Job Title : DevSecOps Engineer Security Automation Specialist
Location : Blythewood, SC 29016, 4 days remote and 1 day on-site.
Duration : 12 Months (Possibility of Extension)
Interview Process : 1 Round Virtual / Online
This position will work 15 hours per week.
Position Overview :
The State of South Carolina is seeking a DevSecOps Engineer Security Automation Specialist to champion security automation and strengthen the overall cybersecurity posture across development and operations environments. The ideal candidate will have strong full-stack development experience, hands-on security automation expertise, and a deep understanding of DevSecOps principles and security frameworks such as NIST, CIS, and CISA.
This individual will collaborate with cross-functional teams to integrate security into every stage of the Software Development Lifecycle (SDLC), develop security tools and scripts, monitor threats, and support incident response operations.
Daily Duties / Responsibilities :
- Champion DevSecOps through Security Automation : Design, implement, and maintain automation scripts and tools to improve security processes such as data protection, vulnerability scanning, and user access control.
- Monitor and Analyze Security Events : Utilize SIEM tools to detect potential threats, investigate alerts, and assess risks in alignment with security frameworks (NIST, CIS, CISA).
- Support Secure Application Development : Partner with development teams to enforce secure coding practices, perform code reviews, and conduct threat modeling throughout the SDLC.
- Incident Response : Participate in incident investigations, identify root causes, mitigate impact, and support recovery procedures.
- Documentation & Training : Develop and maintain documentation for security policies, procedures, and best practices; assist in training teams on security compliance.
- Provide On-Call Support : Offer after-hours assistance when necessary and perform other related duties as required.
Required Skills (Ranked by Importance) :
Exceptional communication and interpersonal skills, with the ability to deliver clear documentation and user training.5+ years of hands-on experience with C#, Python, PowerShell, and (optionally) Rust.Strong understanding of secure-by-design principles.At least 1 year of experience in automation, leveraging AI, ML, and scripting for security operations.3+ years of understanding and application of SDLC and DevSecOps principles for integrating security into software delivery pipelines.Preferred Skills (Ranked by Importance) :
1+ year of experience with SIEM tools (configuration, tuning, threat hunting, and alert creation).1+ year of in-depth knowledge of security frameworks (NIST, CIS, CISA) and their implementation in hybrid environments.Strong understanding of incident response processes and practical implementation experience.Advanced knowledge of security controls in hybrid environments.1+ year of experience in data classification and Data Loss Prevention (DLP) configuration.3+ years of experience with cloud security, including IAM, data security, and compliance.Required Education :
Bachelor's degree in information technology systems, Computer Science, Cybersecurity, or a related field.Equivalent relevant experience may substitute for education on a year-for-year basis.Preferred Certifications :
Certifications are not required, but candidates holding one or more of the following will be given preference :
GCIH GIAC Certified Incident HandlerCSIH Certified Computer Security Incident HandlerECIH EC-Council Certified Incident HandlerCND EC-Council Certified Network DefenderGCIP GIAC Critical Infrastructure ProtectionGDSA GIAC Defensible Security ArchitectureRegards!
Raju Chidurala
216-343-3435
rajuc@devfi.com