Skip to main content
US LBM

US LBM Cybersecurity Engineer – Azure DevSecOps

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior-ish DevSecOps/Cloud security engineer from a developer/DevOps/platform background. Hands-on with Azure (Defender for Cloud, AKS), IaC (Terraform/Bicep/ARM), CI/CD (Azure DevOps/GitHub Actions) and Snyk; must have experience securing cloud-native data platforms. US-eligible, remote nationwide in the United States.

Core skills

Microsoft Defender for CloudSnykTerraform

Required skills

CNAPPCSPMCWPPAzure Kubernetes ServiceAKSSASTDASTSCAAzure DevOpsGitHub ActionsBicepARM templatesCosmos DBMongoDB AtlasRedPandaSnowflakeKubernetesPythonC#/.NETGoJavaScript/TypeScriptPowerShellRESTGraphQLOAuth2managed identitiesservice principalsAzure Cosmos DBAzure Kubernetes Service (AKS)

Optional skills

DatabricksCursorClaude CodeAzure AI FoundryGitHub CopilotCheckmarxVeracodeAZ-204 Developer Associate

What you'll do

  • Implement and manage Microsoft Defender for Cloud (CNAPP) across Azure workloads, covering CSPM and CWPP for VMs, AKS containers, and serverless functions.
  • Own the DevSecOps program using Snyk for SAST, DAST, and SCA integrated into CI/CD pipelines (Azure DevOps, GitHub Actions).
  • Write and maintain Infrastructure as Code (Terraform, Bicep, ARM templates) with security controls embedded by default.
  • Secure data platform integrations between Azure workloads and downstream data services (Cosmos DB, MongoDB Atlas, RedPanda, Snowflake), covering identity/access, encryption, and data flow security.
  • Secure containerized workloads on AKS, including cluster hardening, workload identity, network policy, and image scanning in CI/CD.
  • Partner with application developers to embed security into the SDLC — code review, secure coding guidance, and remediation support for Snyk-identified vulnerabilities.
  • Build and maintain custom tooling, scripts, and APIs to automate security checks, policy enforcement, and reporting.
  • Conduct threat modeling for cloud-native workloads and their data integrations and develop detection and automation use cases.
  • Evaluate and integrate new cloud-native and data platform technologies, including M&A integrations.
  • Secure adoption and governance of AI-assisted development tools and AI agent/model platforms, including secrets and access scoping.
  • Ensure DevSecOps and cloud-native practices align with Zero Trust and NIST Cybersecurity Framework principles.
  • May design and build internal web applications for security reporting dashboards, self-service tooling, and workflow automation portals.
  • Travel to various operating locations for business meetings & conferences; perform physical handling of equipment as described.
  • Implement and manage Microsoft Defender for Cloud (CNAPP) across Azure workloads covering CSPM and CWPP for VMs, AKS containers, and serverless functions.
  • Secure data platform integrations between Azure workloads and downstream services (Cosmos DB, MongoDB Atlas, RedPanda, Snowflake) including identity/access, encryption, and data flow security.
  • Secure containerized workloads on AKS including cluster hardening, workload identity, network policy, and image scanning in CI/CD.
  • Partner with application developers to embed security into SDLC: code review, secure coding guidance, remediation support for Snyk findings.
  • Conduct threat modeling for cloud-native workloads and data integrations and develop detection/automation use cases.
  • Secure adoption and governance of AI-assisted development tools and AI agent/model platforms to protect code and secrets and control agent access.
  • Ensure DevSecOps and cloud-native practices align with Zero Trust and NIST Cybersecurity Framework.
  • May design and build internal web applications for security reporting dashboards, self-service tooling, and workflow automation.

What they require

  • Prior experience as a software engineer, DevOps engineer, or platform engineer — hands-on coding experience is required.
  • Proficiency in at least one modern programming language (Python, C#/.NET, Go, or JavaScript/TypeScript).
  • Hands-on experience with CI/CD pipelines (Azure DevOps, GitHub Actions, or similar) and Infrastructure as Code (Terraform, Bicep, or ARM templates).
  • Experience integrating or securing cloud-native data platforms — Cosmos DB, MongoDB Atlas, RedPanda, Snowflake, Databricks, or similar.
  • Familiarity with Microsoft Defender for Cloud or comparable CNAPP/CWPP/CSPM tooling.
  • Experience with Kubernetes/Azure Kubernetes Service (AKS) — cluster security and securing containerized workloads.
  • Understanding of security implications of AI-assisted software development and governance for AI coding assistants and agent platforms.
  • Experience with SAST/DAST/SCA tools (Snyk preferred; Checkmarx, Veracode, or similar acceptable).
  • Understanding of API design, authentication (OAuth2, service principals, managed identities), and secure service-to-service patterns.
  • Strong communication skills with developers; collaborative, developer-friendly approach to security.
  • Strong understanding of security frameworks such as Zero Trust and the NIST Cybersecurity Framework.
  • Able to support multiple concurrent workstreams in a fast-paced, multi-site organization.
  • Minimum Education required - Bachelor's degree in Computer Science, Software Engineering, Information Systems, or equivalent experience.
  • Minimum 3-5 years of professional software development or DevOps engineering experience, with at least 1-2 years focused on security.
  • Direct experience with Snyk (or equivalent), Microsoft Defender for Cloud, and at least one cloud-native data platform required.
  • Prior experience as a software engineer, DevOps engineer, or platform engineer; hands-on coding experience required.
  • Experience integrating or securing cloud-native data platforms (Cosmos DB, MongoDB Atlas, RedPanda, Snowflake, Databricks, or similar).
  • Experience with Kubernetes/AKS and securing containerized workloads.
  • Understanding of security implications and governance for AI-assisted development and agent platforms.
  • Experience with SAST/DAST/SCA tools (Snyk preferred; Checkmarx, Veracode acceptable).
  • Understanding of API design, authentication (OAuth2, service principals, managed identities), and secure service-to-service integration.
  • Strong communication skills and ability to work with developers in their workflows.
  • Strong understanding of Zero Trust and NIST Cybersecurity Framework principles.
  • Able to support multiple concurrent workstreams in a fast-paced multi-site organization.
  • Bachelor's degree in Computer Science, Software Engineering, Information Systems, or equivalent experience.
  • Minimum 3-5 years professional software development or DevOps engineering experience, with at least 1-2 years focused on security.

Benefits

  • Equal-opportunity employer statement (US LBM Holdings, LLC is an equal-opportunity employer).

US LBM is one of the leading and fastest growing distributors of specialty building materials in the United States, with a team of over 13,000 employees located throughout the country. Since our founding in 2009, we have acquired over 100 companies and have expanded to more than 450 locations serving 37 states.

Construction MaterialsEnterprise
Salary not disclosed