Principal DevSecOps Engineer
Indexed description
The platform ingests and processes real-time telemetry from connected building systems using cloud-native technologies hosted in Microsoft Azure. It provides the foundation for analytics, digital services, applications, and customer integrations across Schneider Electric's building ecosystem.
Role Overview
We are seeking a Principal DevSecOps Engineer to own the implementation, operation, and continuous improvement of the security posture of the EcoStruxure Building Data Platform.
This role serves as the hands-on security leader embedded within the engineering organization. The successful candidate will lead security tooling, security automation, vulnerability remediation coordination, software supply chain security, Secure SDLC implementation, release security readiness, and cloud security enablement across the platform.
The Principal DevSecOps Engineer is accountable for the implementation and operational execution of product security controls.
This role works closely with:
- Security Advisor
- Principal Systems Engineer
- Engineering Technical Leads
- Principal Cloud Operations & Infrastructure Engineer
- Product Owners
- Schneider Electric Product Security
- 24x7 Operation Support Team
In this role, you are responsible for implementation, execution, automation, evidence generation, and remediation coordination.
Key Responsibilities
Security Posture Management
- Own the operational security posture of the EcoStruxure Building Data Platform.
- Establish and maintain security baselines across applications, cloud services, containers, APIs, CI/CD systems, and supporting platform components.
- Continuously assess security maturity and identify opportunities for improvement.
- Implement security controls and automation that reduce platform risk.
- Report operational security health, remediation status, and security trends.
- Operate vulnerability management activities in accordance with Schneider Electric CPCERT processes and security requirements.
- Perform technical triage of findings from SonarQube, Black Duck Binary Analysis (BDBA), penetration tests, container security scans, dependency analysis tools, and cloud security assessments.
- Assess technical applicability of vulnerabilities and identify remediation approaches for affected platform components.
- Partner with the Security Advisor on vulnerability prioritization, risk evaluation, exception reviews, and remediation timelines.
- Lead remediation planning and coordinate execution with Technical Leads and engineering teams.
- Track remediation progress, closure status, security debt metrics, and vulnerability trends.
- Support vulnerability reporting and evidence requirements for security reviews, audits, and compliance activities.
- Partner with the Security Advisor to implement Secure SDLC requirements across the EcoStruxure Building Data Platform.
- Embed automated security controls and validation activities into GitHub Actions workflows and deployment pipelines.
- Implement approved security gates and release readiness checks within software delivery processes.
- Generate and maintain security evidence required for product release reviews and compliance activities.
- Support developer enablement through practical guidance, tooling, templates, and automation that promote secure engineering practices.
- Improve security visibility within the software development lifecycle through automation and metrics.
- Own Software Bill of Materials (SBOM) generation and management processes.
- Establish software supply chain security controls across development and release processes.
- Manage dependency analysis, artifact validation, and binary scanning programs.
- Ensure container image integrity and security compliance.
- Drive adoption of software provenance and artifact attestation practices.
- SonarQube
- Black Duck Binary Analysis (BDBA)
- SBOM Studio
- GitHub Security
- Secret scanning solutions
- Container security platforms
- Dependency analysis solutions
- Security reporting and dashboarding tools
Security Operations & Compliance Enablement
- Implement approved security requirements through engineering controls, automation, and security tooling.
- Partner with the Security Advisor, Product Owners, and Technical Leads to plan and execute security remediation initiatives.
- Support penetration testing, CPCERT reviews, compliance activities, and security assessments.
- Coordinate operational activities supporting release security reviews.
- Maintain security dashboards, remediation reporting, and evidence repositories.
- Drive continuous improvement of security tooling, visibility, operational processes, and security engineering practices.
- Azure Kubernetes Service (AKS)
- Azure Container Registry (ACR)
- Azure Entra ID
- Azure Key Vault
- Workload identities
- Role-Based Access Control (RBAC)
- Container platforms
- Network security controls
- Cloud platform configurations
Cross-Functional Collaboration
- Work closely with Technical Leads to integrate security practices into product development.
- Partner with the Principal Systems Engineer on security-related architecture decisions and standards.
- Collaborate with the Security Advisor on risk reviews, security findings, mitigation strategies, and compliance activities.
- Support 24x7 operations teams with security operational procedures, monitoring guidance, and escalation processes.
- Act as the primary security implementation lead within the EcoStruxure Building Data Platform organization.
- Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Computer Engineering, or a related technical discipline.
- Equivalent combination of education, professional training, and relevant industry experience may be considered.
- 8+ years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, software engineering, or related security-focused roles.
- 3+ years of experience supporting Azure-based cloud-native platforms.
- Experience owning or leading security implementation activities within a software product organization.
- Experience implementing Secure Software Development Lifecycle (Secure SDLC) practices within engineering teams.
- Experience driving vulnerability management and remediation programs across multiple product or engineering teams.
