About the Role
We are seeking a DevSecOps Engineer to support and scale the organization’s citizen development initiatives. This role works closely with non-traditional developers to transition experimental applications into secure, supportable, and production-ready solutions, acting as the connective tissue between business-driven innovation and enterprise engineering standards.
Responsibilities
- Partner directly with citizen developers to refactor, harden, and productionize applications built with Python, JavaScript, and low-code/automation platforms.
- Guide developers on repository structure, branching strategies, pull requests, and versioning.
- Translate loosely defined or experimental solutions into maintainable, supportable codebases.
- Establish, document, and enforce SDLC best practices including source control standards, CI/CD pipelines for build, test, and deployment, and environment separation.
- Create and maintain reusable DevSecOps “golden paths” including standardized pipeline templates, deployment frameworks, and secure configuration and secrets management patterns.
- Perform code reviews with emphasis on security vulnerabilities, error handling, resilience, and maintainability.
- Integrate and operate automated security tooling: SAST, dependency/vulnerability scanning, and secrets detection.
- Work closely with security teams to ensure applications meet enterprise requirements without unnecessary friction.
- Support deployments through controlled CI/CD pipelines, eliminating manual or ad-hoc release processes.
- Troubleshoot pipeline failures, deployment issues, configuration problems, and environment-specific bugs.
- Assist with incident response for citizen-developed applications running in production.
- Help remediate security findings and technical debt discovered post-deployment.
- Document patterns, standards, and common fixes to reduce repeated friction.
- Perform other related duties as assigned.
Requirements
- Advanced proficiency with Git-based source control and collaborative workflows.
- Advanced hands-on experience with Azure DevOps (Repos, Pipelines, Boards).
- Intermediate familiarity with Microsoft Azure services (App Services, Functions, Container Apps, or similar).
- Intermediate knowledge of application security fundamentals: secrets management, dependency risk, and secure configuration.
- Intermediate ability to review and reason about Python and/or JavaScript code.
- Advanced analytical, troubleshooting, and communication skills.
- Structured thinking; comfortable bringing order to unstructured or rapidly developed codebases.
- Enablement mindset with a bias toward pragmatic solutions; meets developers where they are.
- Demonstrated experience implementing and operating CI/CD pipelines.
- Experience supporting citizen development or low-code platforms preferred.
- Familiarity with Infrastructure as Code tools (Terraform, Bicep, or similar) preferred.
- Experience with containerization technologies (Docker) preferred.
- Exposure to security tooling such as Microsoft Defender, Snyk, or equivalent preferred.
- 3+ years of experience in DevOps, DevSecOps, or related engineering roles.
Skills
- Python
- JavaScript
- Low-code/automation platforms
- Git
- Azure DevOps
- Microsoft Azure services
- Application security fundamentals
- CI/CD pipelines
- Infrastructure as Code
- Containerization technologies
- Microsoft Defender
- Snyk
Location
- U.S. office locations
- Remote locations
Work Type
- Full-time
- Exempt
- Hybrid
- Remote
Experience Level
- 3+ years of experience
Education Level
- Bachelor's Degree in Computer Science or a related field preferred
Salary/Compensations
- $126,000 - $189,000
Benefits
- Healthcare
- Life Insurance
- Health Savings Accounts
- Flexible Spending Accounts
- Wellbeing
- Discretionary bonus
About the Company
- At Fenwick, we believe that our partners and employees are our most important asset. Helping you and your families achieve and maintain good health - physical, emotional, and financial - is the reason we offer a comprehensive benefit program.
