Skip to content

Open nowPosted 2 hours agoWe saw it 33 min after it went up

DevSecOps Engineer

StepStone Group54 open roles

Where
Dublin
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDevSecOps EngineerStepStone Group · Dublin
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on StepStone Group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. StepStone Group postings stay open a median of 3 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 34.0%30 days
This job: posted 2 hours ago

StepStone Group median: 3 days open

The posting

We are global private markets specialists delivering tailored investment solutions, advisory services, and impactful, data driven insights to the world’s investors. Leveraging the power of our platform and our peerless intelligence across sectors, strategies, and geographies, we help identify the advantages and the answers our clients need to succeed.

The DevSecOps Engineer is responsible for embedding security into the software development lifecycle and the firm's CI/CD pipelines, with primary focus on application security guardrails, developer-facing tooling, and secure engineering practices. The role also maintains hands-on cloud security expertise, primarily on AWS with working proficiency across Azure, to harden posture and reduce exposure. Sitting within Infrastructure Engineering, the role partners closely with application development, platform, and DevOps teams to build guardrails that get adopted rather than imposed, protecting systems and data while supporting delivery speed.

Key Responsibilities

  • Own and continuously mature the firm's DevSecOps program, embedding SAST, DAST, SCA, infrastructure-as-code and secrets scanning, and policy gates directly into CI/CD pipelines to catch issues before deployment.
  • Partner with application development teams to threat-model new services and features at design time, translating findings into concrete guardrails and remediation guidance developers can act on.
  • Build and maintain secure-by-default patterns, reusable infrastructure-as-code modules, and golden pipeline templates that engineering teams adopt by default.
  • Operationalize the firm's cloud-native application protection platform (Wiz): triage, prioritize, and remediate findings across cloud and application layers, reducing backlog and mean time to remediate.
  • Establish and codify cloud security guardrails primarily on AWS, including Service Control Policies, Config rules, public-access blocking, default encryption, and tagging baselines.
  • Harden identity and access (IAM roles, policies, permission boundaries, and least privilege) and network exposure across cloud workloads.
  • Extend posture management and guardrails to Azure, using tools such as Microsoft Defender for Cloud, Azure Policy, Entra ID, and equivalent GCP controls.
  • Drive down internet-facing exposure, targeting zero critical and high-severity findings across public-facing workloads and applications.
  • Provide security evidence and controls in support of SOC 2, audit, and regulatory requirements, with emphasis on evidencing secure SDLC practices.

Required Skills

  • Strong, hands-on experience embedding security into CI/CD pipelines and the SDLC: SAST, DAST, SCA, infrastructure-as-code scanning, secrets management, and policy-as-code/gating.
  • Practical application security background, including threat modeling and secure coding guidance, with a track record of working directly with developers to land fixes without becoming a blocker to delivery.
  • Solid, hands-on AWS security expertise (IAM, VPC and network security, KMS and encryption, Service Control Policies, public-exposure controls), plus working proficiency in Azure and/or GCP security (Entra ID, Azure RBAC, Microsoft Defender for Cloud, Azure Policy, or equivalent GCP services).
  • Proficiency with infrastructure-as-code (Terraform and/or CloudFormation; Bicep or GCP Deployment Manager an advantage) and scripting and automation (Python preferred).
  • Solid understanding of core security processes, including vulnerability management, logging and detection, secrets management, and incident support.
  • Experience operating a CNAPP/CSPM platform (Wiz preferred), with a track record of remediating findings rather than only reporting them.
  • Familiarity with container and Kubernetes security (EKS/AKS/GKE) and AI/ML application security is desirable.

Educations and Or Work Experience Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Four (4)+ years of experience in DevSecOps, application security, or cloud security engineering.
  • Professional certifications such as a DevSecOps or application security credential (e.g., GWEB, Certified DevSecOps Professional), AWS Certified Security – Specialty, or equivalent.
  • Prior exposure to audit and compliance standards including SOC 2, ISO 27001, or SOX.

#LI-EO1

At StepStone, we believe that our people are our most important asset and crucial to our success. We are an Equal Opportunity Employer that strives to create an environment that empowers our employees and allows them to be heard, regardless of title or tenure. Our organizational community features multiple Employment Resource Groups as well as mentorship programs to enhance the employee experience for all.

As an Equal Opportunity Employer, StepStone does not discriminate on the basis of race, creed, color, religion, sex, national origin, citizenship status, age, disability, marital status, sexual orientation, gender identity, gender expression, genetic information or any other characteristic protected by law.

Candidates must be at least 18 years old to apply.

Developing People at StepStone

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against StepStone Group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on StepStone Group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    StepStone Group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.