Job Title: DevSecOps Engineer Security Automation Specialist
Location: Blythewood SC 29016 4 days remote and 1 day on-site.
Duration: 12 Months (Possibility of Extension)
Interview Process: 1 Round Virtual/Online
This position will work 15 hours per week.
Position Overview:
The State of South Carolina is seeking a DevSecOps Engineer Security Automation Specialist to champion security automation and strengthen the overall cybersecurity posture across development and operations environments. The ideal candidate will have strong full-stack development experience hands-on security automation expertise and a deep understanding of DevSecOps principles and security frameworks such as NIST CIS and CISA.
This individual will collaborate with cross-functional teams to integrate security into every stage of the Software Development Lifecycle (SDLC) develop security tools and scripts monitor threats and support incident response operations.
Daily Duties / Responsibilities:
- Champion DevSecOps through Security Automation: Design implement and maintain automation scripts and tools to improve security processes such as data protection vulnerability scanning and user access control.
- Monitor and Analyze Security Events: Utilize SIEM tools to detect potential threats investigate alerts and assess risks in alignment with security frameworks (NIST CIS CISA).
- Support Secure Application Development: Partner with development teams to enforce secure coding practices perform code reviews and conduct threat modeling throughout the SDLC.
- Incident Response: Participate in incident investigations identify root causes mitigate impact and support recovery procedures.
- Documentation & Training: Develop and maintain documentation for security policies procedures and best practices; assist in training teams on security compliance.
- Provide On-Call Support: Offer after-hours assistance when necessary and perform other related duties as required.
Required Skills (Ranked by Importance):
- Exceptional communication and interpersonal skills with the ability to deliver clear documentation and user training.
- 5 years of hands-on experience with C# Python PowerShell and (optionally) Rust.
- Strong understanding of secure-by-design principles.
- At least 1 year of experience in automation leveraging AI ML and scripting for security operations.
- 3 years of understanding and application of SDLC and DevSecOps principles for integrating security into software delivery pipelines.
Preferred Skills (Ranked by Importance):
- 1 year of experience with SIEM tools (configuration tuning threat hunting and alert creation).
- 1 year of in-depth knowledge of security frameworks (NIST CIS CISA) and their implementation in hybrid environments.
- Strong understanding of incident response processes and practical implementation experience.
- Advanced knowledge of security controls in hybrid environments.
- 1 year of experience in data classification and Data Loss Prevention (DLP) configuration.
- 3 years of experience with cloud security including IAM data security and compliance.
Required Education:
- Bachelors degree in information technology systems Computer Science Cybersecurity or a related field.
- Equivalent relevant experience may substitute for education on a year-for-year basis.
Preferred Certifications:
Certifications are not required but candidates holding one or more of the following will be given preference:
- GCIH GIAC Certified Incident Handler
- CSIH Certified Computer Security Incident Handler
- ECIH EC-Council Certified Incident Handler
- CND EC-Council Certified Network Defender
- GCIP GIAC Critical Infrastructure Protection
- GDSA GIAC Defensible Security Architecture
Regards!
Raju Chidurala
Job Title: DevSecOps Engineer Security Automation Specialist Location: Blythewood SC 29016 4 days remote and 1 day on-site. Duration: 12 Months (Possibility of Extension) Interview Process: 1 Round Virtual/Online This position will work 15 hours per week. Position Overview: The State of...
Job Title: DevSecOps Engineer Security Automation Specialist
Location: Blythewood SC 29016 4 days remote and 1 day on-site.
Duration: 12 Months (Possibility of Extension)
Interview Process: 1 Round Virtual/Online
This position will work 15 hours per week.
Position Overview:
The State of South Carolina is seeking a DevSecOps Engineer Security Automation Specialist to champion security automation and strengthen the overall cybersecurity posture across development and operations environments. The ideal candidate will have strong full-stack development experience hands-on security automation expertise and a deep understanding of DevSecOps principles and security frameworks such as NIST CIS and CISA.
This individual will collaborate with cross-functional teams to integrate security into every stage of the Software Development Lifecycle (SDLC) develop security tools and scripts monitor threats and support incident response operations.
Daily Duties / Responsibilities:
- Champion DevSecOps through Security Automation: Design implement and maintain automation scripts and tools to improve security processes such as data protection vulnerability scanning and user access control.
- Monitor and Analyze Security Events: Utilize SIEM tools to detect potential threats investigate alerts and assess risks in alignment with security frameworks (NIST CIS CISA).
- Support Secure Application Development: Partner with development teams to enforce secure coding practices perform code reviews and conduct threat modeling throughout the SDLC.
- Incident Response: Participate in incident investigations identify root causes mitigate impact and support recovery procedures.
- Documentation & Training: Develop and maintain documentation for security policies procedures and best practices; assist in training teams on security compliance.
- Provide On-Call Support: Offer after-hours assistance when necessary and perform other related duties as required.
Required Skills (Ranked by Importance):
- Exceptional communication and interpersonal skills with the ability to deliver clear documentation and user training.
- 5 years of hands-on experience with C# Python PowerShell and (optionally) Rust.
- Strong understanding of secure-by-design principles.
- At least 1 year of experience in automation leveraging AI ML and scripting for security operations.
- 3 years of understanding and application of SDLC and DevSecOps principles for integrating security into software delivery pipelines.
Preferred Skills (Ranked by Importance):
- 1 year of experience with SIEM tools (configuration tuning threat hunting and alert creation).
- 1 year of in-depth knowledge of security frameworks (NIST CIS CISA) and their implementation in hybrid environments.
- Strong understanding of incident response processes and practical implementation experience.
- Advanced knowledge of security controls in hybrid environments.
- 1 year of experience in data classification and Data Loss Prevention (DLP) configuration.
- 3 years of experience with cloud security including IAM data security and compliance.
Required Education:
- Bachelors degree in information technology systems Computer Science Cybersecurity or a related field.
- Equivalent relevant experience may substitute for education on a year-for-year basis.
Preferred Certifications:
Certifications are not required but candidates holding one or more of the following will be given preference:
- GCIH GIAC Certified Incident Handler
- CSIH Certified Computer Security Incident Handler
- ECIH EC-Council Certified Incident Handler
- CND EC-Council Certified Network Defender
- GCIP GIAC Critical Infrastructure Protection
- GDSA GIAC Defensible Security Architecture
Regards!
Raju Chidurala
View more
View less