Hospital for Special Surgery Logo

Hospital for Special Surgery

DevSecOps Engineer

Posted 4 Days Ago
Be an Early Applicant
In-Office
New York, NY
Senior level
In-Office
New York, NY
Senior level
The DevSecOps Engineer embeds security into software development, cloud infrastructure, CI/CD pipelines, and deployment processes. Responsibilities include implementing automated security controls, managing application and cloud vulnerability scanning, conducting threat modeling and design reviews, securing containers and Infrastructure as Code, developing security automation and reporting, tracking remediation, and supporting audits and compliance activities. The role partners extensively with development, infrastructure, cloud, architecture, cybersecurity, and data teams in a regulated healthcare environment.
The summary above was generated by AI

How you move is why we’re here. ®
Now more than ever.


Get back to what you need and love to do.
The possibilities are endless...
 
Now more than ever, our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximize the abundant opportunities for growth and success.
 
If this describes you then let’s talk!
 
HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report. As a recipient of the Magnet Award for Nursing Excellence, HSS was the first hospital in New York City to receive the distinguished designation. Whether you are early in your career or an expert in your field, you will find HSS an innovative, supportive and inclusive environment.


Working with colleagues who love what they do and are deeply committed to our Mission, you too can be part of our transformation across the enterprise.

Emp Status

Regular Full time

Work Shift

Compensation Range

What you will be doingPosition Activities
  • Partner with application development, data and analytics, infrastructure, cloud, architecture, and cybersecurity teams to embed secure-by-design principles into applications, services, pipelines, platforms, and infrastructure.
  • Design, implement, and maintain security controls within CI/CD pipelines, including automated testing, security gates, build and deployment checks, and risk-based exception workflows.
  • Manage and support application security capabilities such as Static Application Security Testing (SAST), Software Composition Analysis (SCA), secrets detection, dependency review, and code security scanning using tools such as Snyk, Wiz, and GitHub.
  • Review application designs, architecture patterns, data flows, APIs, cloud workloads, and integration points to identify security risks and recommend practical remediation or compensating controls.
  • Support threat modeling, secure code review, and security design reviews throughout the software development lifecycle.
  • Validate, prioritize, and track remediation of application, cloud, container, infrastructure, and development environment vulnerabilities using platforms such as Snyk, Wiz, Sysdig, Tenable, GitHub, and related tools.
  • Review cloud resources, Infrastructure as Code templates, container images, and deployment configurations against organizational policies, secure configuration baselines, and industry best practices.
  • Develop scripts, integrations, dashboards, and automated workflows that improve security testing, vulnerability management, reporting, evidence collection, and developer self-service.
  • Create metrics, reports, diagrams, runbooks, standards, and technical documentation that communicate application security posture, pipeline security effectiveness, vulnerability trends, and remediation status to technical and non-technical audiences.
  • Support audits, assessments, compliance activities, and control validation requests related to application security, cloud security, software supply chain security, and secure development practices.
  • Perform other related duties as assigned.
Minimum Qualifications
  • Bachelor’s degree in computer science, information technology, cybersecurity, software engineering, data engineering, or a related field, or equivalent experience.
  • Seven or more years of professional IT experience with five or more years in DevSecOps, application security, cloud security, software engineering, infrastructure engineering, security engineering, or a related technical role.
  • Working knowledge of secure software development lifecycle practices, application security principles, cloud security concepts, CI/CD security, and vulnerability management.
  • Experience with CI/CD platforms such as GitHub Actions, Azure DevOps, GitLab CI, Jenkins, or similar tools.
  • Experience with cloud platforms such as Microsoft Azure, AWS, or similar environments.
  • Familiarity with application security and software supply chain security capabilities such as SAST, SCA, secrets scanning, dependency analysis, container scanning, and Infrastructure as Code scanning.
  • Experience with scripting, automation, source control, code review processes, and development workflows using tools and languages such as Git, Python, PowerShell, Bash, JavaScript, or similar.
  • Ability to assess technical environments, identify security gaps, evaluate risk, and recommend practical remediation activities.
  • Strong written and verbal communication skills, including the ability to explain technical security concepts to developers, engineers, security teams, and non-technical stakeholders.
  • Excellent analytical, problem-solving, troubleshooting, organizational, and prioritization skills.
Preferred Experience
  • Experience with tools such as Snyk, Wiz, Sysdig, Tenable, GitHub Advanced Security, GitHub Dependabot, or similar security platforms.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform, CloudFormation, Bicep, Open Policy Agent, YAML, JSON, or similar.
  • Experience securing containers, Kubernetes, container registries, cloud-native workloads, APIs, secrets, and microservices architectures.
  • Experience building security automation, integrations, dashboards, reporting, and developer self-service capabilities.
  • Experience working with data and analytics platforms, data pipelines, APIs, reporting platforms, or related engineering teams.
  • Experience supporting audit readiness, compliance activities, control testing, or automated evidence collection in a regulated environment.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, OWASP Top 10, MITRE ATT&CK, HIPAA, HITRUST, ISO 27001, SOC 2, or similar.
  • Security, cloud, or software security certifications such as Security+, CSSLP, GWEB, GCSA, AWS Security Specialty, Azure Security Engineer, CCSP, CISSP, or similar.
  • Experience in healthcare or another highly regulated environment.
Skills and Abilities
  • Ability to connect security requirements to practical software development, cloud deployment, and engineering outcomes.
  • Ability to automate, standardize, and improve repeatable application security, cloud security, and DevSecOps processes.
  • Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
  • Ability to collaborate effectively with application development, data and analytics, infrastructure, cloud, architecture, cybersecurity, compliance, and business stakeholders.
  • Ability to produce professional-level documentation, reports, diagrams, runbooks, standards, and technical guidance.
  • Ability to think critically, make independent decisions, and recommend practical solutions.
  • Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
  • Ability to communicate application security risks, control gaps, remediation needs, and technical recommendations clearly to both technical and non-technical audiences.
  • Ability to support a positive cybersecurity culture by promoting secure development practices, accountability, and continuous improvement.

