{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/code-scanning"},"x-facet":{"type":"skill","slug":"code-scanning","display":"Code Scanning","count":3},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_41857894-7ab"},"title":"DevSecOps Engineer – Identity & Access Management","description":"<p>The DevSecOps Engineer will play a pivotal role in integrating robust security practices throughout the DevOps lifecycle, with a primary emphasis on identity and access management (IAM) using Microsoft Entra ID (formerly Azure AD).</p>\n<p>This role is responsible for designing and implementing secure automation pipelines, enforcing least-privilege and Zero Trust access controls, and managing enterprise identity governance to meet both organisational and regulatory compliance requirements.</p>\n<p>In addition to strong Entra ID expertise, the ideal candidate will bring hands-on experience with GCP pipeline deployment, infrastructure-as-code (IaC), and custom agent development to enhance cloud security observability, policy enforcement, and workload protection across cloud environments.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Design and integrate security tooling into CI/CD pipelines using GitHub Actions and GCP Cloud Build to ensure automated code scanning, dependency security, secrets scanning, and policy enforcement.</li>\n</ul>\n<ul>\n<li>Develop secure, automated pipelines on the GCP platform, enabling continuous compliance validation, vulnerability scanning, and policy-as-code deployment for cloud workloads and containerised environments.</li>\n</ul>\n<ul>\n<li>Implement and manage emerging Microsoft Entra ID security controls, also including Conditional Access, Identity Protection, Privileged Identity Management (PIM), Identity Governance, and adaptive MFA policies across enterprise workloads.</li>\n</ul>\n<ul>\n<li>Leverage emerging Entra technologies such as Entra Agent ID, Entra Workload ID, Identity Governance lifecycle workflows, and Zero-Trust deployments,to strengthen identity protection, automate governance, and modernise access strategies.</li>\n</ul>\n<ul>\n<li>Continuously evaluate new features in Microsoft Entra ID and GCP IAM, providing architectural recommendations and integrating relevant capabilities into enterprise DevSecOps workflows.</li>\n</ul>\n<ul>\n<li>Automate identity and security configuration using scripting and IaC tools such as Terraform, Ansible and ARM templates, with multi-cloud pipeline support for Azure and GCP.</li>\n</ul>\n<ul>\n<li>Build and maintain custom security agents and automation workflows to enhance identity telemetry, enforce real-time access policies, and standardise cloud security controls across environments.</li>\n</ul>\n<ul>\n<li>Conduct regular reviews of roles, permissions, service principals, workload identities, and application registration security, ensuring least-privilege access and Zero Trust alignment.</li>\n</ul>\n<ul>\n<li>Collaborate with engineering teams to perform secure code reviews, threat modelling, vulnerability assessments, and provide remediation guidance during development and deployment cycles.</li>\n</ul>\n<ul>\n<li>Develop dashboards, reports, and automation for identity compliance, audit readiness, and IAM security posture using tools like Azure Monitor, GCP Looker, Sentinel, and BigQuery.</li>\n</ul>\n<p>Qualifications:</p>\n<ul>\n<li>Strong technical, troubleshooting, and strategical skills to build emerging technology solutions at scale.</li>\n</ul>\n<ul>\n<li>3–6+ years of experience in DevOps, SecOps, or Cloud Security Engineering roles.</li>\n</ul>\n<ul>\n<li>Strong hands-on experience with Microsoft Entra ID (AuthN Protocols, Conditional Access, PIM, Identity Protection, Graph API and automation).</li>\n</ul>\n<ul>\n<li>Lead GCP cloud deployments and build scalable, secure automation pipelines, leveraging Cloud Build, Cloud Deploy, Artifact Registry, and GCP-native IaC to support continuous delivery, compliance automation, and multi-cloud DevSecOps workflows.</li>\n</ul>\n<ul>\n<li>Experience with IaC: Terraform, Bicep, or ARM templates.</li>\n</ul>\n<ul>\n<li>Knowledge of container security, Kubernetes, and cloud-native security patterns.</li>\n</ul>\n<ul>\n<li>Solid understanding of Zero Trust principles, IAM, and identity lifecycle management.</li>\n</ul>\n<ul>\n<li>Familiarity with vulnerability management tools and SAST/DAST integrations (42Crunch, CheckmarX and FOSSA)</li>\n</ul>\n<ul>\n<li>Microsoft Azure certifications (e.g., AZ-500, SC-300, AZ-104, AZ-305) are a strong plus.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_41857894-7ab","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Ford Global Career Site Careers","sameAs":"https://careers.ford.com/","logo":"https://logos.yubhub.co/careers.ford.com.png"},"x-apply-url":"https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/60841?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Microsoft Entra ID","GCP pipeline deployment","Infrastructure-as-code (IaC)","Custom agent development","Cloud security observability","Policy enforcement","Workload protection","CI/CD pipelines","GitHub Actions","GCP Cloud Build","Code scanning","Dependency security","Secrets scanning","Conditional Access","Identity Protection","Privileged Identity Management (PIM)","Identity Governance","Adaptive MFA policies","Entra Agent ID","Entra Workload ID","Identity Governance lifecycle workflows","Zero-Trust deployments","Terraform","Ansible","ARM templates","Multi-cloud pipeline support","Azure","GCP","Cloud security controls","Least-privilege access","Zero Trust alignment","Secure code reviews","Threat modelling","Vulnerability assessments","Remediation guidance","Identity compliance","Audit readiness","IAM security posture","Azure Monitor","GCP