DevSecOps Engineer - NHL
Listed on 2025-12-01
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing, IT Consultant
ABOUT THE NATIONAL HOCKEY LEAGUE
Founded in 1917, the National Hockey League (NHL®) is the premier professional ice hockey league in the world and is one of the major professional sports leagues in the United States and Canada. With more than 1500 employees across the US and Canada, the NHL is a global sports and entertainment organization committed to building healthy and vibrant communities using the sport of hockey.
At the NHL, we are looking for dynamic, energetic and impactful individuals who are committed to doing the same by sharing in our philosophy that Hockey is for Everyone.
WHAT WE EXPECT OF YOU SUMMARYThe Dev Sec Ops Engineer plays a pivotal role in integrating robust security practices throughout the Software Development Lifecycle (SDLC) and Infrastructure as Code (IaC) processes. This position partners closely with development, systems, and cloud operations teams to engineer and implement multi-layer cybersecurity solutions for both on-premise and cloud environments. By driving secure automation, managing CI/CD pipeline security, and ensuring compliance with leading frameworks such as NIST CSF, SOC 2, and GDPR, the Dev Sec Ops Engineer helps safeguard the organization’s applications and infrastructure against evolving threats while fostering a culture of proactive security and continuous improvement.
ESSENTIAL DUTIES AND RESPONSIBILITIES- Provide expertise and support to the development, systems, and cloud operations teams to integrate security seamlessly into the entire Software Development Lifecycle (SDLC) and Infrastructure as Code (IaC) processes
- Engineer and implement multi-layer cybersecurity solutions for on-premise and cloud environments. Integrate those solutions with existing automation and management processes and platforms
- Plan, develop, and manage CI/CD pipeline security testing, vulnerability scanning, configuration management, and supply chain security
- Perform and supervise security assessments, which includes penetration testing, vulnerability scans, and threat modeling for applications, APIs, and infrastructure. Coordinate with internal teams and external partners to remediate identified risks
- Evaluate, deploy, and manage advanced security tools and platforms, including static and dynamic code analysis tools, container security solutions, and cloud security posture management platforms, to enhance the security of applications and environments
- Ensure compliance with security frameworks and regulations such as NIST CSF, SOC 2, and GDPR by participating in security audits, risk assessments, and implementing necessary controls to address requirements
- Provide subject matter expertise and support to development and operations teams on secure coding practices, threat prevention, and compliance mandates. Plan, develop, and deploy training programs to facilitate the adoption of secure development methodologies
- Maintain knowledge of the latest security trends, vulnerabilities, and emerging technologies, recommend and implement continuous improvements to enhance the organization's security posture and ensure proactive protection against evolving threats
- Organize and maintain real-time security monitoring, alerting, and reporting mechanisms to provide visibility into security incidents and ensure ongoing compliance with security standards
Knowledge Areas/Experience Required
4+ years of experience in Dev Ops, Cybersecurity, and related roles, with demonstrated experience in integrating security practices into the development lifecycle
- Proficiency with CI/CD tools, including Gitlab, and expertise in automating security processes within these pipelines
- Strong understanding and hands‑on experience with cloud security in AWS, including cloud‑native security tools like AWS Security Hub
- Expertise in Infrastructure as Code (IaC) using tools like Terraform with a focus on secure automation and managing cloud environments
- Experience with security tools such as static and dynamic code analysis, container security (e.g. Prisma Cloud), and vulnerability management platforms
- Strong knowledge of threat modeling, vulnerability assessment, and penetration testing, with the ability to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).