Logo for Mastercam

DevSecOps Security Engineer

Role overview

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required
  • 4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering
  • 1+ year of hands-on experience supporting Kubernetes or containerized application environments
  • Experience securing cloud-native applications and services

Responsibilities

  • Secure Kubernetes-based platforms and containerized workloads
  • Integrate security controls into CI/CD pipelines
  • Implement secure management of secrets, certificates, encryption keys, and service credentials
  • Create dashboards and alerts for security events

Key facts

Hard skills

Other skills

  • Communication
  • Teamwork
  • Curiosity
  • Accountability
  • Problem Solving

About the company

Mastercam logo

Mastercam

Computer Software / SaaS

Founded in 1983, Mastercam is one of the oldest companies in the PC-based CAD/CAM industry. The company was built on the concept of providing an inexpensive PC-based CAM system at a time when most other systems were expensive CAD-oriented products. We are one of the first companies to introduce CAD/CAM software designed for both the machinist and the engineer. Today, Mastercam falls under the Design & Planning Automation division within Sandvik Manufacturing and Machining Solutions. Our corporate headquarters and training facility is in a 53,000 sq. ft. environmentally-friendly building located in Tolland, Connecticut. We embrace remote work, with a growing global team spanning three continents: Asia, Europe, and North America. The backbone of the Mastercam community is our global reseller network. With over 285,000 installations, Mastercam is the number one CAD/CAM software in the world. Mastercam Resellers have developed strong partnerships with our customers, offering advice, strategy, and experience to Mastercam users globally. Mastercam offers solutions for designers and NC programmers in a spectrum of industries, including milling, turning, wire EDM, router programming, plasma cutting, lasers, and 3D design and drafting. Our customers range from one-person job shops to Fortune 100 manufacturers. The same software that is utilized by corporations such as Boeing, IBM, and Sikorsky is still accessible to the small job shop. To ensure a new generation of trained metal and woodworking personnel, Mastercam is available to educational institutions at sizable discounts. As the company and Mastercam continue to grow and expand into new markets and technology, our focus remains on our customers. We're committed to delivering tools that support the higher productivity and greater precision demanded by today's, and tomorrow's, manufacturing.

Company details

IndustryComputer Software / SaaS
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

 Your Role at a Glance

The DevSecOps Security Engineer is responsible for securing and governing Mastercam's cloud-native application platforms, AI-enabled solutions, and supporting infrastructure. This role integrates security throughout the software development lifecycle, including CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads. 

Working closely with Software Engineering, Platform Engineering, Infrastructure, and IT Operations teams, the DevSecOps Security Engineer designs, implements, and maintains security controls that protect applications, infrastructure, data, and AI services while supporting the efficient delivery of business solutions. The role helps establish security standards, improve risk management practices, and promote secure-by-design principles across development and operational processes. 

This position requires expertise in cloud-native technologies, Kubernetes, container security, CI/CD environments, and modern application security practices, along with the ability to contribute to emerging AI and platform security initiatives. The role serves as a key technical resource in advancing the organization's security posture while enabling innovation and operational scalability.

 How You’ll Drive Success

Platform Security

  • Secure Kubernetes-based platforms and containerized workloads. 
  • Implement and maintain Kubernetes security controls including RBAC, Network Policies, Pod Security Standards, and namespace segmentation. 
  • Perform security reviews of platform architecture and application deployments. 
  • Develop infrastructure hardening standards and security baselines. 

DevSecOps

  • Integrate security controls into CI/CD pipelines. 
  • Implement automated vulnerability scanning, code analysis, and compliance checks. 
  • Establish secure software supply chain processes. 
  • Partner with development teams to remediate vulnerabilities and improve secure coding practices. 
  • Develop and maintain security guardrails within GitOps workflows. 

Identity & Access Management

  • Secure authentication and authorization systems. 
  • Implement least-privilege access controls across applications and infrastructure. 
  • Support identity federation, Single Sign-On (SSO), OAuth2, OpenID Connect, and Multi-Factor Authentication (MFA). 
  • Review systems for access governance and privileged access risks. 

Secret Management

  • Implement secure management of secrets, certificates, encryption keys, and service credentials. 
  • Support automated secret rotation and certificate lifecycle management. 
  • Ensure secure application integration with centralized secrets management platforms. 

API & Service Security

  • Secure API gateways and service-to-service communications. 
  • Review API implementations against OWASP API Security standards. 
  • Implement authentication, authorization, rate limiting, and API threat protection controls. 
  • Support Zero Trust networking initiatives. 

Security Monitoring & Detection

  • Create dashboards and alerts for security events.
  • Develop security metrics and monitoring capabilities.
  • Collaborate with operations teams during security investigations and incident response activities.
  • Analyze platform telemetry and audit logs to identify threats and control gaps.

