AbbVie logo

Senior DevSecOps Engineer (Remote)

AbbVie
Remote
United States
$106,500 - $202,500 USD yearly
IT

Role Summary

Become a key player in our Information Security team as a Senior DevSecOps Engineer, leveraging expertise in application security and security engineering to support and enhance code scanning and finding management processes. This role involves the implementation and administration of application security tooling, integration of scanning into CI/CD pipelines, and building or implementing automated finding management technologies to facilitate developer remediation activities. This position can be virtually anywhere in the U.S.

Responsibilities

  • Implementing and maintaining Application Security Testing (AST) tools (SAST, DAST, IAST, SCA, etc.) to identify vulnerabilities and configuration issues during the software development lifecycle.
  • Implementing and maintaining tools (such as Application Security Posture Management / ASPM) to centralize and deduplicate findings from multiple solutions and integrate reporting into software development workflows.
  • Integrating security tooling with large-scale enterprise CI/CD pipelines.
  • Building and managing tooling and processes to drive efficient DevSecOps operations.

Qualifications

  • Required: Bachelors Degree and 7 years experience OR Masters Degree and 6 years experience OR PhD and 2 years experience
  • Required: 4+ years of experience in security engineering and/or DevSecOps with a focus on security process automation
  • Required: 2+ years of experience implementing, administering, and supporting application security tooling such as SAST/DAST/IAST/SCA
  • Required: Demonstrated experience designing, building, and optimizing CI/CD pipelines (such as GitHub Actions and Azure DevOps) for large-scale enterprise environments, including integrating security testing solutions, for both on-premises and cloud environments to ensure secure, efficient, and compliant software delivery throughout the development lifecycle
  • Required: Ability to effectively communicate and document technical findings to both technical and non-technical stakeholders
  • Required: Experience automating workflows via programming languages such as Python
  • Preferred: Experience implementing custom or commercial solutions (such as Application Security Posture Management (ASPM) tooling) to automate DevSecOps processes, manage scan findings, and integrate with developer workflows
  • Preferred: Experience implementing and maintaining container security in enterprise environments, utilizing industry-leading tools and practices for vulnerability management, image scanning, access control, and runtime protection to safeguard applications throughout the container lifecycle.
  • Preferred: Experience administering Snyk in large enterprise environments
  • Preferred: Experience integrating security tooling and processes with Jfrog Artifactory or other artifact repositories
  • Preferred: Proven experience managing, storing, and distributing build artifacts at scale in enterprise environments, implementing best practices for artifact versioning, security, and traceability to support robust, efficient, and compliant software delivery pipelines
Apply now
Share this job