DevSecOps Engineer - Information Security
Indexed description
Please note that per our policy on hybrid/virtual work, candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment, unless an accommodation is granted as required by law.
PLEASE NOTE: This position is not eligible for current or future visa sponsorship.
The DevSecOps Engineer - Information Security develops, recommends, and implements enterprise information security policies, technical standards, guidelines, procedures, and other elements of an infrastructure necessary to support information security in compliance with established company policies, regulatory requirements, and generally accepted information security controls.
You will lead the design and integration of DevSecOps, Application Security and Vulnerability Management capabilities across our enterprise. This individual contributor role will drive secure-by-design practices across CI/CD pipelines, cloud-native platforms, and modern development workflows—including AI-assisted coding environments. You will partner closely with application engineering, cloud, and platform teams to embed scalable, automated security controls that reduce risk while enabling developer velocity.
How You Will Make An Impact
- Define and implement secure SDLC practices, including automated testing, threat modeling, and secure coding standards
- Drive vulnerability management strategy, including risk-based prioritization and integration into developer workflows
- Lead development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations
- Lead the development of requirements, system architecture, and software design of security products and services
- Lead system and network architecture support for information and network security technologies
- Serve as a technical advisor and escalation point for complex security and integration challenges
- Develop security incident response plans and strategies
- Provide trouble resolution and serve as point of technical escalation on complex problems
- Act as a subject matter expert among peers, with manager and senior management
- Lead the design and implementation of DevSecOps solutions integrated into CI/CD pipelines (GitHub, GitLab, Jenkins)
- Integrate and tune AppSec tools (SAST, DAST, SCA, container scanning) for scalable pipeline adoption
- Own and optimize CNAPP platforms (e.g., Wiz, Prisma Cloud) to improve cloud security posture and workload protection
- Partner with engineering teams to reduce vulnerability backlog and MTTR
- Define KPIs and reporting for security posture, pipeline coverage, and risk reduction
- Establish guardrails for AI-generated code security, including validation of outputs and mitigation of risks such as insecure code patterns and data exposure
- Embed security controls into AI-enabled applications and APIs, addressing emerging risks (e.g., prompt injection, model misuse)
- Create presentations and seek IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise
Preferred Skills, Experiences And Competencies
- Vulnerability management and risk prioritization
- Strong knowledge of Application Security (SAST, DAST, SCA, API security) & Cloud Security (AWS, Azure, or GCP), Containers & Kubernetes security
- Experience in DevSecOps (Harness pipelines), Application Security, Cloud Security, or related fields
- Hands-on experience integrating security into CI/CD pipelines at scale
- Experience with CNAPP platforms (e.g., Wiz, Prisma Cloud)
- Experience with tools such as Snyk, Checkmarx, Veracode, SonarQube
- Experience with JFrog Artifactory, Xray, and Curation
- Experience securing AI/LLM-enabled applications or AI-assisted development workflows
- Familiarity with AI security risks (e.g., OWASP Top 10 for LLMs, prompt injection, data leakage)
- Security certifications (e.g., CISSP, CCSP, CSSLP) preferred
- Strong understanding of DevOps and Agile practices
Who We Are
Elevance Health is a health company dedicated to improving lives and communities – and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry, looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.
How We Work
At Elevance Health, we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy, power our business outcomes and drive our shared success - for our consumers, our associates, our communities and our business.
We offer a range of market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.
Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager, associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.
The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated, your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal, state and local laws.
Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age, citizenship status, color, creed, disability, ethnicity, genetic information, gender (including gender identity and gender expression), marital status, national origin, race, religion, sex, sexual orientation, veteran status or any other status or condition protected by applicable federal, state, or local laws. Applicants who require accommodation to participate in the job application process may contact [email protected] for assistance.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state, and local laws, including, but not limited to, the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.
Prospective employees required to be screened under Florida law should review the education and awareness resources at HB531 | Florida Agency for Health Care Administration.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search