DevSecOps Engineer
Background
Accumulus Synergy is a nonprofit trade association working on behalf of industry to address the global need for digital transformation. To help solve for this need, Accumulus is developing a transformative data exchange platform to enable enhanced collaboration and efficiency between life sciences organizations and National Regulatory Authorities worldwide. The Accumulus Platform aims to improve efficiencies in the regulatory process by leveraging advanced technology, including data science and AI, as well as tools for secure data exchange to improve patient safety, help reduce the cost of innovation, and ultimately bring patients safe and effective medicines faster. Accumulus is working with key stakeholders in the life sciences - regulatory ecosystem to build and sustain a platform that aims to meet regulatory, cybersecurity, and privacy requirements spanning clinical, safety, chemistry and manufacturing, and regulatory exchanges and submissions. Accumulus Synergy sponsors include Amgen, Astellas, AstraZeneca, GSK, Johnson & Johnson, Lilly, Merck, Pfizer, Roche, Sanofi, and Takeda.
Job Description
Accumulus is seeking a DevSecOps Engineer. This will be a key role within the Security Solutions Architecture team, reporting directly to the Lead DevSecOps Engineer.
As a DevSecOps Engineer, you will play a crucial role in integrating security into every phase of our software development and operational processes. Your work will directly contribute to the secure delivery of our product offerings, ensuring that security best practices are embedded from code to cloud. This position is perfect for a proactive and skilled engineer passionate about automating security and operational excellence.
Responsibilities
- Embed security controls and best practices into the CI/CD pipeline, ensuring the secure development and deployment of software.
- Develop and maintain automation scripts and tools to automate security testing (SAST, DAST, SCA) and compliance scanning. Utilize infrastructure as code (IaC) to manage and provision resources securely.
- Complete security risk assessments on development features and working with development teams to incorporate security requirements.
- Complete security reviews of development features to ensure that security requirements have been satisfied.
- Identify, analyze, and remediate vulnerabilities in software and infrastructure. Work closely with development teams to address security issues in early development stages.
- Participate in the incident response process, including analysis, and remediation of security incidents.
- Collaborate with cross-functional teams to enhance security posture.
- Participate as security subject matter expert (SME) for multiple project teams.
- Proficient in at least one coding language (Python, Ruby, Java or similar).
- Experience working in Agile development with experience in technologies such as Containers (Docker, Kubernetes, or similar).
- Ensure compliance with security policies, standards, and regulations.
- Contribute to the development and enforcement of security hardening guidelines.
- Work closely with development, operations, and security teams to foster a culture of security awareness. Advocate for security best practices and educate team members on security-centric methodologies.
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience
- Relevant industry recognized information security certifications
- Demonstrable experience in a DevSecOps role, with a strong background in security as it relates to cloud computing, SaaS environments, and CI/CD pipelines
- Proficiency in scripting and automation tools (e.g., Python, Bash, Terraform, Ansible)
- At least 3 years of experience working with Microsoft Azure cloud.
- Experience with containerization technologies (e.g., Docker, Kubernetes)
- Knowledge of security standards and compliance frameworks relevant to the SaaS industry
- Experience implementing and operating security scanning and vulnerability management tools
Benefits
While we hope the Accumulus mission is what really attracts you, we also have a lot to offer. Organizations are built by great people, and to attract great people you need to offer a great employee experience. Accumulus can provide:
- Very competitive compensation w/ bonus plan. We must compete with big names in tech & pharma for top talent and compensate accordingly.
- 401(k) contribution, immediately vested
- A full benefits package: multiple health plans, vision, dental, life, and disability insurance
- 100% remote work. Accumulus is a fully remote organization, and we intend to remain so
- Experienced leadership to mentor you. We have drawn successful leaders from the biopharma industry with a deep understanding of regulatory affairs and combined them with similarly successful leaders in SaaS product development. Learning opportunities abound.
Unsolicited Contact Policy
Please note that we do not consider resumes submitted by unsolicited third-party recruitment firms. Additionally, we kindly request that candidates refrain from sending unsolicited resumes or making unsolicited contact directly to Accumulus employees. To be considered for any open positions, please utilize our online job application system. We appreciate your cooperation and understanding.
Important Notice: Please note that all official communication from Accumulus Synergy Inc. regarding this job application will be conducted through an email address ending in @accumulus.org
. If you receive any communication from an email address that does not match this domain, please disregard it as it may not be legitimate.
Apply for this job
*
indicates a required field