Looker","Sentinel","BigQuery"],"x-skills-preferred":[],"datePosted":"2026-04-25T12:13:46.127Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Chennai"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Automotive","skills":"Microsoft Entra ID, GCP pipeline deployment, Infrastructure-as-code (IaC), Custom agent development, Cloud security observability, Policy enforcement, Workload protection, CI/CD pipelines, GitHub Actions, GCP Cloud Build, Code scanning, Dependency security, Secrets scanning, Conditional Access, Identity Protection, Privileged Identity Management (PIM), Identity Governance, Adaptive MFA policies, Entra Agent ID, Entra Workload ID, Identity Governance lifecycle workflows, Zero-Trust deployments, Terraform, Ansible, ARM templates, Multi-cloud pipeline support, Azure, GCP, Cloud security controls, Least-privilege access, Zero Trust alignment, Secure code reviews, Threat modelling, Vulnerability assessments, Remediation guidance, Identity compliance, Audit readiness, IAM security posture, Azure Monitor, GCP Looker, Sentinel, BigQuery"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9d30cfce-beb"},"title":"Security Engineer - Azure Government","description":"<p>We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security controls across our Azure Gov Cloud environment. In this hands-on role, you will build, strengthen, and maintain our cloud security posture, protect critical workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle.</p>\n<p>Key responsibilities include: Implementing, designing, and managing security architecture for Azure Government and Commercial deployments. Configuring and optimising Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response. Designing and enforcing identity &amp; access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access. Securing network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints. Protecting data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls. Developing and maintaining security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.). Performing threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries. Conducting security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads. Collaborating with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults. Monitoring and remediating security findings, reducing attack surface, and improving overall security posture per the Microsoft Cloud Security Benchmark (MCSB). Deploying configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services.</p>\n<p>Basic qualifications include: Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one. 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus). Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview. Strong understanding of DLP implementation both in cloud and on endpoints utilising Purview and other Microsoft native controls. Experience implementing security in hybrid/multi-cloud environments. Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform). Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management. Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements. Excellent problem-solving, analytical, and communication skills. Strong verbal and written communication skills and the ability to stay composed under pressure.</p>\n<p>Preferred skills and experience include: Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100). Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD). Deep experience with detection and response engineering and SOC operations. Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection. Prior experience in government regulations frameworks such as FedRAMP and CMMC.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9d30cfce-beb","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/5050657007?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$180,000 - $440,000 USD","x-skills-required":["Azure Security Engineer","Microsoft Defender for Cloud","Microsoft Sentinel","Microsoft Defender for Endpoint","Azure Key Vault","Azure Policy","Microsoft Purview","Identity & Access Management","Network Security","Data Loss Prevention","Compliance Frameworks","Cloud Security Posture Management","Threat Hunting","Incident Response","Forensics","Infrastructure as Code","Containers","Kubernetes","Serverless Workloads","DevSecOps","CI/CD Pipelines","Code Scanning","Secure Defaults","Microsoft Cloud Security Benchmark"],"x-skills-preferred":["Microsoft Certified: Azure Security Engineer Associate (AZ-500)","Microsoft Cybersecurity Architect (SC-100)","CISSP","CCSP","Microsoft Certified: Azure Administrator","AWS Security Specialty","SANS GCPS","SANS GCAD","Detection and Response Engineering","SOC Operations","Container Security","Secure DevOps","AI/ML Workload Protection","Government Regulations Frameworks"],"datePosted":"2026-04-24T17:05:13.646Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA; Washington, D.C."}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Azure Security Engineer, Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, Azure Key Vault, Azure Policy, Microsoft Purview, Identity & Access Management, Network Security, Data Loss Prevention, Compliance Frameworks, Cloud Security Posture Management, Threat Hunting, Incident Response, Forensics, Infrastructure as Code, Containers, Kubernetes, Serverless Workloads, DevSecOps, CI/CD Pipelines, Code Scanning, Secure Defaults, Microsoft Cloud Security Benchmark, Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100), CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD, Detection and Response Engineering, SOC Operations, Container Security, Secure DevOps, AI/ML Workload Protection, Government Regulations Frameworks","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":180000,"maxValue":440000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_46d6bdd3-23c"},"title":"Senior Backend Engineer (RoR), AST: Secret Detection","description":"<p>As a Senior Backend Engineer on the Secret Detection team, you&#39;ll help protect sensitive data by building services, scanning workflows, and remediation paths that prevent leaked secrets from reaching production.