Stefanini Group

The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia. More than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence.

Lead IT Security Engineer

Security EngineerSecurity EngineerContractRemote

Location

United States

Posted

3 days ago

Salary

Not specified

Git Lab Ci/cdDockerKubernetesTerraformAWSPythonBashGitCi/cd Pipeline DesignContainer SecurityInfrastructure AS CodeSecurity Scanning ToolsDev Sec Ops

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

The Client - Common Data Platform (CDP) is seeking an experienced Security Engineer to drive the integration of security capabilities into our CI/CD pipelines and development workflows. This role is critical to our multi-year DevSecOps transformation initiative, which aims to modernize security practices across five development teams while supporting CDP's cloud migration and platform modernization goals.

As a Security Engineer, you will work at the intersection of development, security, and operations to build automated security controls directly into our software delivery pipelines. You will partner closely with Application Security, Security Champions, and development teams to ensure security is embedded early in the development lifecycle without compromising delivery velocity.

This is a hands-on technical role requiring deep expertise in CI/CD automation, containerization, infrastructure-as-code, and security tooling integration. You will be responsible for:

  • Implementing build gates
  • Automating security scans
  • Developing custom integrations
  • Ensuring our GitLab-based pipelines provide consistent, measurable security controls across the entire CDP portfolio

Key Areas of Work:

  • Design, implement, and maintain security controls within GitLab CI/CD pipelines
  • Develop pipeline automation scripts
  • Develop and enforce container security policies aligned with Client standards
  • Work with Security Champions to provide technical support and training on pipeline security features
  • Develop reference architectures and example implementations for secure pipelines
  • Support developers in understanding and resolving security findings
  • Support pipeline assessment data collection through pipeline telemetry
  • Coordinate with GRC teams on security control validation and evidence collection
  • Mentor and guide team members in secure development practices
  • Advocate for security throughout the SDLC

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience)
  • Ability to document technical processes, create runbooks, and develop training materials
  • Self-starter with ability to work independently and manage multiple priorities
  • Team focus, flexible thinking, willingness to learn, desire to enable security to support the business
  • Ability to travel to San Francisco main office for final interview and/or onboarding

Requirements

  • 5+ years of experience in DevOps, SRE, or Platform Engineering roles
  • 3+ years of hands-on experience with GitLab CI/CD (or similar platforms like Jenkins, GitHub Actions, Azure DevOps)
  • Strong expertise in CI/CD pipeline design, implementation, and optimization
  • Proficiency in scripting and automation using Python, Bash, or similar languages
  • Deep understanding of containerization technologies (Docker, Kubernetes, ECS)
  • Experience with Infrastructure-as-Code tools (Terraform preferred)
  • Practical knowledge of AWS cloud services
  • Experience integrating security scanning tools into CI/CD pipelines
  • Strong understanding of Git workflows, branching strategies, and merge request processes
  • Experience with configuration management and pipeline-as-code practices

Benefits

  • Listed salary ranges may vary based on experience, qualifications, and local market
  • Some positions may include bonuses or other incentives

Company Description

The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence.

Job Requirements

  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent experience)
  • Ability to document technical processes, create runbooks, and develop training materials
  • Self-starter with ability to work independently and manage multiple priorities
  • Team focus, flexible thinking, willingness to learn, desire to enable security to support the business
  • Ability to travel to San Francisco main office for final interview and/or onboarding
  • 5+ years of experience in DevOps, SRE, or Platform Engineering roles
  • 3+ years of hands-on experience with GitLab CI/CD (or similar platforms like Jenkins, GitHub Actions, Azure DevOps)
  • Strong expertise in CI/CD pipeline design, implementation, and optimization
  • Proficiency in scripting and automation using Python, Bash, or similar languages
  • Deep understanding of containerization technologies (Docker, Kubernetes, ECS)
  • Experience with Infrastructure-as-Code tools (Terraform preferred)
  • Practical knowledge of AWS cloud services
  • Experience integrating security scanning tools into CI/CD pipelines
  • Strong understanding of Git workflows, branching strategies, and merge request processes
  • Experience with configuration management and pipeline-as-code practices

Benefits

  • Listed salary ranges may vary based on experience, qualifications, and local market
  • Some positions may include bonuses or other incentives

Related Categories

Related Job Pages

More Security Engineer Jobs

Chief DevSecOps Engineer

9th Way Insignia

Serving the federal government with courage, integrity, and excellence.

Security Engineer3 days ago
ContractRemoteTeam 51-200Since 2018H1B No Sponsor

This position is contingent upon contract award. Professional Level: Level E3 Engineer - The position is a senior-level engineering role responsible for independently designing, implementing, and supporting complex enterprise systems. This role provides technical leadership, supp...

DevSecOpsAWSKubernetesCI/CDInfrastructure as CodeVulnerability ScanningNIST SP 800-53FISMAFedRAMPMicroservicesAPIContainer SecurityCloud SecurityZero Trust Architecture
United States
$98.2K - $109K / year

Senior Staff Security Engineer

Illumio

Illumio, the Zero Trust Segmentation company, stops breaches from spreading across the hybrid attack surface.

Security Engineer3 days ago
Full TimeRemoteTeam 501-1,000H1B Sponsor

Senior technical resource in Detect, Respond and Recover functions at Illumio

AWSAzureCloudPythonRuby
Tennessee
$180K - $216K / year

Community Lead, Security

Crogl, Inc.

Autonomous Knowledge Engine for Security Operations

Security Engineer3 days ago
Full TimeRemoteTeam 11-50Since 2023H1B No Sponsor

Practitioner Community Lead building a trusted security community

AWSCloudPythonSplunk
United States
Security Engineer3 days ago
Full TimeRemote

The Cyber Security Engineer provides hands-on cybersecurity engineering and advisory services to Meriplex clients. This role works directly with client environments to design, deploy, configure, and support security technologies across infrastructure, cloud services, networks, an...

Network SecurityFirewallsSIEMEDRXDRActive DirectoryWindows ServerLinuxVMwareVulnerability ManagementIncident ResponseNISTISO 27001CISMITRE ATT&CKCompliance
United States