DevSecOps Engineer, Junior
Consumer Cellular
- Job
- 36555
- Posted
- Location
- Scottsdale, AZ
- Work type
- Full Time
- Tax terms
- W2, Yearly
- Experience
- Experience open
- Openings
- 1 opening
Skills
- DevSecOps
- Finance
- Cellular
- Application Development
- Software Engineering
- Software Development
- Security Controls
- Continuous Integration
- Continuous Delivery
- Scripting
- Coaching
- Vulnerability Management
- Dashboard
- Threat Modeling
- Design Review
- Software Security
- Knowledge Transfer
About the job
Our Commitment to You
At Consumer Cellular, recruiting is human. Every application is reviewed by a real member of our Talent Acquisition team because we believe the people behind the rsum matter just as much as what's on it.
All official communication from Consumer Cellular will come from a @consumercellular.com email address or through our verified texting platform, which will only be used to schedule interviews. We will never ask for personal and financial information during the recruiting process. If you receive outreach that doesn't match these criteria, please do not engage and feel free to verify directly at
Job Summary
The Junior DevSecOps Engineer supports the integration of security throughout the software development lifecycle and helps operate Application Security capabilities across Consumer Cellular. Working under the guidance of experienced security and engineering staff, this role assists with automated security testing, CI/CD controls, vulnerability triage, and secure development practices so issues can be identified and addressed earlier.The Junior DevSecOps Engineer collaborates with Security, application development, cloud, platform, and operations teams to support SAST and DAST tools, maintain reusable pipeline controls, connect findings to development workflows, and document secure-by-default practices. This role is designed for an early-career technologist who brings foundational security or software engineering knowledge, a strong learning mindset, and an interest in growing into application security and DevSecOps engineering.
You will need to reside within 50 miles of our Corporate Headquarters in Scottsdale, AZ as this role has the option of hybrid or onsite.
Key Responsibilities
Application Security Support:
- Assist with documented Application Security processes, standards, procedures, and service activities.
- Support secure software delivery requirements and reusable practices for internally developed and third-party applications.
- Work with senior team members to translate application security findings into clear remediation guidance for developers.
Shift-Left Security and Secure SDLC:
- Support security activities throughout the software development lifecycle, including requirements, testing, validation, and remediation follow-up.
- Operate and monitor SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure-as-code scanning tools.
- Review tool output, document potential false positives, and escalate complex findings for further analysis.
CI/CD Security Controls:
- Help implement, test, and maintain approved security controls in build, test, release, and deployment pipelines.
- Use established pipeline templates, quality gates, and exception workflows under guidance from senior engineers.
- Assist with connecting security results to source control, CI/CD platforms, ticketing systems, and vulnerability management workflows.
Security Automation:
- Create and maintain basic scripts, APIs, integrations, and workflow automations with coaching and peer review.
- Support automation for evidence collection, finding intake, ticket creation, reporting, and remediation tracking.
- Document integration dependencies, data sources, troubleshooting steps, and operating procedures.
Developer Enablement:
- Help maintain security guidance, documentation, training materials, and reusable code examples.
- Respond to routine developer questions and escalate complex design or risk decisions to senior staff.
- Participate in security champion, knowledge-sharing, and secure coding activities.
Vulnerability Management:
- Assist with application vulnerability intake, validation, prioritization, assignment, tracking, and closure verification.
- Follow established procedures and service levels while coordinating remediation status with application teams.
- Maintain reports and dashboards for scan coverage, vulnerability aging, and remediation progress.
Learning and Continuous Improvement:
- Participate in threat modeling and security design reviews to build practical application security knowledge.
- Research assigned security topics, tools, and engineering practices and share findings with the team.
- Contribute to playbooks, standards, runbooks, and knowledge transfer while developing technical depth.
- Perform other duties as assigned.