Jobs Companies US LBM US LBM Cybersecurity Engineer – Azure DevSecOps

Über diese US LBM Cybersecurity Engineer – Azure DevSecOps Stelle bei US LBM

US LBM · Remote · Remote - Nationwide

US LBM is one of the leading and fastest growing distributors of specialty building materials in the United States, with a team of over 13,000 employees located throughout the country. Since our founding in 2009, we have acquired over 100 companies and have expanded to more than 450 locations serving 37 states. US LBM is a progressive organization that promotes a unique culture that focuses on the value of its customers and associates. Developing our people is critical to our strategy and fostering our culture of empowerment.

.

A Brief Overview

The US LBM Cybersecurity Engineer – Azure DevSecOps is part of the Cybersecurity Solutions team and is responsible for securing cloud-native application workloads across their full lifecycle — from code and pipeline through cloud runtime and the data platforms they integrate with. This role requires a strong software engineering background: the ability to read and reason code, work fluently in CI/CD pipelines, and understand how modern applications are built, deployed, and integrated with cloud data services.

As an engineering-first security role, candidates should come from a developer, DevOps, or platform engineering background with a demonstrated knowledge in security. This role owns cloud-native application protection, DevSecOps pipeline security, and the security of data platforms — both Azure-native services such as Cosmos DB and third-party that integrate with Azure workloads, as well as the security of AI-assisted development tools and AI agent platforms increasingly embedded in the software development lifecycle.

Pay Range: $115k - $130k


Key Responsibilities:

  • Implement and manage Microsoft Defender for Cloud (CNAPP) across Azure workloads, covering both cloud security posture management (CSPM) and cloud workload protection (CWPP) for virtual machines, Azure Kubernetes Service (AKS) containers, and serverless functions.
  • Own the DevSecOps program using Snyk for SAST, DAST, and software composition analysis (SCA), integrated directly into CI/CD pipelines (Azure DevOps, GitHub Actions).
  • Write and maintain Infrastructure as Code (Terraform, Bicep, ARM templates) with security controls embedded by default — policy-as-code and guardrails rather than after-the-fact review.
  • Secure data platform integrations between Azure workloads and downstream data services, including Azure-native platforms (Cosmos DB), third-party managed databases (MongoDB Atlas), streaming platforms (RedPanda), and SaaS data warehouses (Snowflake), covering identity/access boundaries, encryption, and data flow security.
  • Secure containerized workloads running on Azure Kubernetes Service (AKS), including cluster hardening, workload identity, network policy, and image scanning integrated into the CI/CD pipeline.
  • Partner directly with application developers to embed security into the software development lifecycle — code review participation, secure coding guidance, and remediation support for vulnerabilities identified by Snyk.
  • Build and maintain custom tooling, scripts, and APIs to automate security checks, policy enforcement, and reporting across the cloud-native environment.
  • Conduct threat modeling for cloud-native workloads and their data integrations, developing corresponding detection and automation use cases.
  • Evaluate and integrate new cloud-native and data platform technologies as the organization's architecture evolves, including technology integration from mergers and acquisitions.
  • Secure the adoption of AI-assisted development tools (e.g., Cursor, Claude Code) and AI agent/model platforms (e.g., Azure AI Foundry), including governance of code and secrets exposure, access scoping for AI coding agents, and safe integration of AI-generated code into the CI/CD pipeline.
  • Ensure DevSecOps and cloud-native practices align with Zero Trust and NIST Cybersecurity Framework principles.
  • May design and build internal web applications for the Cybersecurity Solutions team, such as security reporting dashboards, self-service tooling, and workflow automation portals.

Required and Preferred Knowledge, Skills, and Abilities:

  • Prior experience as a software engineer, DevOps engineer, or platform engineer — hands-on coding experience is required, not just security tooling experience.
  • Proficiency in at least one modern programming language (Python, C#/.NET, Go, or JavaScript/TypeScript) — able to read, write, and debug application code.
  • Hands-on experience with CI/CD pipelines (Azure DevOps, GitHub Actions, or similar) and Infrastructure as Code (Terraform, Bicep, or ARM templates).
  • Experience integrating or securing cloud-native data platforms — Cosmos DB, MongoDB Atlas, RedPanda, Snowflake, Databricks, or similar managed data and streaming services.
  • Familiarity with Microsoft Defender for Cloud or comparable CNAPP/CWPP/CSPM tooling.
  • Experience with Kubernetes/Azure Kubernetes Service (AKS) — container orchestration, cluster security configuration, and securing containerized workloads.
  • Understanding of the security implications of AI-assisted software development — including AI coding assistants (Cursor, Claude Code) and AI agent/model platforms (Azure AI Foundry) — and how to govern their access to code, secrets, and infrastructure.
  • Experience with SAST/DAST/SCA tools (Snyk preferred; Checkmarx, Veracode, or similar acceptable).
  • Understanding of API design, authentication (OAuth2, service principals, managed identities), and secure service-to-service integration patterns.
  • Ability to communicate security requirements to developers in terms that fit their existing workflow, rather than requiring separate security-only processes.
  • Strong understanding of security frameworks such as Zero Trust and the NIST Cybersecurity Framework.
  • Able to support multiple concurrent workstreams in a highly matrix, fast-paced, multi-site organization experiencing rapid growth.
  • Strong interpersonal and communication skills, with a collaborative, developer-friendly approach to security.
  • Must be a self-starter with a builder's mindset — comfortable writing tools and automation rather than relying solely on vendor dashboards.
  • Travel required to various operating locations along with business-related meetings & conferences.
  • Physical demands include sitting for extended periods of time, standing and walking, bending or stooping, lifting up to 25 pounds frequently and up to 50 pounds on occasion. Lifting equipment such as PC CPU's and monitors and transporting to various locations.

