CPI Security

Technology

DevSecOpsEngineer

$135–185k ~AI est. Charlotte, North Carolina, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“DevSecOps Engineer at CPI Security. Skills: DevSecOps, CI/CD, Cloud security, Application security. Manage release engineering. Manage branching strategies”

What You'll Achieve.

Ship faster; Ship safer

Industry & Context.

Technology
Problems you'll solve

Troubleshoot pipeline issues; Root cause analysis

What They're Looking For.

Must Have

5+ years application delivery lifecycle, Experience with CI/CD pipelines, Experience with cloud-native services, Experience with AWS infrastructure IaC, Experience with Docker, Experience with ECS/EKS or AKS, Experience with SBOMs, Experience with signing, Experience with provenance

Nice to Have

Salesforce certifications, AWS certifications, Snyk experience preferred, Checkmarx experience preferred, SonarQube experience preferred

What You'll Do.

Manage release engineering

Manage branching strategies

Manage automated deployments

Manage metadata diffing

Manage sandbox seeding

Manage rollback playbooks

Design secure CI/CD pipelines

Operate secure CI/CD pipelines

Design cloud-native services

Operate cloud-native services

Identify technical pipeline issues

Resolve technical pipeline issues

Escalate pipeline items

Retain ownership of pipeline issues

Embed automated security gates

Embed container image scanning

Embed secrets detection

Support AI code quality gates

Extend AI code quality gates

Support Snyk code quality gates

Extend Snyk code quality gates

Architect AWS infrastructure IaC

Maintain AWS infrastructure IaC

Enforce security baselines

Containerize workloads

Orchestrate workloads

Harden images against CVEs

Harden images against supply-chain attacks

Partner for pipeline incident response

Partner for infrastructure security events

Automate security tool tuning

Troubleshoot pipelines

How You'll Work.

Team & Collaboration

Application engineering team; Other IT teammates; Security team

Communication Scope

Explain vulnerability; Explain regex

Full Job Description

Position Summary:  CPI is looking for a DevSecOps Engineer to join our application engineering team. This is not a traditional DevOps role. This role must recognize and imbed security across the entire application delivery lifecycle. This teammate drives efficiency into the engineering team’s work, while embedding controls, automation, and threat-aware thinking into every pipeline, deployment, and platform. You'll work at the intersection of Salesforce delivery, cloud infrastructure, and application security, partnering with engineers and security teammates to ship faster and safer. Key Responsibilities:  Manage release engineering, branching strategies, automated deployments, metadata diffing, sandbox seeding, and rollback playbooks (Salesforce/GearSet are currently core applications) Design and operate secure CI/CD pipelines and cloud-native services (Salesforce, AWS, Snowflake) Work in conjunction with other IT teammates to identify and resolve technical pipeline issues and escalate items while retaining ownership Embed automated security gates (SAST, DAST, SCA, IaC scanning), container image scanning, and secrets detection directly into developer workflows Support and extend AI and Snyk code quality gates Architect and maintain AWS infrastructure IaC (Terraform), with security baselines enforced via policy-as-code Containerize workloads with Docker, orchestrate via ECS/EKS (or AKS), and harden images against CVEs and supply-chain attacks (SBOMs, signing, provenance) Partner with security team for pipeline incident response and infrastructure security events and postmortems Continuously evaluate tool alerts and reduce alert fatigue through tuning and automation Support and troubleshoot all pipeline e. g. Snyk (preferrable), Checkmarx, SonarQube Container/image scanning, SBOM generation, and policy-as-code Soft Skills Strong communication — you can explain a vulnerability to an executive and a regex to a junior engineer in the same afternoon Pragmatic risk thinker

Free ATS check

Applying for this DevSecOps Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about CPI Security?

Real rants from real employees. Read before you apply.

Read Company Rants →