hirly

Divergent

DevSecOps Engineer

Torrance, California, United States

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Divergent first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Mid level
Stated salary
$115,843 – $180,977 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
1 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Divergent is building the new industrial age. Every day, our teams design, manufacture, and assemble advanced systems for some of the world’s most demanding industries. Our integrated engineering and manufacturing platform transforms complex designs into production-ready solutions, helping customers move faster, build smarter, and deliver critical systems when they matter most. Divergent is a qualified Tier 1 supplier to global automotive OEMs and supports leading U.S. aerospace and defense companies.

Join us and help push the boundaries of what can be built.

Purpose

We are seeking a DevSecOps Engineer to embed security into every stage of the software delivery lifecycle, from the first commit through production operation. Divergent Technologies Inc. builds and operates a digital manufacturing platform in which software, hardware, and physical production are tightly coupled, which means the pipelines that ship our code warrant the same protection as the code itself. In this role you will own the automation that makes secure delivery the default rather than the exception: hardened CI/CD pipelines, policy-as-code guardrails, reproducibly provisioned cloud infrastructure, and vulnerability findings that reach the responsible engineer with enough context to act on. You will partner with software, platform, and IT teams to reduce risk without slowing delivery, treating security controls as engineering problems to be solved with tooling rather than checklists to be enforced after the fact.

The Role

Design, build, and maintain CI/CD pipelines with automated security gates — static analysis, software composition analysis, secrets detection, container image scanning, and infrastructure-as-code policy checks — that fail fast and produce actionable findings.

Provision and manage cloud infrastructure as code across Azure and AWS environments and enforce configuration standards through policy-as-code rather than manual review.

Harden container and Kubernetes workloads, including base image lifecycle, admission control, runtime policy, network segmentation, and least-privilege workload identity.

Own secrets management and pipeline authentication — vaulted credentials, short-lived tokens, and federated identity — and drive the elimination of long-lived static keys.

Triage and prioritize vulnerability findings across source code, third-party dependencies, container images, and cloud posture; partner with engineering owners to drive remediation to closure against defined service levels.

Build and maintain software supply chain controls, including dependency and lockfile hygiene, artifact signing and provenance, and software bill of materials generation and distribution.

Instrument delivery and runtime environments for security observability by defining detections, dashboards, and alerting, and participate in response for pipeline and infrastructure incidents.

Automate cloud security posture assessment and remediation across accounts and subscriptions, covering identity, network, logging, and encryption baselines.

Support control mapping and audit evidence collection for applicable frameworks, favoring automated evidence generation over manual attestation.

Raise the security baseline of other engineers through reusable pipeline templates, documented golden paths, code review, and hands-on mentoring.

Basic Qualifications

Must be a U.S. Person as defined by the International Traffic in Arms Regulations (22 CFR §120.62) — a U.S. citizen, lawful permanent resident, or other protected individual.

5–10 years of professional experience in DevOps, platform, site reliability, security, or software engineering, including at least 3 years with direct responsibility for securing CI/CD pipelines or cloud infrastructure.

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related technical field, or equivalent demonstrated experience.

Production experience with at least one major cloud provider (Azure or AWS), including its identity and access management, networking, and logging services.

Hands-on experience building and maintaining pipelines in a modern CI/CD system such as GitHub Actions, GitLab CI, Azure Pipelines, or Jenkins.

Proficiency with infrastructure as code (Terraform, Bicep, CloudFormation, or Pulumi), with changes managed through version control and peer review.

Working knowledge of containers and orchestration (Docker and Kubernetes), including image hardening and cluster access control.

Automation and scripting ability in Python, Go, Bash, or PowerShell sufficient to build internal tooling and integrate vendor APIs, not solely to configure existing tools.

Practical experience integrating and operating application security tooling (Blackduck or Rapid7) — SAST, software composition analysis, secrets scanning, and image scanning — and triaging its output.

Solid grasp of core security concepts, including least privilege, network segmentation, key management, authentication and authorization protocols (OAuth 2.0, OIDC, SAML), and common vulnerability classes such as the OWASP Top 10.

Experience with Git-based team workflows, code review, and branch protection.

Clear written and verbal communication, with the ability to explain security risk and engineering tradeoffs to both technical and non-technical audiences.

Preferred Qualifications

Experience in an export-controlled or otherwise regulated environment (ITAR/EAR, CMMC, NIST SP 800-171), or in aerospace, automotive, or advanced manufacturing.

Exposure to manufacturing or operational technology systems, including securing build, test, or production-floor systems that cannot tolerate unplanned downtime.

Software supply chain security experience with SBOM tooling (Syft, CycloneDX, SPDX), artifact signing (Sigstore/cosign), SLSA provenance, or platforms such as Black Duck, Snyk, or Dependency-Track.

Policy-as-code experience with Open Policy Agent/Rego, Kyverno, Conftest, Checkov, or cloud-native policy engines.

Kubernetes security depth, including admission controllers, service mesh mTLS, and runtime detection tooling such as Falco or Tetragon.

Secrets platform experience with HashiCorp Vault, Azure Key Vault, or AWS Secrets Manager, including dynamically issued credentials.

Detection engineering or SIEM experience (Microsoft Sentinel, Splunk, or Elastic), including log pipeline design and tuning.

Threat modeling experience and familiarity with the MITRE ATT&CK framework.

Observability tooling experience with Prometheus, Grafana, OpenTelemetry, or Datadog.

Relevant certifications such as CISSP, CCSP, CKS, GIAC (GCSA, GCLD, GWAPT), or a cloud provider security specialty.

Contributions to internal developer platforms, golden-path templates, or open-source security tooling.

Work Environment

This is a hybrid on-site role located at our Torrance, CA headquarters.

Standard schedule is Monday through Friday during core business hours, with flexibility required for occasional after-hours deployment windows, maintenance, and security incident response.

Participation in a shared on-call rotation for pipeline and infrastructure incidents.

Work is performed primarily in office and laboratory settings, with periodic time on the manufacturing floor where personal protective equipment is required.

Prolonged periods of sitting and working at a computer.

Occasional lifting and moving of equipment weighing up to 25 pounds.

The role requires access to export-controlled technical data; continued access is contingent on maintaining U.S. Person status.

teams to reduce risk without slowing delivery, treating security controls as engineering problems to be solved with tooling rather than checklists to be enforced after the fact.

The Role

Design, build, and maintain CI/CD pipelines with automated security gates — static analysis, software composition analysis, secrets de

Original posting on Divergent's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job