Security Engineer - Applications Security and DevSecOps
FragomenAbout the role
Job Description
About the Role: Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Security Engineer – Application Security & DevSecOps to join our talented Cyber Security team. This senior-level position is based in Fragomen's Immigration Technology Innovation Lab. Our industry-leading, immigration-specific applications and technology is undergoing tremendous transformation and security is on the critical path to success in that endeavor.
A professional, who is passionate about security, capable of effecting change, and ready to take on new challenges, is what we seek. You will be joining a small team of Security Engineers who help make security a distinguishing factor in our immigration software and service offerings. An individual in this role would work closely with developers, under the direction of IT Security, to integrate security tools into development pipelines and ensure that security verification is an active, integrated part of the development process.
This role will be based in Costa Rica.
How will you make a difference as a Security Engineer - Application Security & DevSecOps at Fragomen?
- Evaluate, propose and test security verification tools to integrate into the development process, e.g., SAST, DAST, SCA and scanners that review code for hardcoded secrets, API keys and more
- Orchestrate the development of security unit tests
- Add security checks directly into the build and release pipelines
- Optimize security testing based on policy, code changes and risk
- Automate workflows using scripts and glue code as needed to integrate security tools into development pipelines
- Design and recommend gating as automation matures to ensure security issues are addressed at the appropriate times in the SDLC
- Assist with prioritization of findings and remediation efforts
- Operate and maintain security tools
- Perform tasks related to other IT Security domains; threat detection and disruption, security engineering and architecture and incident response
- Participate in cyber security investigations
Leverage your valuable skills and experience to make an impact at Fragomen:
- A passionate team player who builds knowledge and solves complex problems
- Seven or more years of web application development and cyber security experience
- Proficient in scripting, coding and development frameworks (,NET, Python, Bash, PowerShell)
- Experience with CICD tools such as Jenkins, GitLab, Bamboo, Octopus and Proget a plus
- Knowledgeable about SDLC best practices
- Experience with cloud native security tools a plus
- Experience with Kubernetes a plus
- Strong, professional communication skills that maintain under pressure
- One or more relevant certifications such as GWEB, OSCP
- BA degree in a related field or a combination of related experience
Benefits:
At Fragomen, we know that great people make a great organization. We value our people and offer employees a broad range of benefits which includes:
- Paid days off
- Insurance
- And other financial benefits which we encourage you to ask us about!
Learn More About Fragomen:
Please take time to read About Us, explore the Meaningful and Impactful Work we do for our clients, and review the standard Benefits we offer. You can find all the material to the right of this page.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s