Rodeo
Get started

Schneider Electric

Principal DevSecOps Engineer

Andover
$0/yr
Posted 2 days ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About the EcoStruxure Building Data Platform

The EcoStruxure Building Data Platform is Schneider Electric's independent data layer for collecting, contextualizing, storing, and analyzing building operational data at scale.

The platform ingests and processes real-time telemetry from connected building systems using cloud-native technologies hosted in Microsoft Azure. It provides the foundation for analytics, digital services, applications, and customer integrations across Schneider Electric's building ecosystem.

Role Overview

We are seeking a Principal DevSecOps Engineer to own the implementation, operation, and continuous improvement of the security posture of the EcoStruxure Building Data Platform.

This role serves as the hands-on security leader embedded within the engineering organization. The successful candidate will lead security tooling, security automation, vulnerability remediation coordination, software supply chain security, Secure SDLC implementation, release security readiness, and cloud security enablement across the platform.

The Principal DevSecOps Engineer is accountable for the implementation and operational execution of product security controls.

This role works closely with:

  • Security Advisor
  • Principal Systems Engineer
  • Engineering Technical Leads
  • Principal Cloud Operations & Infrastructure Engineer
  • Product Owners
  • Schneider Electric Product Security
  • 24x7 Operation Support Team

The Security Advisor remains responsible for independent governance, risk assessment, policy interpretation, CPCERT alignment, risk acceptance guidance, and security oversight.

In this role, you are responsible for implementation, execution, automation, evidence generation, and remediation coordination.

Key Responsibilities

Security Posture Management

  • Own the operational security posture of the EcoStruxure Building Data Platform.
  • Establish and maintain security baselines across applications, cloud services, containers, APIs, CI/CD systems, and supporting platform components.
  • Continuously assess security maturity and identify opportunities for improvement.
  • Implement security controls and automation that reduce platform risk.
  • Report operational security health, remediation status, and security trends.

Vulnerability Management & Remediation

  • Operate vulnerability management activities in accordance with Schneider Electric CPCERT processes and security requirements.
  • Perform technical triage of findings from SonarQube, Black Duck Binary Analysis (BDBA), penetration tests, container security scans, dependency analysis tools, and cloud security assessments.
  • Assess technical applicability of vulnerabilities and identify remediation approaches for affected platform components.
  • Partner with the Security Advisor on vulnerability prioritization, risk evaluation, exception reviews, and remediation timelines.
  • Lead remediation planning and coordinate execution with Technical Leads and engineering teams.
  • Track remediation progress, closure status, security debt metrics, and vulnerability trends.
  • Support vulnerability reporting and evidence requirements for security reviews, audits, and compliance activities.

Secure SDLC Implementation & Automation

  • Partner with the Security Advisor to implement Secure SDLC requirements across the EcoStruxure Building Data Platform.
  • Embed automated security controls and validation activities into GitHub Actions workflows and deployment pipelines.
  • Implement approved security gates and release readiness checks within software delivery processes.
  • Generate and maintain security evidence required for product release reviews and compliance activities.
  • Support developer enablement through practical guidance, tooling, templates, and automation that promote secure engineering practices.
  • Improve security visibility within the software development lifecycle through automation and metrics.

Software Supply Chain Security

  • Own Software Bill of Materials (SBOM) generation and management processes.
  • Establish software supply chain security controls across development and release processes.
  • Manage dependency analysis, artifact validation, and binary scanning programs.
  • Ensure container image integrity and security compliance.
  • Drive adoption of software provenance and artifact attestation practices.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Security Tooling Ownership

  • Own project level configuration, operational effectiveness, and continuous improvement of:
    • SonarQube
    • Black Duck Binary Analysis (BDBA)
    • SBOM Studio
    • GitHub Security
    • Secret scanning solutions
    • Container security platforms
    • Dependency analysis solutions
    • Security reporting and dashboarding tools
  • Partner with engineering teams to ensure security tooling is effective, adopted, and integrated into day-to-day development activities.

Security Operations & Compliance Enablement

  • Implement approved security requirements through engineering controls, automation, and security tooling.
  • Partner with the Security Advisor, Product Owners, and Technical Leads to plan and execute security remediation initiatives.
  • Support penetration testing, CPCERT reviews, compliance activities, and security assessments.
  • Coordinate operational activities supporting release security reviews.
  • Maintain security dashboards, remediation reporting, and evidence repositories.
  • Drive continuous improvement of security tooling, visibility, operational processes, and security engineering practices.

Cloud & Platform Security

  • Partner with the Principal Cloud Operations & Infrastructure Engineer to secure:
    • Azure Kubernetes Service (AKS)
    • Azure Container Registry (ACR)
    • Azure Entra ID
    • Azure Key Vault
    • Workload identities
    • Role-Based Access Control (RBAC)
    • Container platforms
    • Network security controls
    • Cloud platform configurations
  • Provide guidance and implementation support for secure cloud architecture patterns.