</p>\n<p>Your work will contribute to the full secret management lifecycle, from push protection to pipeline-based scanning, validation, and auditability, so developers can move quickly without taking on avoidable security risk.</p>\n<p>This is a strong opportunity if you want to work on security features with clear customer impact, improve detection quality, and help teams act when credentials, API keys, or other secrets are exposed.</p>\n<p>You&#39;ll focus on backend systems that power Secret Detection across GitLab&#39;s DevSecOps platform, working closely with product management and engineering peers in an async-first environment.</p>\n<p>In your first year, you&#39;ll contribute to core product capabilities, improve performance and result quality, and help shape technical direction through code reviews, RFCs, and proof of concepts.</p>\n<p>Some examples of our projects:</p>\n<ul>\n<li>Prevent secret leaks in source code with GitLab Secret Push Protection</li>\n<li>Verify validity of secret detection findings</li>\n</ul>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Guide the design and implementation of backend features for GitLab Secret Detection in Ruby on Rails, GraphQL, and Go, delivering capabilities that improve coverage, reliability, or response time for secret detection workflows.</li>\n<li>Build clean, well-tested, maintainable code that meets GitLab standards for reliability and performance, helping reduce regressions and maintain backend systems at scale.</li>\n<li>Partner with product management and engineering peers to deliver backend capabilities that improve detection, validation, remediation, and audit trail coverage across the secret management lifecycle.</li>\n<li>Improve detection quality by reducing false positives, strengthening secret validation workflows, and enabling faster, more effective remediation paths.</li>\n<li>Contribute to code reviews, RFCs, and proof-of-concept work that guide technical approaches across the Secret Detection category.</li>\n<li>Identify technical debt and operational inefficiencies, then propose and implement practical improvements.</li>\n<li>Diagnose performance and optimization issues in backend systems and implement improvements that increase efficiency, scalability, and service reliability.</li>\n<li>Work effectively in a globally distributed, async-first team while participating in planning, engineering discussions, and pairing when needed.</li>\n</ul>\n<p><strong>Requirements</strong></p>\n<ul>\n<li>Experience building backend applications and services using Ruby on Rails, with working knowledge of GraphQL and interest in backend-focused product development.</li>\n<li>Experience designing and delivering secure, maintainable systems that power production web applications at scale.</li>\n<li>Knowledge of security concepts, common vulnerabilities, mitigation techniques, and secure coding practices.</li>\n<li>Background developing or working with security tools or products, especially in areas related to code scanning or secret detection.</li>\n<li>Experience investigating performance issues and improving backend reliability, efficiency, and maintainability.</li>\n<li>Ability to work closely with cross-functional partners, including product, design, and technical writing, to deliver useful product outcomes.</li>\n<li>Communicate clearly in writing and in conversation, especially in remote, async-first environments with distributed teams.</li>\n<li>Bring transferable experience and a willingness to grow into parts of the security or Go stack.</li>\n</ul>\n<p><strong>About the Team</strong></p>\n<p>The Secret Detection team owns GitLab&#39;s Secret Detection category, and we build the backend systems and related user workflows that help developers identify and mitigate exposed secrets as code is contributed.</p>\n<p>We work with the broader security product suite while maintaining focused investment in secret scanning quality, validation, remediation, and developer experience.</p>\n<p>Our work spans Rails and Go services, and we work primarily asynchronously across time zones as a globally distributed team.</p>\n<p>Current opportunities include expanding coverage across the secret management lifecycle and improving result quality across the findings our tools detect.</p>\n<p>For more on how we work, see the Team Handbook page.</p>\n<p><strong>Benefits</strong></p>\n<ul>\n<li>Benefits to support your health, finances, and well-being</li>\n<li>Flexible Paid Time Off</li>\n<li>Team Member Resource Groups</li>\n<li>Equity Compensation &amp; Employee Stock Purchase Plan</li>\n<li>Growth and Development Fund</li>\n<li>Parental leave</li>\n<li>Home office support</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_46d6bdd3-23c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"GitLab","sameAs":"https://about.gitlab.com/","logo":"https://logos.yubhub.co/about.gitlab.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/gitlab/jobs/8432262002?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$117,600-$252,000 USD","x-skills-required":["Ruby on Rails","GraphQL","Go","Backend development","Security","Secure coding practices","Code scanning","Secret detection"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:50:50.538Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote, Canada; Remote, Ireland; Remote, Israel; Remote, Netherlands; Remote, United Kingdom; Remote, US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Ruby on Rails, GraphQL, Go, Backend development, Security, Secure coding practices, Code scanning, Secret detection","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":117600,"maxValue":252000,"unitText":"YEAR"}}}]}