Non-Discrimination Policy
Hospital for Special Surgery is committed to providing high quality care and skilled, compassionate, reliable service to our community in a safe and healing environment. Consistent with this commitment, Hospital for Special Surgery provides care, admits, and treats patients and provides all services without regard to age, race, color, creed, ethnicity, religion, national origin, culture, language, physical or mental disability, socioeconomic status, veteran or military status, marital status, sex, sexual orientation, gender identity or expression, or any other basis prohibited by federal, state, or local law or by accreditation standards.

Similar Jobs

One Month Ago
Remote or Hybrid
USA
Senior level
Senior level
Software
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Top Skills: Api SecurityAquaAzureAzure DevopsAzure Key VaultAzure Security CenterBlack DuckBurp SuiteCheckmarxCi/CdDastGithub Advanced SecurityHashicorp VaultMendMicroservicesOwasp ZapPrisma CloudSastScaSecrets ManagementSemgrepSnykSonarqubeTerraformVeracodeWiz
One Month Ago
Remote or Hybrid
United States
121K-204K Annually
Senior level
121K-204K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead DevSecOps engineer on the Infrastructure and Platform Services team responsible for implementing and operating global SaaS infrastructure security. Duties include file integrity monitoring, automating audit evidence collection, hardening base images, securing containerized applications, release automation, incident response via on-call rotation, and collaborating with engineering and cybersecurity to meet compliance (FedRAMP, ISO, SOC) and remediation SLAs.
Top Skills: AWSAzureChefContainerizationFile Integrity MonitoringIdsIpsJenkinsPuppetPythonRubySIEMSirpTerraformWaf
26 Days Ago
In-Office
78K-176K Annually
Senior level
78K-176K Annually
Senior level
Information Technology
Develop and manage cloud-native infrastructure, virtual machines, networks, storage, servers, and CI/CD pipelines. Automate builds, testing, monitoring, releases, and infrastructure provisioning while troubleshooting pipeline issues. Collaborate with cloud architects and engineers, administer Linux systems, and improve DevOps and DevSecOps maturity across technical environments. The role supports modernization efforts for government and commercial clients and requires eligibility for Secret clearance.
Top Skills: AWSAzureBashBoto3C++Ci/CdDockerInfrastructure-As-CodeJavaJenkinsKubernetesLinuxPython

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account