About the role
Who We Are
At Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people.
We’re helping businesses get off the ground by enabling them to focus on running their business. We solve HR issues. We’re data-driven and never stop iterating. If you’d like to work in a supportive, entrepreneurial environment, are interested in building something meaningful and having fun while doing it, we’d love to hear from you.
We're united by shared goals and shared motivations at Justworks. These are best summed up in our company values, which are reflected in our product and in our team.
Our Values
If this sounds like you, you’ll fit right in.
Who You Are
You believe the secure path should be the easy path. You've spent your career where security and engineering meet, and you've learned that scanners nobody reads and gates nobody can pass don't make software safer, they make engineers route around you. So you build guardrails instead: pipelines that catch vulnerabilities before a human ever has to, golden paths with security baked in, and automation that turns "did we patch that?" from a meeting into a dashboard.
You're comfortable in a CI/CD pipeline, an AWS account, and a Kubernetes cluster. You can read application code well enough to tell a real injection risk from scanner noise, and you'd rather fix the template that generated the bug than file 40 tickets about it.
This is a foundational role. You'll be one of the first dedicated DevSecOps engineers on a platform organization supporting 300+ engineers, working alongside our Developer Experience and SRE teams and partnering closely with the Security organization. You'll shape how secure software gets built here, not just review it after the fact – including how we use AI to find and fix vulnerabilities before they reach production.
Security is primarily responsible for discovering, prioritizing, and reporting on risk posture; Engineering is primarily responsible for remediation. This role lives at that seam — partnering with Digital Security on coverage, and driving the fixes through Engineering.
This role reports to Platform Engineering but has a dotted line reporting to Digital Security leadership.
What You Will Work On
- Own security automation across our CI/CD pipelines (GitHub Actions): SAST, SCA, secrets detection, and container scanning that runs fast and flags things worth fixing.
- Build security into our golden path templates for Go, Rails, and Vue.js services, so new services start secure by default.
- Harden our software supply chain: dependency management, artifact signing, SBOM generation, and provenance for what we ship.
- Implement and tune infrastructure-as-code scanning (Terraform) and Kubernetes policy enforcement, catching misconfigurations before they reach an environment.
- Coordinate vulnerability exposure remediation across all of Engineering, including code vulnerabilities, infrastructure configuration changes, and patching.
- Build vulnerability management automation that routes findings to owning teams with context, deduplicates noise, and tracks remediation without spreadsheets.
- Own implementation of secrets management patterns and tooling, and drive the elimination of long-lived credentials in favor of short-lived, federated identity.
- Partner with the Security team on cloud security posture across our AWS environments, and make sure Platform's telemetry gives Detection & Response what they need.
- Support Security's rollout of agentic penetration testing, and build the auto-remediation that turns vulnerability findings into fixes before they can be exploited.
- Explore and roll out AI-assisted security review of code changes, with guardrails that keep signal high and false positives low.
- Drive adoption through documentation and developer education, because a control nobody understands is a control nobody follows.
- Measure what matters: time-to-remediate, scan coverage, secrets findings, and mean time to patch, so we can see whether we're actually getting safer.
- Serve as an advocate for secure development practices, defining how secure software is engineered.
How You Will Do Your Work
As a Senior DevSecOps Engineer, how results are achieved is paramount for your success and ultimately result in our success as an organization. In this role, your foundational knowledge, skills, abilities and personal attributes are anchored in the following competencies:
Good judgement - the exercise of critical thinking, analyzing and assessing problems and implications, identifying patterns, making connections of underlying issues, understanding risks and developing mitigation strategies, and taking ownership of the outcome.
Resourcefulness - taking a can-do approach, even in the face of obstacles and constraints by assessing what’s in front of you and effectively and efficiently optimizing what you have, whether it's working on something new or thinking about how to do something better.Teamwork and communication - putting our collective best together through documentation, collaboration, relationship-building, listening, empathy, recruiting, and evangelism.
Influence and leadership - fostering a community of knowledge-sharing, collaboration, mentorship, and forward-thinking.Skills and knowledge - the capacity to actively learn and apply specific domain knowledge, know-how, and best practices to continually enhance and improve.
In addition, all Justworkers focus on aligning their behaviors to our core values known as COGIS. It stands for:
- Camaraderie - Day to day you can be seen working together toward a higher purpose. You like to have fun. You’re an active listener, treat people respectfully, and have a strong desire to know and help others.
- Openness - Your default is to be open. You're willing to share information, understand other perspectives, and consider new possibilities. You’re curious, ask open questions, and are receptive to thoughts and feedback from others.
- Grit - You demonstrate grit by having the courage to commit and persevere. You’re committed, earnest, and dive in to get the job done well with a positive attitude.
- Integrity - Simply put, do what you say and say what you'll do. You’re honest and forthright, have a strong moral compass, and strive to match your words with your actions while leading by example.
- Simplicity - Be like Einstein: “Everything should be made as simple as possible, but no simpler.”
Qualifications
- 5+ years of professional experience in software engineering, infrastructure, or security engineering
- 3+ years focused on application security, security automation, or DevSecOps practice
- Hands-on experience integrating security tooling into CI/CD pipelines (GitHub Actions strongly preferred): SAST, SCA, secrets detection, container scanning
- Proficiency with AWS and its security services (IAM, GuardDuty, Security Hub, CloudTrail); you understand cloud identity well enough to design least-privilege access, not just audit it
- Experience with Kubernetes and infrastructure-as-code (Terraform preferred), including policy-as-code enforcement
- Proficiency in at least one programming language (Go, Python, or Ruby preferred); you build tooling, not just configure it
- Demonstrated ability to reduce security friction for engineers, with examples of controls teams adopted willingly
- Strong written communication; you document as you build
The base wage range for this position based in our New York City Office is targeted at $188,000.00 to $242,000.00 per year.
Actual compensation is based on multiple factors that are unique to each candidate, including and not limited to skill set, level of relevant experience, and specific work location. Salary ranges for positions based in other locations may differ based on the cost of labor in that location.
For more information about Justworks’ Total Reward Philosophy, including all of the perks and benefits we are proud to offer our team members, please visit Total Rewards @ Justworks.
Diversity At Justworks
Justworks is committed to maintaining a workplace where diversity of identity, culture, and life experience is the norm and is celebrated authentically and respected consistently. Diversity in our work, our people, and our product drives creativity and innovation, entrepreneurial leadership and integrity, competitiveness, and collaboration throughout our business and in the market. We depend on our differences to make our team stronger, our workplace more dynamic, and our product accessible to all of our customers.
We’re proud to be an equal opportunity employer open to all qualified applicants regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital or familial status, disability, pregnancy, gender identity or expression, veteran status, genetic information, or any other legally protected status. Justworks is fully dedicated to providing necessary support to candidates with disabilities who may require reasonable accommodations.
We also provide reasonable accommodations to employees based on their sincerely held religious beliefs, as well as for other covered reasons consistent with applicable federal, state, and local laws. If you're in need of a reasonable accommodation, please reach out to us at accommodations@justworks.com. Your comfort and success matter to us, and we're here to ensure an inclusive experience.
Source: the employer's own careers page.