolving cyber threats.

On the job

  • Integrate automated security testing tools (SAST, DAST, SCA) into CI/CD pipelines.
  • Develop and implement security as code practices and policies for cloud infrastructure.
  • Collaborate with development and operations teams to embed security best practices and remediate vulnerabilities.
  • Design and build security automation tools and scripts to enhance detection and response capabilities.
  • Monitor security metrics, analyze threat intelligence, and adapt security controls proactively.
DevSecOps Engineer at work

Tools & technology

GitJenkinsGitLab CI/CDDockerKubernetesAWS/Azure/GCPTerraformAnsibleSonarQubeNessusPythonGo

Average salary

$135K
MEDIAN SALARY Annual · USD
$100K Bottom 10%
$170K Top 10%

Job outlook

Excellent

New job opportunities are highly likely. Demand significantly outpaces supply in most markets.

Education & training

Bachelor's degree in Computer Science, Information Security, or a related engineering field, often complemented by relevant industry certifications.

Career pathways

WHERE YOU COULD GO

Senior DevSecOps Engineer
Security Architect
Cloud Security Architect
Principal Engineer, Security

CURRENT ROLE

DevSecOps Engineer

IT Operations & Security

ADJACENT MOVES

DevOps Engineer
Application Security Engineer
Devops Engineer
Security Analyst
Software Engineer
System Administrator

STARTING POINTS

Who thrives here

Interest profile

C

conventional · CIR

Individuals who are methodical, enjoy analytical problem-solving, and have a practical, results-oriented approach to technology will find this role engaging. It suits those who thrive on systematic processes, intellectual challenges, and hands-on technical work.

Personality characteristics

Conscientious

Exhibits strong attention to detail and a methodical approach to securing complex systems and pipelines.

Inquisitive

Driven by curiosity to understand how systems work, identify vulnerabilities, and explore new security technologies.

Analytical

Enjoys dissecting technical problems, analyzing data, and applying logical reasoning to design robust security solutions.

Practical

Prefers hands-on work, building and implementing security tools and automation directly.

Collaborative

Works effectively with development, operations, and other teams to integrate security seamlessly.

Resilient

Manages pressure well during security incidents and can adapt to a constantly evolving threat landscape without becoming overwhelmed.

Best for

  • Individuals who enjoy blending software engineering principles with cybersecurity practices.
  • Problem-solvers passionate about automating security controls and building resilient systems.
  • Those who thrive on intellectual challenges and contributing to a secure software development lifecycle.

Watch out for

  • Requires continuous learning and adaptation to new technologies and evolving cyber threats.
  • Can involve high-pressure situations during security incidents or critical vulnerability remediation.
  • Requires strong communication skills to bridge the gap between security, development, and operations teams.

A week in the life

A representative working week for a DevSecOps Engineer — where the deep work, meetings, and admin actually land.

8am9am10am11am12pm1pm2pm3pm4pm5pm6pm
Mon
Daily Standup & Priority Setting
CI/CD Security Tool Integration & Scripting
Code Review & Security Feedback for Dev Teams
Security Architecture Review Meeting
Tue
Developing Cloud Security Automation (IaC)
Vulnerability Triage and Remediation Planning
Team Sync & Knowledge Sharing Session
Wed
Threat Modeling Workshop with Product Team
Researching New Security Technologies & Vulnerabilities
Updating Security Policies and Documentation
Mentoring Junior Engineers
Thu
Incident Response Plan Review & Drills
Vendor Security Assessment / External Audit Support
Refining Security Monitoring & Alerting Systems
Fri
Optimizing Security Scanners & Pipeline Performance
Weekly Planning & Administrative Tasks
Deep work Meeting External Social Admin

FREE ASSESSMENT

Does DevSecOps Engineer fit you?

Measure your personality and interests, then see how this career ranks against 1,300+ others — for you personally.

Take the free assessment →