Cyber Security Analyst PSEG LI -DevSecOps Engineer

LIPAPRDTown of Oyster Bay, NY
$93,600 - $148,200Hybrid

About The Position

We are seeking an experienced DevSecOps Engineer who can build, integrate, and operationalize security within our DevOps processes and CI/CD pipelines. This role will focus on embedding security controls into the software development lifecycle, securing cloud infrastructure, and ensuring that applications and APIs meet enterprise security and compliance requirements. Using a modern technology stack and agile approach, you will work closely with development, infrastructure, and cybersecurity teams to integrate automated security testing, vulnerability management, and compliance validation across our development and cloud environments.

Requirements

  • BS degree or higher with 4+ years of professional experience in DevOps Engineering or DevSecOps Engineering. In place of a degree, candidates with 8+ years of hands-on experience working with DevSecOps tooling, methodologies, and processes will be considered.
  • CI/CD Pipeline Security: Proven track record building, securing, and maintaining Continuous Integration and Continuous Deployment (CI/CD) pipelines with integrated security controls.
  • CI/CD Platforms: Proficiency with major CI/CD platforms (e.g., Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps).
  • Application Security Testing: Direct experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.
  • API Security: Demonstrated ability implementing API security solutions and protecting application endpoints.
  • Container & Artifact Security: Expertise in container security (e.g., Docker, Kubernetes) and managing secure artifact repositories (e.g., JFrog Artifactory, Nexus).
  • Cloud Security: Deep background working with public cloud platforms (AWS, Azure, or GCP) and securing cloud infrastructure.
  • CSPM: Familiarity with Cloud Security Posture Management (CSPM) tools (e.g., Wiz, Prisma Cloud, Orca Security).
  • Core Competencies: Strong professional communication, cross-functional collaboration, and team-building skills.

Nice To Haves

  • Prior work with Infrastructure as Code (IaC) tools, such as Terraform, CloudFormation, or Ansible.
  • Ability to write scripts and automation workflows using Python, Bash, or similar programming languages.
  • Familiarity with automated code scanning, dependency scanning, and secret detection / secret management tools.
  • Direct exposure to Software Composition Analysis (SCA) tools and open-source vulnerability scanning.
  • History of supporting and scaling Secure Software Development Lifecycle (SSDLC) initiatives.
  • Practical knowledge supporting IT compliance and cloud governance frameworks, including NIST, CIS Benchmarks, or SOC 2.
  • Collaborative background interfacing with Vulnerability Management infrastructure or Penetration Testing teams.

Responsibilities

  • Integrate security controls into CI/CD pipelines to enable secure and automated software delivery.
  • Develop and maintain DevSecOps pipelines that incorporate security scanning, code analysis, and compliance checks.
  • Implement automated security testing including: Static Application Security Testing (SAST), Software Composition Analysis (SCA), Container image scanning, API security testing.
  • Integrate and operationalize code security capabilities including code scanning, secret detection, and dependency vulnerability monitoring.
  • Implement and maintain API security controls using tooling to monitor and protect enterprise APIs.
  • Support container security practices including image scanning, artifact security, and repository management (e.g., Sonatype Nexus or equivalent).
  • Work with development teams to remediate vulnerabilities identified through automated security tooling and penetration testing.
  • Implement security best practices for cloud-native architectures, including infrastructure-as-code security validation.
  • Support cloud security posture management (CSPM) initiatives to ensure cloud environments remain compliant with security policies and regulatory requirements.
  • Develop automation scripts and tooling to support DevSecOps processes.
  • Collaborate with security, infrastructure, and development teams to maintain secure deployment pipelines and reduce application security risk.
  • Provide guidance and training to development teams on secure coding practices and DevSecOps principles.

Benefits

  • medical
  • dental
  • vision
  • paternal leave
  • family leave programs
  • behavioral health programs
  • 401(k) with company match
  • life insurance
  • tuition reimbursement
  • generous paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service