- Experience performing vulnerability assessment, technical triage, remediation planning, and risk reduction activities.
- Experience working with application security testing, dependency analysis, software composition analysis, and container security tools.
- Experience implementing software supply chain security controls and Software Bill of Materials (SBOM) processes.
- Experience integrating security controls, validation, and automation into CI/CD pipelines and software delivery workflows.
- Experience supporting release security reviews, compliance activities, audits, penetration testing, or security assessments.
- Experience securing cloud-native platforms, containerized workloads, APIs, and Kubernetes-based environments.
- Experience working with identity and access management, secrets management, and role-based access control models.
- Experience generating security evidence, remediation reporting, and security metrics for leadership and compliance stakeholders.
- Experience working within Agile software delivery environments.
- Experience influencing engineering teams and driving security improvements without direct organizational authority.
- Experience collaborating effectively with software engineering, architecture, operations, security, and product management teams.
- Experience supporting SaaS, IoT, telemetry, or real-time data platforms.
- Experience supporting platforms operating under 24x7 availability requirements.
- Experience supporting Azure-based data platforms.
- Experience working within globally distributed engineering organizations.
- Experience supporting external audits, penetration testing programs, and compliance initiatives.
- Experience working within regulated enterprise environments.
- Experience supporting ISO 27001-aligned environments.
- Experience applying IEC 62443 security principles within industrial or operational technology environments.
- Experience supporting SOC 2 readiness programs or equivalent security control frameworks.
- Experience implementing security programs aligned with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), or similar industry frameworks.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500).
- Microsoft Certified: Azure DevOps Engineer Expert (AZ-400).
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
- Certified Secure Software Lifecycle Professional (CSSLP).
- Certified Kubernetes Security Specialist (CKS).
- GIAC Cloud Security Automation (GCSA).
- Reduction of security debt and vulnerability backlog.
- Timely remediation of critical and high-risk vulnerabilities.
- Effective operation and adoption of SonarQube, BDBA, SBOM, and security automation tooling.
- Improved Secure SDLC adoption across engineering teams.
- High-quality and audit-ready release security evidence.
- Successful support of CPCERT, penetration testing, and security review activities.
- Reduction in recurring security findings.
- Improved visibility into platform security posture through actionable metrics and reporting.
- Sustainable alignment with Schneider Electric security requirements and engineering standards.
- Lead transformative projects that protect critical infrastructure and make a measurable impact
- Work with cutting-edge technologies and solve complex cybersecurity challenges across diverse industries
- Collaborative culture that values technical excellence, innovation, and continuous professional development
- Access to certifications, training, and resources that accelerate your career growth
At Schneider, we believe that every employee is a talent who deserves equal opportunities. This means you matter. Every individual needs to feel valued, supported, and treated fairly to do their best work.
Our Total Rewards is our way of saying: “We see you. We value you”. It’s more than just pay and benefits- it’s a meaningful investment in you. It is designed for you to perform, grow, feel safe, and elevate your potential to shine as an impact maker.
For this U.S. based position, the expected pay range is USD 142,400 - USD 213,600 per year. This pay range includes base pay and short-term incentives. The compensation range for this full-time position applies to candidates located within the United States. Our pay ranges are determined by reviewing roles of similar responsibility and level. Within the pay range, individual pay is determined by several factors including performance, knowledge, job-related skills, experience, and relevant education or training.
Schneider Electric is there when it matters most to you
Our Total Rewards package outlines all the benefits and support you’ll enjoy as part of the Schneider Electric team:
Care for Yourself and Your Family. We ensure you feel secure with benefits that help you and your family thrive: medical (with member reward points), dental, vision, and basic life insurance, Benefit Bucks, flexible work arrangements, paid family leaves, well-being programs, 12 holidays per year, and 15 days of paid time off per year.
Invest and Plan Your Future. We help you plan and invest for the future with competitive pay and programs including base salary, incentives, company share ownership, and 401(k) with match.
Grow Your Skills and Career. We support development through performance discussions, global opportunities, the Schneider Career Hub, and learning platforms like Coursera.
Team Up in the Workplace. We encourage collaboration, recognition, sharing your voice, and an inclusive workplace.
Support Your Community. We make a difference through volunteer leave, programs with the Schneider Electric Foundation, youth education initiatives, and military leave benefits.
If you believe this job posting is not compliant with applicable state pay transparency laws in the U.S., please notify the Company as soon as possible upon discovery by completing this form Job Posting Compliance Form.
Looking to make an IMPACT with your career?
When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values – Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork – starts with us.
IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world.
We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one.
Become an IMPACT Maker with Schneider Electric – apply today!
€40 billion global revenue
+9% organic growth
150 000+ employees in 100+ countries
You must submit an online application to be considered for any position with us. This position will be posted until filled.
Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and ‘inclusion’ is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do.
At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here
Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search