Hybrid role in Waltham, MA focused on making secure software delivery repeatable across product lines, engineering teams, and infrastructure. You will help operationalize DevSecOps by embedding security throughout the software and infrastructure lifecycle, combining hands-on engineering work with organizational leadership and cross-functional alignment across Engineering, Product, Platform, Quality, DevOps, SecOps, and GRC.
What you’ll be doing
- Drive adoption of Imprivata’s DevSecOps strategy across products, cloud, data centers, and traditional software by partnering with Engineering, Product, Platform, Quality, DevOps, SecOps, and GRC to clarify ownership.
- Set up security-by-design and secure-by-default practices, including policy-as-code, reusable standards, reference architectures, and minimum security requirements.
- Embed security controls into CI/CD, integrating SAST, DAST, SCA, secrets detection, container scanning, IaC scanning, API scanning, and license scanning with measurable, risk-based security gates tailored to products and deployment models.
- Harden the end-to-end software supply chain by securing Git workflows and build systems, runners, identities, repositories, signing systems, credentials, release artifacts, SBOMs, provenance, and related controls.
- Apply secure-by-default safeguards across cloud, networks, identity, platforms, containers, databases, APIs, serverless services, and service communications.
- Use infrastructure-as-code and policy-as-code automation to reduce drift, excessive privileges, exposed services, and insecure network paths, partnering on secrets, encryption, segmentation, logging, monitoring, resilience, testing, and remediation.
- Cover security across authentication, authorization, privileged access, sessions, tenant isolation, APIs, federation, mobile, endpoints, healthcare data, new services, acquisitions, and major releases.
- Secure agentic AI and MCP servers/clients using threat modeling and practical controls such as least privilege, authentication and authorization, tool validation, secure APIs, prompt-injection protection, data-loss prevention, sandboxing, isolation, monitoring, and human approval.
- Operationalize results from code, dependency, container, cloud, penetration testing, bug reports, and other tools by improving ownership, prioritization, remediation, exceptions, reporting, and monitoring with SecOps.
- Support response for compromised credentials, malicious code, exposed secrets, supply-chain attacks, unauthorized deployments, and cloud compromise, including exercises and post-incident reviews.
- Support compliance and control evidence for NIST SSDF, NIST CSF, CIS Controls, OWASP, ISO 27001, SOC 2, and healthcare requirements, using metrics, incidents, audits, assessments, and engineering feedback to drive continuous improvement.
- Perform other duties as assigned and required.
What you bring
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent experience.
- 7+ years of experience in DevOps, cloud, software, application, or infrastructure security, including 3+ years hands-on DevSecOps or security engineering.
- Experience integrating security into CI/CD and development workflows across both cloud-native and traditional environments.
- Proficiency with AWS, Azure, or Google Cloud; infrastructure as code; containers; Kubernetes; Git; and CI/CD platforms such as GitHub Actions, GitLab, or Jenkins.
- Hands-on experience with SAST, DAST, SCA, secrets detection, container security, IaC security, vulnerability management, and software supply-chain controls including SBOMs, SLSA, Sigstore, artifact signing, or provenance.
- Strong scripting or programming skills in Python, Go, JavaScript, Java, Bash, or comparable languages.
- Working knowledge of IAM, least privilege, authentication, authorization, encryption, certificates, logging, secure network design, and policy-as-code.
- Experience securing SaaS, on-premises, hybrid, virtualized, customer-managed, mobile, endpoint, API, microservice, serverless, or service-mesh environments.
- Experience securing products in healthcare, financial services, government, or other regulated industries, including identity, privileged-access, authentication, or zero-trust solutions.
- Experience integrating security tools with Jira, ServiceNow, GitHub, GitLab, SIEM, CNAPP, vulnerability-management, or GRC platforms.
- Familiarity with STRIDE, PASTA, attack trees, or other threat-modeling methods, plus relevant certifications such as CISSP, CCSP, CSSLP, AWS, Azure, Google Cloud, or Kubernetes security certifications.
- Ability to explain technical risk to both technical and nontechnical stakeholders and drive adoption across teams.
Salary: USD 163,000 - 173,000 per year.
Technologies you’ll work with: AWS, Azure, Google Cloud, infrastructure as code, containers, Kubernetes, Git, GitHub Actions, GitLab, Jenkins, SAST, DAST, SCA, secrets detection, SBOMs, SLSA, Sigstore, artifact signing, provenance, Python, Go, JavaScript, Java, Bash, IAM, encryption, certificates, logging, policy-as-code, Jira, ServiceNow, SIEM, CNAPP, STRIDE, PASTA.