6 hours ago
Richmond, VA, USA or McLean, VA, USASenior
Responsibilities
- Design, build, and maintain automated security workflows across the software development lifecycle and broader security environment.
- Automate vulnerability intake, ticket creation, assignment, enrichment, escalation, remediation tracking, exception handling, and reporting.
- Integrate security platforms with ticketing, CI/CD, cloud, and engineering systems using APIs, webhooks, scripts, and workflow automation.
- Embed application, dependency, secrets, infrastructure-as-code, container, and API security testing into CI/CD pipelines.
- Define risk-based release gates, remediation timelines, exception processes, and finding ownership.
- Build reusable secure pipeline templates, hardened images, self-service security controls, and policy-as-code guardrails.
- Strengthen security across cloud infrastructure, containers, Kubernetes, identity, secrets management, networking, and deployment processes.
- Triage and route vulnerabilities and security findings based on severity, exploitability, exposure, asset criticality, and business impact.
- Secure source code, dependencies, build systems, artifacts, container images, and software supply-chain processes.
- Support application security reviews, threat modeling, security architecture reviews, monitoring, and incident-response activities.
- Translate regulatory and compliance requirements into scalable technical controls and automated audit evidence.
- Partner with Engineering teams to remediate security issues and promote secure development practices.
- Evaluate emerging security capabilities, develop security metrics and dashboards, lead cross-functional initiatives, and mentor engineers.
Requirements
- At least eight years of experience in DevOps, platform engineering, cloud engineering, application security, product security, DevSecOps, or cybersecurity engineering.
- Significant hands-on experience designing, implementing, and operating DevSecOps capabilities in production environments.
- Demonstrated experience building security automation and integrating security tools, ticketing platforms, CI/CD systems, and engineering workflows.
- Strong software development or scripting experience using Python and/or Java, with additional experience in PowerShell, Bash, JavaScript, or TypeScript.
- Ability to develop maintainable, reusable, and tested automation rather than relying solely on one-time scripts.
- Strong knowledge of CI/CD security, application security testing, vulnerability management, software supply-chain security, APIs, webhooks, and systems integrations.
- Experience securing cloud platforms, containerized workloads, Kubernetes, infrastructure as code, Linux, networking, identity, encryption, logging, and secrets management.
- Knowledge of SAST, DAST, software composition analysis, secrets scanning, container scanning, infrastructure-as-code scanning, threat modeling, OWASP guidance, web and API security, authentication, and authorization.
- Bachelor’s degree in computer science, cybersecurity, engineering, or a related discipline, or equivalent practical experience.
- Preferred experience with CrowdStrike, Microsoft Sentinel, Aikido Security, Code42, Qualys, Jira, ServiceNow, SOAR platforms, Kubernetes, Docker, Terraform, Helm, cloud IAM, OPA, Rego, or Kyverno.
- Preferred familiarity with SBOMs, artifact signing, dependency security, provenance, software supply-chain frameworks, FedRAMP, NIST, SOC 2, ISO 27001, security metrics, dashboards, and automated compliance evidence.
Benefits
- The position is preferably based in Richmond, Virginia.
- Exiger has a hybrid work policy that is periodically reviewed and adjusted to align with evolving business needs.
- The company provides equal employment opportunity without regard to protected characteristics.
Tech Stack
Categories
About Exiger
Exiger builds AI- and data-driven software for supply chain, third‑party risk, and compliance management, used by corporations, banks, and government agencies. Its 1Exiger platform provides supplier visibility, risk detection, and due diligence, delivered as SaaS with supporting analytics and advisory services. Headquartered in McLean, Virginia, Exiger is FedRAMP authorized for U.S. public‑sector use and is majority‑owned by The Carlyle Group.
