DevSecOps Security Engineer
Mastercam · United States
Skills in this posting
The posting
Your Role at a Glance
The DevSecOps Security Engineer is responsible for securing and governing Mastercam 's cloud-native application platforms, AI-enabled solutions, and supporting infrastructure. This role integrates security throughout the software development lifecycle, including CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads.
Working closely with Software Engineering, Platform Engineering, Infrastructure, and IT Operations teams, the DevSecOps Security Engineer designs, implements, and maintains security controls that protect applications, infrastructure, data, and AI services while supporting the efficient delivery of business solutions. The role helps establish security standards, improve risk management practices, and promote secure-by-design principles across development and operational processes.
This position requires expertise in cloud-native technologies, Kubernetes, container security, CI/CD environments, and modern application security practices, along with the ability to contribute to emerging AI and platform security initiatives. The role serves as a key technical resource in advancing the organization's security posture while enabling innovation and operational scalability.
How You’ll Drive Success
Platform Security
Secure Kubernetes-based platforms and containerized workloads.
Implement and maintain Kubernetes security controls including RBAC, Network Policies, Pod Security Standards, and namespace segmentation.
Perform security reviews of platform architecture and application deployments.
Develop infrastructure hardening standards and security baselines.
DevSecOps
Integrate security controls into CI/CD pipelines.
Implement automated vulnerability scanning, code analysis, and compliance checks.
Establish secure software supply chain processes.
Partner with development teams to remediate vulnerabilities and improve secure coding practices.
Develop and maintain security guardrails within GitOps workflows.
Identity & Access Management
Secure authentication and authorization systems.
Implement least-privilege access controls across applications and infrastructure.
Support identity federation, Single Sign-On (SSO), OAuth2, OpenID Connect, and Multi-Factor Authentication (MFA).
Review systems for access governance and privileged access risks.
Secret Management
Implement secure management of secrets, certificates, encryption keys, and service credentials.
Support automated secret rotation and certificate lifecycle management.
Ensure secure application integration with centralized secrets management platforms.
API & Service Security
Secure API gateways and service-to-service communications.
Review API implementations against OWASP API Security standards.
Implement authentication, authorization, rate limiting, and API threat protection controls.
Support Zero Trust networking initiatives.
Security Monitoring & Detection
Create dashboards and alerts for security events.
Develop security metrics and monitoring capabilities.
Collaborate with operations teams during security investigations and incident response activities.
Analyze platform telemetry and audit logs to identify threats and control gaps.
AI & Emerging Technology Security
Support security reviews for AI and machine learning workloads.
Assist with implementing controls to protect against prompt injection, sensitive data exposure, and model misuse.
Participate in AI governance and risk assessment activities.
Evaluate emerging risks associated with Large Language Models (LLMs), vector databases, and AI platforms.
The Talents We’re Seeking
Education & Experience
Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required; equivalent combinations of education, military service, and relevant professional experience will also be considered.
4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering.
1+ year of hands-on experience supporting Kubernetes or containerized application environments.
Experience securing cloud-native applications and services.
Experience implementing vulnerability management and application security programs.
Experience working with software development teams and CI/CD pipelines.
Experience supporting cloud environments such as AWS, Azure, or Google Cloud.
Required Skills
Kubernetes
Knowledge of
Kubernetes architecture
Pods, Deployments, Services, and Ingresses
RBAC
Network Policies
Container security
Workload isolation
Cluster security fundamentals
Containers
Experience with
Docker
Container image security
Image scanning
Vulnerability remediation
Secure image lifecycle management
DevSecOps
Experience with
CI/CD pipelines
Source code management platforms
Git workflows
Automation and scripting
DAST
Dependency scanning
Secret scanning
Infrastructure-as-Code security
Identity Management
Knowledge of
OAuth2
OpenID Connect
SAML
MFA
Role-Based Access Control
Security Operations
Experience with
Vulnerability management
Threat detection
Security monitoring
Incident response support
Risk assessments
Scripting
Ability to automate security processes using
Python
Bash
PowerShell
Preferred Skills
Experience with any of the following technologies is highly desirable:
Platform Technologies
Kubernetes
Istio
FluxCD
The PivotHop read
- What a security engineer actually earnsmedian, seniority, by country
- What security engineers do insteadevery measured route out
- Penetration Tester → Security Engineer51% readiness
- All open security engineer rolesthe full board
Where these skills also reach
- 71 open penetration tester roles78% readiness from security engineer
- 268 open network engineer roles62% readiness from security engineer
- 503 open systems administrator roles52% readiness from security engineer
- 1596 open systems engineer roles51% readiness from security engineer
More security engineer roles
Cybersecurity Analyst at SalienseUnited States · Remote$70k–$75kTodayApply- Senior Infrastructure & Cybersecurity Engineer (UK) at A-GasUnited Kingdom · RemoteTodayApply
- Security Engineer III , Vulnerability Management at Direct employerIndia - GurgaonTodayUnlock
- Senior Security Engineer at DdomeGermany1d agoApply
Staff Product Security Engineer at DashlaneParis1d agoApply
Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.