US LBM Cybersecurity Engineer – Azure DevSecOps
US LBM - United States
Hiring: US LBM Cybersecurity Engineer – Azure DevSecOps Company: US LBM Location: United States Job Posted Time: 2026-09-16 15:27:45 Target Skills & Keywords : .NET, API Design, Azure, Azure DevOps, C#, CI/CD, Cosmos DB, DAST, Data Warehouse, Databricks, Embedded Systems, Encryption, Foundry, GitHub Actions, Infrastructure as Code, JavaScript, Kubernetes, MongoDB, OAuth2, Python, SAST, SCA, SaaS, Serverless, Snowflake, Snyk, Terraform, TypeScript, Zero Trust About the job Required Skills: •Implement and manage Microsoft Defender for Cloud (CNAPP) across Azure workloads, covering both cloud security posture management (CSPM) and cloud workload protection (CWPP) for virtual machines, Azure Kubernetes Service (AKS) containers, and serverless functions. •Own the DevSecOps program using Snyk for SAST, DAST, and software composition analysis (SCA), integrated directly into CI/CD pipelines (Azure DevOps, GitHub Actions). •Write and maintain Infrastructure as Code (Terraform, Bicep, ARM templates) with security controls embedded by default — policy-as-code and guardrails rather than after-the-fact review. •Secure data platform integrations between Azure workloads and downstream data services, including Azure-native platforms (Cosmos DB), third-party managed databases (MongoDB Atlas), streaming platforms (RedPanda), and SaaS data warehouses (Snowflake), covering identity/access boundaries, encryption, and data flow security. •Secure containerized workloads running on Azure Kubernetes Service (AKS), including cluster hardening, workload identity, network policy, and image scanning integrated into the CI/CD pipeline. •Partner directly with application developers to embed security into the software development lifecycle — code review participation, secure coding guidance, and remediation support for vulnerabilities identified by Snyk. •Build and maintain custom tooling, scripts, and APIs to automate security checks, policy enforcement, and reporting across the cloud-native environment. •Conduct threat modeling for cloud-native workloads and their data integrations, developing corresponding detection and automation use cases. Qualifications: •Prior experience as a software engineer, DevOps engineer, or platform engineer — hands-on coding experience is required, not just security tooling experience. •Proficiency in at least one modern programming language (Python, C#/.NET, Go, or JavaScript/TypeScript) — able to read, write, and debug application code. •Applied hands-on capability in CI/CD pipelines (Azure DevOps, GitHub Actions, or similar) and Infrastructure as Code (Terraform, Bicep, or ARM templates). •Operational familiarity with Microsoft Defender for Cloud or comparable CNAPP/CWPP/CSPM tooling. •Understanding of the security implications of AI-assisted software development — including AI coding assistants (Cursor, Claude Code) and AI agent/model platforms (Azure AI Foundry) — and how to govern their access to code, secrets, and infrastructure. •Understanding of API design, authentication (OAuth2, service principals, managed identities), and secure service-to-service integration patterns. •Demonstrated capacity to communicate security requirements to developers in terms that fit their existing workflow, rather than requiring separate security-only processes. •In-depth knowledge of security frameworks such as Zero Trust and the NIST Cybersecurity Framework. •Able to support multiple concurrent workstreams in a highly matrix, fast-paced, multi-site organization experiencing rapid growth. •Strong interpersonal and communication skills, with a collaborative, developer-friendly approach to security. Compensation: •$115,000 - $130,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!