Cross-Functional Collaboration

  • Work closely with Technical Leads to integrate security practices into product development.
  • Partner with the Principal Systems Engineer on security-related architecture decisions and standards.
  • Collaborate with the Security Advisor on risk reviews, security findings, mitigation strategies, and compliance activities.
  • Support 24x7 operations teams with security operational procedures, monitoring guidance, and escalation processes.
  • Act as the primary security implementation lead within the EcoStruxure Building Data Platform organization.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Software Engineering, Information Technology, Computer Engineering, or a related technical discipline.
  • Equivalent combination of education, professional training, and relevant industry experience may be considered.

Required Experience

  • 8+ years of experience in cybersecurity engineering, application security, cloud security, DevSecOps, software engineering, or related security-focused roles.
  • 3+ years of experience supporting Azure-based cloud-native platforms.
  • Experience owning or leading security implementation activities within a software product organization.
  • Experience implementing Secure Software Development Lifecycle (Secure SDLC) practices within engineering teams.
  • Experience driving vulnerability management and remediation programs across multiple product or engineering teams.
  • Experience performing vulnerability assessment, technical triage, remediation planning, and risk reduction activities.
  • Experience working with application security testing, dependency analysis, software composition analysis, and container security tools.
  • Experience implementing software supply chain security controls and Software Bill of Materials (SBOM) processes.
  • Experience integrating security controls, validation, and automation into CI/CD pipelines and software delivery workflows.
  • Experience supporting release security reviews, compliance activities, audits, penetration testing, or security assessments.
  • Experience securing cloud-native platforms, containerized workloads, APIs, and Kubernetes-based environments.
  • Experience working with identity and access management, secrets management, and role-based access control models.
  • Experience generating security evidence, remediation reporting, and security metrics for leadership and compliance stakeholders.
  • Experience working within Agile software delivery environments.
  • Experience influencing engineering teams and driving security improvements without direct organizational authority.
  • Experience collaborating effectively with software engineering, architecture, operations, security, and product management teams.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Preferred Experience

  • Experience supporting SaaS, IoT, telemetry, or real-time data platforms.
  • Experience supporting platforms operating under 24x7 availability requirements.
  • Experience supporting Azure-based data platforms.
  • Experience working within globally distributed engineering organizations.
  • Experience supporting external audits, penetration testing programs, and compliance initiatives.
  • Experience working within regulated enterprise environments.
  • Experience supporting ISO 27001-aligned environments.
  • Experience applying IEC 62443 security principles within industrial or operational technology environments.
  • Experience supporting SOC 2 readiness programs or equivalent security control frameworks.
  • Experience implementing security programs aligned with NIST Cybersecurity Framework (CSF), NIST Secure Software Development Framework (SSDF), or similar industry frameworks.

Preferred Qualifications

  • Microsoft Certified: Azure Security Engineer Associate (AZ-500).
  • Microsoft Certified: Azure DevOps Engineer Expert (AZ-400).
  • Certified Information Systems Security Professional (CISSP).
  • Certified Cloud Security Professional (CCSP).
  • Certified Secure Software Lifecycle Professional (CSSLP).
  • Certified Kubernetes Security Specialist (CKS).
  • GIAC Cloud Security Automation (GCSA).

Success Measures

Success in this role will be measured by:

  • Reduction of security debt and vulnerability backlog.
  • Timely remediation of critical and high-risk vulnerabilities.
  • Effective operation and adoption of SonarQube, BDBA, SBOM, and security automation tooling.
  • Improved Secure SDLC adoption across engineering teams.
  • High-quality and audit-ready release security evidence.
  • Successful support of CPCERT, penetration testing, and security review activities.
  • Reduction in recurring security findings.
  • Improved visibility into platform security posture through actionable metrics and reporting.
  • Sustainable alignment with Schneider Electric security requirements and engineering standards.

What's in it for me?

  • Lead transformative projects that protect critical infrastructure and make a measurable impact.
  • Work with cutting-edge technologies and solve complex cybersecurity challenges across diverse industries.
  • Collaborative culture that values technical excellence, innovation, and continuous professional development.
  • Access to certifications, training, and resources that accelerate your career growth.
  • Bring your cybersecurity expertise to a team that's ready to support your success — apply today!

About Schneider Electric

At Schneider, we believe that every employee is a talent who deserves equal opportunities. This means you matter. Every individual needs to feel valued, supported, and treated fairly to do their best work.

Our Total Rewards is our way of saying: “We see you. We value you”. It’s more than just pay and benefits- it’s a meaningful investment in you. It is designed for you to perform, grow, feel safe, and elevate your potential to shine as an impact maker.

For this U.S. based position, the expected pay range

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

36 Bartlet St, Andover, MA 01810, USA

Sign up to applySee more jobs like this