This job is closed Remote Job
This job is closed. But you can apply to other open Developer / Engineer jobs.

DevSecOps Engineer

When you feel like you belong, work is no longer work – it's personal. At Paylocity, we believe better employees lead to better companies. Workplaces and cultures that care will build the future, and at Paylocity, we’re doing just that. Join us as we develop strategies for change and transform the trajectory of your career!

We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it’s career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.

Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology!

Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience.

Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!

Position Overview

The DevSecOps Engineer is responsible for understanding and providing guidance to internal teams on best practices in software security and architecture for Paylocity’s Information Systems. Responsibilities will also include development and maintenance of internal application security tools, and performing threat modeling, static analysis, and dynamic analysis of our web and mobile applications.

Performance Objectives

The below represents the primary responsibilities of the position. Other duties may be assigned as needed.

· Develop, implement, and maintain automated security testing tools and processes to identify vulnerabilities and weaknesses.

· Collaborate with software developers to integrate security into the software development lifecycle from design, implementation, testing to release.

· Integrate security tools and practices into our CI/CD pipelines ensuring secure code releases.

· Proactively identify and address classes of security vulnerabilities, rather than just individual instances.

· Provide expert guidance and recommendations for strategic and tactical security architecture topics through risk advisory services.

· Support offensive security professionals by suggesting remediation strategies for reported vulnerabilities.

· Assist developers in remediating vulnerabilities by providing line-by-line guidance.

· Provide training sessions for development teams on software security best practices and coding standards.

Education and Experience

· Bachelors’ Degree in InfoSec, Computer Science, or a related discipline required.

· Minimum 3-5 years’ experience with full-stack web development, DevSecOps, Security Engineering, or a similar role.

· Proficiency in scripting languages like Python, Ruby, or Bash.

· Familiarity with CI/CD tools such as TeamCity, CircleCI, GitLab, or Jenkins.

· Hands-on experience with SAST, DAST, SCA, and API security tools.

· Strong knowledge of cloud environments like AWS, Azure, and GCP and their security specifics.

· Experience developing and working with Web APIs.

· Strong knowledge of Security Token Services, Federated Identity Providers, SAML 2.0, claims-based security and other SSO technologies.

· Experience in remediating security vulnerabilities beyond OWASP Top 10.

Nice to have:

· Experience developing in .NET is a plus.

· Experience with NoSQL/MongoDB is a plus.

· Functional knowledge of container-based application infrastructure with Docker is a plus.

· Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus.

· Experience with writing Burp plugins, opensource security tools, presenting at security conferences, writing technical research papers, or publishing CVEs is a plus.

EEO and accessibility Statement

Paylocity is an equal-opportunity employer. Paylocity is committed to the full inclusion of all individuals. We recruit, train, compensate, and promote regardless of race, religion, color, national origin, sex, disability, age, veteran status, and other protected status as required by applicable law. At Paylocity, we believe diversity makes us better.

We embrace and encourage our employees’ differences in age, culture, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion or spiritual belief, sexual orientation, socio-economic status, veteran status, and other characteristics that make our employees unique. We actively cultivate these differences through our employee resource groups (ERGs), employee experiences, perspectives, talents, and approaches to drive innovation in the software and services we provide our customers.

We comply with federal and state disability laws and make reasonable accommodations for applicants and employees with disabilities. To request reasonable accommodation in the job application or interview process, please contact accessibility@paylocity.com.

This role can be performed from any office in the US. The pay range for this position is $85,000 - $131,000 /yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via www.paylocity.com/careers.

This job is closed
But you can apply to other open Remote Developer / Engineer jobs