Pay: $48.00 - $50.00 per hour
Job Title: Security Engineer – DevSecOps
Location: 100% Remote
Employment Type: Contract
About the Opportunity:
ZipStaff is seeking an experienced Security Engineer to join the DevSecOps team at a large, leading healthcare and pharmacy services organization.
This is a hands-on operational role focused on application security, CI/CD pipeline security, vulnerability management, and developer enablement within a highly regulated healthcare environment. The ideal candidate is detail-oriented, strong in day-to-day security operations, and skilled at driving efficiency through automation.
What You’ll Do:
- Perform security operations across application security, infrastructure security, and CI/CD pipeline security.
- Ensure complete and consistent security scan coverage (SAST, SCA, Container, IaC, DAST, MAST) for assigned applications.
- Support developer onboarding to security tools and processes; provide clear guidance and training.
- Identify and automate recurring security tasks to reduce manual effort and improve efficiency.
- Manage vulnerabilities through accurate tagging, tracking, ownership workflows, and remediation support.
- Support compliance and risk management by tracking policy adherence and documenting exceptions.
- Handle operational tasks including ServiceNow tickets, daily updates, and participation in on-call rotations.
- Collaborate with engineering teams to improve secure coding practices and security awareness.
Required Qualifications:
- 3+ years of experience in Security Engineering, DevSecOps, or a related field.
- Hands-on experience with application security and CI/CD security tooling.
- Familiarity with SAST, SCA, Container scanning, IaC scanning, DAST, and MAST.
- Experience automating security workflows in a DevSecOps environment.
- Understanding of secure coding and modern development practices.
- Experience with operational processes (ticketing systems, on-call support, etc.).
- Strong communication skills with the ability to explain security concepts to both technical and non-technical audiences.
- Bachelor’s degree in a related field or equivalent practical experience.
- Must be legally authorized to work in the United States without sponsorship now or in the future.
Preferred Qualifications:
- Background in mobile application security.
- Knowledge of compliance frameworks (HIPAA, PCI, NIST) and data protection regulations (GDPR, CCPA).
- Experience providing developer coaching or security training.
- Familiarity with AWS, Azure, or GCP and containerization (Docker, Kubernetes).
- Relevant security certifications (CISSP, CISM, CEH, or similar).
About ZipStaff:
ZipStaff partners with leading organizations to connect skilled technology and security professionals with high-impact contract opportunities. We focus on quality matches and long-term success. Ref#PVN1
To apply, please submit your resume highlighting your DevSecOps, application security, and automation experience.
Benefits:
- 401(k).
- 401(k) matching.
- Paid time off.
- Referral program.
Application Question(s):
- Are you legally authorized to work in the United States?
- Will you now or in the future require employer sponsorship for employment authorization?
- Are you familiar with security scanning tools and practices such as SAST, SCA, Container scanning, IaC, DAST, or MAST? Please briefly list the ones you have used.
- Do you have experience automating security workflows or recurring security tasks in a DevSecOps environment?
Experience:
- Security Engineering or DevSecOps: 3 years (Required)
Work Location: Remote