Enter a job title or keyword

DevSecOps Engineer


Job Location:

New York City, NY - USA

Monthly Salary: Not provided by the employer
Posted: 13 September 2026 (3 hours ago)
Application Deadline: 11 December 2026
Vacancies: 1 Vacancy

Job Summary

How you move is why were here.
Now more than ever.


Get back to what you need and love to do.
The possibilities are endless...

Now more than ever our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximizethe abundant opportunities for growth and success.

If this describes you then lets talk!

HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report. As a recipient of the Magnet Award for Nursing Excellence HSS was the first hospital in New York City to receive the distinguished designation. Whether you are early in your career or an expert in your field you will find HSS an innovative supportive and inclusive environment.


Working with colleagues who love what they do and are deeply committed to our Mission you too can be part of our transformation across the enterprise.

Emp Status

Regular Full time

Work Shift

Compensation Range

What you will be doing
Position Activities
  • Partner with application development data and analytics infrastructure cloud architecture and cybersecurity teams to embed secure-by-design principles into applications services pipelines platforms and infrastructure.
  • Design implement and maintain security controls within CI/CD pipelines including automated testing security gates build and deployment checks and risk-based exception workflows.
  • Manage and support application security capabilities such as Static Application Security Testing (SAST) Software Composition Analysis (SCA) secrets detection dependency review and code security scanning using tools such as Snyk Wiz and GitHub.
  • Review application designs architecture patterns data flows APIs cloud workloads and integration points to identify security risks and recommend practical remediation or compensating controls.
  • Support threat modeling secure code review and security design reviews throughout the software development lifecycle.
  • Validate prioritize and track remediation of application cloud container infrastructure and development environment vulnerabilities using platforms such as Snyk Wiz Sysdig Tenable GitHub and related tools.
  • Review cloud resources Infrastructure as Code templates container images and deployment configurations against organizational policies secure configuration baselines and industry best practices.
  • Develop scripts integrations dashboards and automated workflows that improve security testing vulnerability management reporting evidence collection and developer self-service.
  • Create metrics reports diagrams runbooks standards and technical documentation that communicate application security posture pipeline security effectiveness vulnerability trends and remediation status to technical and non-technical audiences.
  • Support audits assessments compliance activities and control validation requests related to application security cloud security software supply chain security and secure development practices.
  • Perform other related duties as assigned.
Minimum Qualifications
  • Bachelors degree in computer science information technology cybersecurity software engineering data engineering or a related field or equivalent experience.
  • Seven or more years of professional IT experience with five or more years in DevSecOps application security cloud security software engineering infrastructure engineering security engineering or a related technical role.
  • Working knowledge of secure software development lifecycle practices application security principles cloud security concepts CI/CD security and vulnerability management.
  • Experience with CI/CD platforms such as GitHub Actions Azure DevOps GitLab CI Jenkins or similar tools.
  • Experience with cloud platforms such as Microsoft Azure AWS or similar environments.
  • Familiarity with application security and software supply chain security capabilities such as SAST SCA secrets scanning dependency analysis container scanning and Infrastructure as Code scanning.
  • Experience with scripting automation source control code review processes and development workflows using tools and languages such as Git Python PowerShell Bash JavaScript or similar.
  • Ability to assess technical environments identify security gaps evaluate risk and recommend practical remediation activities.
  • Strong written and verbal communication skills including the ability to explain technical security concepts to developers engineers security teams and non-technical stakeholders.
  • Excellent analytical problem-solving troubleshooting organizational and prioritization skills.
Preferred Experience
  • Experience with tools such as Snyk Wiz Sysdig Tenable GitHub Advanced Security GitHub Dependabot or similar security platforms.
  • Experience with Infrastructure as Code and policy-as-code technologies such as Terraform CloudFormation Bicep Open Policy Agent YAML JSON or similar.
  • Experience securing containers Kubernetes container registries cloud-native workloads APIs secrets and microservices architectures.
  • Experience building security automation integrations dashboards reporting and developer self-service capabilities.
  • Experience working with data and analytics platforms data pipelines APIs reporting platforms or related engineering teams.
  • Experience supporting audit readiness compliance activities control testing or automated evidence collection in a regulated environment.
  • Familiarity with security frameworks and standards such as NIST Cybersecurity Framework CIS Controls OWASP Top 10 MITRE ATT&CK HIPAA HITRUST ISO 27001 SOC 2 or similar.
  • Security cloud or software security certifications such as Security CSSLP GWEB GCSA AWS Security Specialty Azure Security Engineer CCSP CISSP or similar.
  • Experience in healthcare or another highly regulated environment.
Skills and Abilities
  • Ability to connect security requirements to practical software development cloud deployment and engineering outcomes.
  • Ability to automate standardize and improve repeatable application security cloud security and DevSecOps processes.
  • Ability to evaluate technical findings through a risk-based lens and prioritize remediation appropriately.
  • Ability to collaborate effectively with application development data and analytics infrastructure cloud architecture cybersecurity compliance and business stakeholders.
  • Ability to produce professional-level documentation reports diagrams runbooks standards and technical guidance.
  • Ability to think critically make independent decisions and recommend practical solutions.
  • Ability to balance security requirements with delivery timelines and operational realities in a complex healthcare environment.
  • Ability to communicate application security risks control gaps remediation needs and technical recommendations clearly to both technical and non-technical audiences.
  • Ability to support a positive cybersecurity culture by promoting secure development practices accountability and continuous improvement.

Non-Discrimination Policy
Hospital for Special Surgery is committed to providing high quality care and skilled compassionate reliable service to our community in a safe and healing environment. Consistent with this commitment Hospital for Special Surgery provides care admits and treats patients and provides all services without regard to age race color creed ethnicity religion national origin culture language physical or mental disability socioeconomic status veteran or military status marital status sex sexual orientation gender identity or expression or any other basis prohibited by federal state or local law or by accreditation standards.


Required Experience:

IC


About Company

Company Logo

HSS is the #1 ranked hospital in the U.S. for orthopedics, #2 for rheumatology, and top-ranked for pediatric orthopedics. Locations in NY, NJ, CT, and FL.

View Profile View Profile