CPI Security
Technology
DevSecOpsEngineer
Neural analysis suggests this role is
optimal for Mid+ candidates.
“DevSecOps Engineer at CPI Security. Skills: DevSecOps, CI/CD, Cloud security, Application security. Manage release engineering. Manage branching strategies”
What You'll Achieve.
Ship faster; Ship safer
Industry & Context.
Troubleshoot pipeline issues; Root cause analysis
What They're Looking For.
Must Have
5+ years application delivery lifecycle, Experience with CI/CD pipelines, Experience with cloud-native services, Experience with AWS infrastructure IaC, Experience with Docker, Experience with ECS/EKS or AKS, Experience with SBOMs, Experience with signing, Experience with provenance
Nice to Have
Salesforce certifications, AWS certifications, Snyk experience preferred, Checkmarx experience preferred, SonarQube experience preferred
What You'll Do.
Manage release engineering
Manage branching strategies
Manage automated deployments
Manage metadata diffing
Manage sandbox seeding
Manage rollback playbooks
Design secure CI/CD pipelines
Operate secure CI/CD pipelines
Design cloud-native services
Operate cloud-native services
Identify technical pipeline issues
Resolve technical pipeline issues
Escalate pipeline items
Retain ownership of pipeline issues
Embed automated security gates
Embed container image scanning
Embed secrets detection
Support AI code quality gates
Extend AI code quality gates
Support Snyk code quality gates
Extend Snyk code quality gates
Architect AWS infrastructure IaC
Maintain AWS infrastructure IaC
Enforce security baselines
Containerize workloads
Orchestrate workloads
Harden images against CVEs
Harden images against supply-chain attacks
Partner for pipeline incident response
Partner for infrastructure security events
Automate security tool tuning
Troubleshoot pipelines
How You'll Work.
Team & Collaboration
Application engineering team; Other IT teammates; Security team
Communication Scope
Explain vulnerability; Explain regex
Full Job Description
Position Summary: CPI is looking for a DevSecOps Engineer to join our application engineering team. This is not a traditional DevOps role. This role must recognize and imbed security across the entire application delivery lifecycle. This teammate drives efficiency into the engineering team’s work, while embedding controls, automation, and threat-aware thinking into every pipeline, deployment, and platform. You'll work at the intersection of Salesforce delivery, cloud infrastructure, and application security, partnering with engineers and security teammates to ship faster and safer. Key Responsibilities: Manage release engineering, branching strategies, automated deployments, metadata diffing, sandbox seeding, and rollback playbooks (Salesforce/GearSet are currently core applications) Design and operate secure CI/CD pipelines and cloud-native services (Salesforce, AWS, Snowflake) Work in conjunction with other IT teammates to identify and resolve technical pipeline issues and escalate items while retaining ownership Embed automated security gates (SAST, DAST, SCA, IaC scanning), container image scanning, and secrets detection directly into developer workflows Support and extend AI and Snyk code quality gates Architect and maintain AWS infrastructure IaC (Terraform), with security baselines enforced via policy-as-code Containerize workloads with Docker, orchestrate via ECS/EKS (or AKS), and harden images against CVEs and supply-chain attacks (SBOMs, signing, provenance) Partner with security team for pipeline incident response and infrastructure security events and postmortems Continuously evaluate tool alerts and reduce alert fatigue through tuning and automation Support and troubleshoot all pipeline e. g. Snyk (preferrable), Checkmarx, SonarQube Container/image scanning, SBOM generation, and policy-as-code Soft Skills Strong communication — you can explain a vulnerability to an executive and a regex to a junior engineer in the same afternoon Pragmatic risk thinker
Applying for this DevSecOps Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about CPI Security?
Real rants from real employees. Read before you apply.