AI & Emerging Technology Security

  • Support security reviews for AI and machine learning workloads.
  • Assist with implementing controls to protect against prompt injection, sensitive data exposure, and model misuse.
  • Participate in AI governance and risk assessment activities.
  • Evaluate emerging risks associated with Large Language Models (LLMs), vector databases, and AI platforms.

 The Talents We’re Seeking

Education & Experience

  • Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related field required; equivalent combinations of education, military service, and relevant professional experience will also be considered. 
  • 4 - 5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering. 
  • 1+ year of hands-on experience supporting Kubernetes or containerized application environments. 
  • Experience securing cloud-native applications and services. 
  • Experience implementing vulnerability management and application security programs. 
  • Experience working with software development teams and CI/CD pipelines. 
  • Experience supporting cloud environments such as AWS, Azure, or Google Cloud. 

Required Skills

Kubernetes

Knowledge of:

  • Kubernetes architecture
  • Pods, Deployments, Services, and Ingresses
  • RBAC
  • Network Policies
  • Container security
  • Workload isolation
  • Cluster security fundamentals

Containers

Experience with:

  • Docker
  • Container image security
  • Image scanning
  • Vulnerability remediation
  • Secure image lifecycle management

DevSecOps

Experience with:

  • CI/CD pipelines
  • Source code management platforms
  • Git workflows
  • Automation and scripting

Understanding of:

  • SAST
  • DAST
  • Dependency scanning
  • Secret scanning
  • Infrastructure-as-Code security

Identity Management

Knowledge of:

  • OAuth2
  • OpenID Connect
  • SAML
  • MFA
  • Role-Based Access Control

Security Operations

Experience with:

  • Vulnerability management
  • Threat detection
  • Security monitoring
  • Incident response support
  • Risk assessments

Scripting

Ability to automate security processes using:

  • Python
  • Bash
  • PowerShell

Preferred Skills

Experience with any of the following technologies is highly desirable:

Platform Technologies

  • Kubernetes
  • Istio
  • FluxCD
  • APISIX
  • OpenTelemetry
  • Grafana

Identity & Security Technologies

  • Keycloak
  • OpenBao
  • HashiCorp Vault
  • Azure Entra ID
  • AWS IAM

Data & Messaging Platforms

  • PostgreSQL
  • RabbitMQ
  • Qdrant

AI Platforms

  • Amazon Bedrock
  • Generative AI applications
  • Retrieval Augmented Generation (RAG)
  • Vector databases
  • LLM Security

Preferred Security Knowledge

Knowledge of:

  • OWASP Top 10
  • OWASP API Security Top 10
  • OWASP Top 10 for LLM Applications
  • NIST Cybersecurity Framework
  • CIS Benchmarks
  • Zero Trust Architecture
  • Secure Software Development Lifecycle (SSDLC)

Preferred Certifications

One or more of:

  • Security+
  • Certified Kubernetes Administrator (CKA)
  • Certified Kubernetes Security Specialist (CKS)
  • AWS Certified Security Specialty
  • CISSP
  • CCSP
  • GIAC Certifications

 Who We Are

At Mastercam, we do not just keep pace with manufacturing—we set the pace. For over 40 years, we have been the name behind the breakthroughs, the partner for those who refuse to settle. When the industry says “too complex,” we say, “challenge accepted.” 

We are more than software. We are a movement of makers, innovators, and problem-solvers driving transformation across the globe. 

Backed by a network of 400 Channel Partners and a thriving developer community, Mastercam delivers the tools and expertise to turn ambitious ideas into flawless reality. From aerospace to automotive, medical to education, we empower manufacturers to push boundaries and redefine what is possible. 

As part of Intelligent Manufacturing and the Sandvik Group, we are leading the charge in digital transformation. Our team of 500+ professionals is united by a single mission: to help achieve precision, productivity, and performance without compromise. 

Our Core Values? They are not just words. They are how we win: 

  • Winning Together: Collaboration is not optional—it is the engine that drives us. 
  • Curiosity: We question, we explore, we innovate. Every day. 
  • Responsibility: Safety, integrity, and sustainability aren’t boxes to check—they are the foundation of trust. 
  • Customer-Focused: We listen. We adapt. We deliver. Always. 

Innovation. Collaboration. Growth. That is the Mastercam way. Explore more at www.mastercam.com, connect on LinkedIn, and join the conversation with #mastercam. 

The next big challenge is waiting—are you ready to accept? 

It is the policy of the company to provide equal employment opportunities to all employees and employment applicants without regard to race, color, religion, sex, or national origin or any other classification protected by applicable local or state laws.

EOE/M/F/Vet/Disabled are encouraged to apply.

We are an E-Verify Employer.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Mastercam

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.