If you’ve worked at a software company and enjoy building secure, scalable platforms, this DevSecOps Engineer role offers the chance to apply that experience to the world’s largest geospatial Software as a Service offering.
Key Responsibilities
Build and maintain secure CI/CD pipelines and automation, using Infrastructure and Automation as Code
Develop automation using Python, JavaScript, or similar languages (such as Go, Rust, Ruby)
Integrate and administer security tooling (SAST, DAST, SCA) within development pipelines
Implement and secure containerized workloads using Docker
Define and operate monitoring, logging, and alerting across AWS and Azure
Automate provisioning, configuration, and enforcement using AWS and Azure Management APIs
Apply secure identity, authentication, and cryptographic practices, including OAuth 2.0, X.509 certificates, and key management
Build automated tooling leveraging AI Integration (CoPilot, GPT, Claude, and more) to handle non-deterministic workloads
Develop against the Microsoft Fabric Stack (SharePoint, PowerApps, Power Automate, Power BI) with an emphasis on security and automation, along with utilizing GitHub Actions
Contribute to secure development standards, operational documentation, and support procedures
Work across teams developing Esri’s SaaS, desktop, and enterprise server products, along with the extensions and apps hosted inside of them covering various domains of geospatial data and operations
Work across a diverse set of development and CI/CD practices and technologies, utilizing a variety of software languages, to improve their security and compliance
Requirements
2+ years of DevOps or DevSecOps engineering experience, preferably in cloud-based SaaS
Experience with DevOps/DevSecOps practices, including IaC and automation-first design
Experience building and operating CI/CD pipelines (GitHub Actions, GitLab CI, CircleCI)
AI driven exploit discovery & analysis, AI code review
Proficiency with Linux and Windows, including Bash and PowerShell scripting
Hands-on experience with Terraform and Ansible
Experience integrating and automating web and cloud APIs
Experience administering security tools and integrating them into pipelines
Strong understanding of package management, dependency control, and supply-chain security
Experience with Docker and container-based workflows
Proficiency with Git/GitHub, including branching and code reviews
Experience implementing monitoring, logging, and alerting in cloud environments
Experience applying secure development practices in a SaaS environment
Visa sponsorship is not available for this posting. Applicants must be authorized to work for any employer in the U.S.
Bachelor's degree in Computer Science, Engineering, Information Systems, Data Science, or related field
Master's degree in Computer Science, Engineering, Information Systems, Data Science, or related field
Security or technical certifications (such as CISSP, SSCP, GIAC, CEH, OSCP) are desirable
Experience with AI agents, AI-assisted development, and AI security
Knowledge of security frameworks such as OWASP Top 10, SANS Top 25, BSIMM, and CISA Secure Development Guidance
Experience integrating test automation (such as Selenium) into CI/CD pipelines
Familiarity with compliance frameworks (NIST, ISO 27001, FedRAMP, FIPS)
Experience supporting regulated environments and audit readiness
Strong collaboration and communication skills
Familiarity with Esri software
Familiarity with Jenkins
#LI-AL1
#LI-Onsite
Benefits & Perks
Esri’s competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.