DevSecOps Engineer

Paylocity · Remote

Company

Paylocity

Location

Remote

Type

Full Time

Job Description

Paylocity is an equal opportunity employer.
When you feel like you belong, work is no longer work - it's personal. At Paylocity, we believe better employees lead to better companies. Workplaces and cultures that care will build the future, and at Paylocity, we're doing just that. Join us as we develop strategies for change and transform the trajectory of your career!
We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it's career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.
Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology!
Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience.
Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!
Position Overview
The DevSecOps Engineer is responsible for understanding and providing guidance to internal teams on best practices in software security and architecture for Paylocity's Information Systems. Responsibilities will also include development and maintenance of internal application security tools, and performing threat modeling, static analysis, and dynamic analysis of our web and mobile applications.
Performance Objectives
The below represents the primary responsibilities of the position. Other duties may be assigned as needed.
• Develop and maintain internal application security tooling.
• Automate security testing and vulnerability management procedures where reasonable.
• Integrate security into the build/deployment process.
• Promote a proactive approach to addressing the changing threat landscape by recommending and implementing architectural improvements to security infrastructure.
• Provide expert guidance and recommendations for strategic and tactical security architecture topics through risk advisory services.
• Perform vulnerability research, assessment and management, serve as a technical security/risk advisor on all new technologies used/developed at Paylocity such as cloud, session management, SSO, database, WAF, Opensource libraries.
• Support offensive security professionals by suggesting remediation strategies for reported vulnerabilities.
• Assist developers in remediating vulnerabilities by providing line-by-line guidance.
• Provide training and education to developers on software security best practices in various cloud-based systems.
• Utilize dynamic application vulnerability scanning using tools like White Hat Sentinel, IBM AppScan, HP WebInspect, Netsparker, AppSpider, or Cenzic Hailstorm.
• Utilize static application vulnerability scanning using tools like HP Fortify, Checkmarx, Veracode, Coverity, etc.
Education and Experience
• Bachelors' Degree in InfoSec, Computer Science, or a related discipline required
• Minimum 3-5 years' experience with full-stack web development.
• In-depth knowledge of at least one JavaScript framework (React/Angular/etc.) or Vanilla JavaScript/JQuery.
• Working knowledge of SQL.
• Experience developing and working with Web APIs.
• Experience interpreting results from Static Code Scanning tools.
• Strong knowledge of Security Token Services, Federated Identity Providers, SAML 2.0, claims-based security and other SSO technologies.
• Experience with creating and maintaining Threat Models at scale.
• Experience with securing database platforms.
• Experience in remediating security vulnerabilities beyond OWASP Top 10.
• Experience in performing security assessments on cloud-based multi-tenant Software-as-a-Service (SaaS) applications running on the .NET platform.
• Experience in assessing security of native and hybrid mobile applications beyond the use of automated tools.
Nice to have:
• Experience developing in .NET is a plus.
• Experience with NoSQL/MongoDB is a plus.
• Experience with message-based systems (RabbitMQ/NServiceBus/etc.) is a plus.
• Experience in at least one scripting language (Python/Ruby/Perl/PHP/etc.) is a plus.
• Functional knowledge of container-based application infrastructure with Docker is a plus.
• Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus.
• Experience with writing Burp plugins, opensource security tools, presenting at security conferences, writing technical research papers or publishing CVEs is a plus.
EEO and accessibility Statement
Paylocity is an equal opportunity employer.
Paylocity is committed to the full inclusio n of all individuals. We comply with federal and state disability laws and make reasonable accommodations for applicants and employees with disabilities. To request reasonable accommodation in the job application or interview process, please contact [email protected]
This role can be performed from any office in the US. The pay range for this position is $91,350 - $141,750 /yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via www.paylocity.com/careers.
#LI-Tech #LI-Remote
Apply Now

Date Posted

03/02/2023

Views

2

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Software Engineer Networking Software and Services - xAI

Views in the last 30 days - 0

The text describes xAIs mission to develop AI systems for understanding the universe and advancing human knowledge It outlines a role involving networ...

View Details

Associate Technical Support Engineer - Recharge

Views in the last 30 days - 0

Recharge is a subscription platform for innovative brands offering customer retention solutions They seek Technical Support roles with 247 coverage em...

View Details

Full Stack Product Engineer - Jiga

Views in the last 30 days - 0

Jiga is a remotefriendly company focused on empowering engineers with trust autonomy and flexibility They emphasize simplicity ownership and impactful...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Executive Director Patient Advocacy - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...

View Details