Avatar for IMR Soft
IMR Soft
Actively Hiring
  • B2B
  • Growth Stage
    Expanding market presence

Devsecops Engineer with Python

Posted: 5 days ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
SQL
JSON
Jenkins
Cron
Docker
CVE
Llm
Airflow
CVSS
GitHub Actions
Snyk
CodeQL
Jfrog Artifactory
Semgrep
Trivy
Prompt Engineering
JFrog Xray
Github Advanced Security
Dependabot
GitHub PR Workflows

About the job

Position: Devsecops Engineer with Python

Location: NYC, NY (3 days onsite is must )

Duration: 12 Months

Role Summary

Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings — cutting manual triage and patch time firm-wide.

Core Technical Skills

  • Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue
  • Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases
  • Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)
  • AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents
  • CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron
  • Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends

Supporting Skills

  • Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)
  • Risk-based prioritization beyond raw CVSS scores
  • Semantic versioning awareness for safe auto-upgrades
  • Testing discipline — regression validation before auto-merge

Communication Skills

  • Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)
  • Writing clear status emails on scan coverage and outstanding critical items
  • Building the business case (time saved, risk reduced) for non-technical stakeholders

Continuous Learning

  • Tracking emerging agentic/AI remediation tools and evaluating fit before firm-wide adoption

Skill Levels

  • Expert Level resource: 8 to 10 or more total experience out of which at least three years of experience in the relevant AI driven automation for code scanning and remediation matching the above skills
  • Advanced level: Total 6 – 8 years of total experience out of which at least three years of experience in the relevant AI driven automation for code scanning and remediation matching the above skills

Similar Jobs

Scale AI company logo
Scale AI
Accelerate the development of AI applications
Pulse company logo
Pulse
Transforming healthcare by creating remarkable experiences for doctors and patients
Kalepa company logo
Kalepa
We're on a mission to transform the $7 trillion insurance industry
Yuzu Health company logo
Yuzu Health
Create your own health plan
Merciv company logo
Merciv
The Future of Enterprise Intelligence. Read your data’s past. Write your company’s future