Information Security Analyst - DevSecOps

Neology
Carlsbad, CA

Role Purpose

We’re hiring an Information Security Analyst who lives at the intersection of DevSecOps, Application Security, and Compliance‑as‑Code. You’ll embed security into our software delivery pipelines, harden cloud workloads, operationalize policy as code, and produce auditor‑ready evidence by design—not as an afterthought. Expect to partner closely with platform engineering, SRE, QA, and managed cloud providers in a shared‑responsibility model.

Why This Role Matters

Neology’s global operations demand a proactive security posture. By embedding DevSecOps best practices into every layer of technology and process this role is vital to protecting sensitive data, reducing operational risk, supporting business agility and innovation, and meeting compliance requirements. As cyber threats evolve this role gets to adapt the implementation of Zero Trust principles and advanced automation of compliance checks and assurance for long term security and efficiency.

Key Responsibilities


  • DevSecOps & Platform Guardrails

    • Design and maintain CI/CD guardrails for SAST/SCA/DAST, container image scanning, and IaC checks; integrate findings into issue trackers with SLAs.

    • Enforce secure SDLC entry/exit criteria; drive PR checks (e.g., SonarQube quality gates, license policies) and verify SBOM generation & signing.

    • Partner with SRE/platform teams to set Kubernetes/EKS admission and network policies; validate egress controls and secrets hygiene.


  • Application Security

    • Lead threat modeling for new services; define secure coding patterns and developer enablement (OWASP‑aligned training and playbooks).

    • Coordinate third‑party and internal penetration tests; track remediation to closure with measurable risk reduction.


  • Compliance-as-Code & Evidence Automation

    • Translate NIST/ISO/SOC requirements into machine‑enforceable policies (e.g., AWS Config Conformance Packs, OPA policies) and automate evidence capture.

    • Maintain continuous compliance dashboards; deliver auditor‑ready evidence for periodic reporting and assessments.

    • Tune GuardDuty/Security Hub detections and triage flows.


Required Qualifications


  • 3–5+ years in Information Security with a focus on DevSecOps/AppSec and cloud security (AWS preferred) and integrating automated security checks within pipelines.

  • Hands‑on with: Git‑based CI/CD (GitHub Actions/GitLab/Bitbucket), IaC (Terraform/CloudFormation), container security (EKS/ECR), and policy‑as‑code (OPA/Rego, Conftest; Sentinel/Checkov).

  • Demonstrated experience aligning SDLC and cloud controls to NIST 800‑53/800‑207 (Zero Trust), ISO 27001, and SOC 2.

  • Strong ability to convert framework control statements into automated checks and durable evidence.

  • Strong communication and collaboration skills to work across development, security, and operations teams.

  • Ability to promote a security-first culture and provide training to developers.

Preferred Skills


  • Ability to conduct risk assessments, penetration testing, and manage vulnerability remediation.

  • Incident response skills.

  • Experience with AI-driven security analytics for anomaly detection.

  • Certifications: Azure (Identity & Access Admin), AWS Security Specialty, SSCP/Security+, CISSP, or similar.

  • Exposure to regulated environments and customer audits; ability to “speak auditor” while staying developer‑friendly.

Location

This position is fully remote unless located in the San Diego area. Then occasional trips to the Corporate Office in Carlsbad may be requested (training, meetings, etc.). Applicants must be located in one of the following states: AL, CA, CO, FL, GA, KS, KY, MD, MI, MN, MO, NC, NJ, NV, NY, OH, OK, OR, SC, TX, VA, WA .

Compensation

We offer a base pay of $90,000 - $120,000, plus incentive compensation and benefits. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, and PTO. 

Sponsorship

This is a full-time, permanent position. US Citizens and those who are authorized to work independently in the United States are encouraged to apply. This includes GC-EAD, H4-EAD, and L1-EAD. We are unable to sponsor at this time. No OPT-EAD, H-1B, or TN candidates please.

About Neology

Neology, Inc. is a global technology company headquartered in Carlsbad, California, with manufacturing and operations facilities in North America, Latin America, Europe, and Asia Pacific. We’re partnering with our customers to [re]imagine mobility by combining Artificial Intelligence with state-of-the-art tolling, automated vehicle identification and classification, data processing, and digital payment systems – all delivered with superior service. It’s our mission to help communities around the world enhance mobility, increase sustainability, improve safety, and generate increased revenue.

 

Posted 2025-11-04

Recommended Jobs

Director of Customer Success, Scaled

Cloudinary
San Jose, CA

Cloudinary is the Image and Video API platform trusted by millions of developers and over 10,000 companies worldwide. Our powerful tools fuel websites to be faster, richer in user engagement, and bre…

View Details
Posted 2025-10-01

Sales Ticket Writer / Sales Associate

BLISS Car Wash
Placentia, CA

Job Details: ~$500 to $1,000 Sign on Bonus. ~ Hourly plus commission and incentives. ~ Medical, Dental, Vision, Critical Illness & Accident Insurance Plans. ~401k with Employer Matching. ~ …

View Details
Posted 2025-07-29

Project Engineer

Riddle Recruitment
San Marcos, CA

About the Company Our confidential client is recognized as one of California’s premier mechanical and plumbing contractors. With over 40 years of industry experience, they specialize in custom de…

View Details
Posted 2025-10-22

Elementary Teacher [IMMEDIATE]

Lighthouse Community Public Schools
Oakland, CA

Elementary Teacher The Organization Lighthouse Community Public Schools At Lighthouse Community Public Schools we are engaged in an educational movement that goes beyond our classrooms worki…

View Details
Posted 2025-11-03

Title Assistant

McCarthy & Holthus LLP
San Diego, CA

At McCarthy & Holthus, LLP, and our affiliate companies, we have years of expertise in representing financial institutions across a wide range of banking law matters, and we’re looking for passiona…

View Details
Posted 2025-10-31

Enterprise Data Services Manager

Ca Health & Human Services Agency
Sacramento County, CA

Job Description and Duties If you find working in cloud data environments, data visualization, and data analytics exciting then the CalHHS Enterprise Data Services Manager position is for you. The…

View Details
Posted 2025-10-31

Project Coordinator

Department of General Services
Yolo County, CA

Job Description and Duties This position is eligible to telework up to one (1) days a week, in accordance with the Statewide Telework Policy, and will be required to report to the office as needed…

View Details
Posted 2025-10-31

Cyber Security Engineer II

Pingwind
San Diego, CA

Location: San Diego CA Required Clearance: Secret Certifications: DoD 8570.01-M in accordance with (IAW) DFARS 252.239-7001 Baseline Certification, minimum IAT Level III Required Education…

View Details
Posted 2025-09-22

Sr. Data Engineer

Slickdeals
Paradise, CA

About Slickdeals: We believe shopping should feel like winning. That’s why 10 million people come to Slickdeals to swap tips, upvote the best finds, and share the thrill of a great deal. Tog…

View Details
Posted 2025-10-13

Semi Truck Driver

Veritas Quantitative Services
Glendale, CA

Job Description Job Description We are seeking a Semi Truck Driver to join our team! You will be responsible for safely operating a truck with a capacity of at least 26,000 pounds Gross Vehicle W…

View Details
Posted 2025-07-29