ZipStaff Inc.

Security Engineer – DevSecOps

RemoteUnited StatesContract
$48 - $50 hourly
About the Job
Pay: $48.00 - $50.00 per hour
Job Title: Security Engineer – DevSecOps
Location: 100% Remote
Employment Type: Contract
About the Opportunity:
ZipStaff is seeking an experienced Security Engineer to join the DevSecOps team at a large, leading healthcare and pharmacy services organization.

This is a hands-on operational role focused on application security, CI/CD pipeline security, vulnerability management, and developer enablement within a highly regulated healthcare environment. The ideal candidate is detail-oriented, strong in day-to-day security operations, and skilled at driving efficiency through automation.
What You’ll Do:
  • Perform security operations across application security, infrastructure security, and CI/CD pipeline security.
  • Ensure complete and consistent security scan coverage (SAST, SCA, Container, IaC, DAST, MAST) for assigned applications.
  • Support developer onboarding to security tools and processes; provide clear guidance and training.
  • Identify and automate recurring security tasks to reduce manual effort and improve efficiency.
  • Manage vulnerabilities through accurate tagging, tracking, ownership workflows, and remediation support.
  • Support compliance and risk management by tracking policy adherence and documenting exceptions.
  • Handle operational tasks including ServiceNow tickets, daily updates, and participation in on-call rotations.
  • Collaborate with engineering teams to improve secure coding practices and security awareness.
Required Qualifications:
  • 3+ years of experience in Security Engineering, DevSecOps, or a related field.
  • Hands-on experience with application security and CI/CD security tooling.
  • Familiarity with SAST, SCA, Container scanning, IaC scanning, DAST, and MAST.
  • Experience automating security workflows in a DevSecOps environment.
  • Understanding of secure coding and modern development practices.
  • Experience with operational processes (ticketing systems, on-call support, etc.).
  • Strong communication skills with the ability to explain security concepts to both technical and non-technical audiences.
  • Bachelor’s degree in a related field or equivalent practical experience.
  • Must be legally authorized to work in the United States without sponsorship now or in the future.
Preferred Qualifications:
  • Background in mobile application security.
  • Knowledge of compliance frameworks (HIPAA, PCI, NIST) and data protection regulations (GDPR, CCPA).
  • Experience providing developer coaching or security training.
  • Familiarity with AWS, Azure, or GCP and containerization (Docker, Kubernetes).
  • Relevant security certifications (CISSP, CISM, CEH, or similar).
About ZipStaff:
ZipStaff partners with leading organizations to connect skilled technology and security professionals with high-impact contract opportunities. We focus on quality matches and long-term success. Ref#PVN1
To apply, please submit your resume highlighting your DevSecOps, application security, and automation experience.

Benefits:
  • 401(k).
  • 401(k) matching.
  • Paid time off.
  • Referral program.


Application Question(s):
  • Are you legally authorized to work in the United States?
  • Will you now or in the future require employer sponsorship for employment authorization?
  • Are you familiar with security scanning tools and practices such as SAST, SCA, Container scanning, IaC, DAST, or MAST? Please briefly list the ones you have used.
  • Do you have experience automating security workflows or recurring security tasks in a DevSecOps environment?

Experience:
  • Security Engineering or DevSecOps: 3 years (Required)


Work Location: Remote