Systems Experience:

  • Cloud-Native Application Protection: Microsoft Defender for Cloud (CNAPP, CWPP, CSPM), Azure Policy.
  • DevSecOps / Application Security: Snyk (SAST, DAST, SCA), Azure DevOps, GitHub Actions.
  • Infrastructure as Code: Terraform, Bicep, ARM templates.
  • Data Platforms: Azure Cosmos DB, MongoDB Atlas, RedPanda, Snowflake, Azure Data Factory, or similar data integration/pipeline and streaming tooling.
  • Programming & Scripting: Python, C#/.NET, Go, or JavaScript/TypeScript; PowerShell for Azure automation.
  • Cloud & Infrastructure: Microsoft Azure (compute, storage, networking, identity), Azure Kubernetes Service (AKS).
  • AI-Assisted Development & Agent Platforms: Cursor, Claude Code, Azure AI Foundry, GitHub Copilot, or similar AI coding assistants and agent platforms.
  • APIs & Integration: REST/GraphQL API design, OAuth2, managed identities, service principals.
  • Compliance & Governance: Familiarity with NIST CSF, Zero Trust, and cloud security benchmarks.

Qualifications:

  • Minimum Education required - Bachelor's degree in Computer Science, Software Engineering, Information Systems, or equivalent experience required.
  • Minimum 3-5 years of professional software development or DevOps engineering experience, with at least 1-2 years focused on security.
  • Direct experience with Snyk (or equivalent SAST/DAST/SCA), Microsoft Defender for Cloud, and at least one cloud-native data platform (Cosmos DB, MongoDB Atlas, RedPanda, Snowflake, or similar) required.
  • Relevant certifications preferred (e.g., AZ-204 Developer Associate, AZ-500, CKA/CKAD, Snyk certifications, Terraform Associate).

.

Click Here for Information Regarding Our Benefits


US LBM Holdings, LLC, is an equal-opportunity employer. We do not discriminate on the basis of race, color, religion, creed, national origin or ancestry, sex, age, physical or mental disability, veteran or military status, genetic information, sexual orientation, gender identity, marital status, military status, order of protection status, or any other legally recognized protected basis under federal, state, or local law.

Bereit, sich bei US LBM zu bewerben?
Bei US LBM bewerben

Wie sich dieses Gehalt für Cybersecurity vergleicht

Diese Stelle zahlt $122,500/yrim Einklang mit der üblichen Spanne für Cybersecurity Stellen.

$85,000 dem Median $128,250 $192,509

Übliche Spanne $101,700–$147,500/yr, aus 38 vergleichbaren Cybersecurity Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Cybersecurity ansehen →

Über US LBM

National scale with a strong local focus US LBM is a leading distributor of specialty building materials in the United States. Founded in 2009 with 16 locations in three states, today US LBM operates more than 400 locations across the country and is the largest privately owned full-line building products distributor. Offering a comprehensive portfolio of specialty products, US LBM combines the scale and operational advantages of a national platform with a local go-to-market strategy through its national network of locations across the country.

Alle Jobs bei US LBM ansehen →

Ähnliche Jobs

Accela
Cybersecurity Engineer
Accela
⚡ Früh bewerben Remote Based - US · standortgebunden $90,000–$110,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Support Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, United States Vor Ort $94,000–$94,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Support Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, Canada Vor Ort $118,600–$118,600
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, Canada Vor Ort $118,600–$118,600
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Virtru
Security Governance Risk & Compliance (GRC) Analyst
Virtru
⚡ Früh bewerben Washington, DC - Remote · standortgebunden $130,000–$170,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Pinterest
Security GRC Analyst
Pinterest
⚡ Früh bewerben San Francisco, CA, US; Remote,... · standortgebunden $123,696–$254,667
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Twilio
Senior Analyst, Security Risk
Twilio
⚡ Früh bewerben Remote - Canada · standortgebunden $99,760–$124,700
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
CO
HR Data Security Sr. Analyst (Workday)
Cox
⚡ Früh bewerben REMOTE - USA · standortgebunden $81,400–$122,000
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
CACI
Cybersecurity Assessment Data Analyst
CACI
⚡ Früh bewerben Remote (Any State) · standortgebunden $90,300–$189,600
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei US LBM

Alle Jobs bei US LBM ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos