Requisition:Â Â 82540
PSEG Company:Â Â PSEG Long Island
Salary Range: $Â 93,600Â - $Â 148,200
Work Location Category:Â Hybrid
We’re one of the country’s largest energy companies, with a vision of powering a future where people use energy more efficiently and it’s safer and delivered more reliably than ever. We’re also deeply connected to the communities we serve, with more than 13,000 employees working together to support our customers and make a difference every day.
Here, you’ll have the stability and exciting opportunities that come with being a Fortune 500 company — along with a supportive, friendly work environment where your contributions are valued.
We offer a flexible work environment designed to balance employee needs with collaboration and operational excellence. Roles fall into two categories:
- Onsite: Employees work onsite daily.
- Hybrid: A blend of remote and onsite work, with at least three onsite days per week required.
Â
As an employee, if you are regularly scheduled to work 20 or more hours per week, you will have access to a wide range of comprehensive benefits designed to support your total well-being: medical, dental, vision, paternal leave and family leave programs, behavioral health programs, 401(k) with company match, life insurance, tuition reimbursement, and generous paid time off.
More than 13,000 people already call PSEG their work home, taking pride in providing safe, reliable service to millions of customers. If you’re looking for a place where you can build a meaningful career and help power and support our communities, we’d love to welcome you to the team.
PSEG is not offering visa sponsorship for this position.
Job Summary
We are seeking an experienced DevSecOps Engineer who can build, integrate, and operationalize security within our DevOps processes and CI/CD pipelines. This role will focus on embedding security controls into the software development lifecycle, securing cloud infrastructure, and ensuring that applications and APIs meet enterprise security and compliance requirements.
Using a modern technology stack and agile approach, you will work closely with development, infrastructure, and cybersecurity teams to integrate automated security testing, vulnerability management, and compliance validation across our development and cloud environments.
Job Responsibilities
- Integrate security controls into CI/CD pipelines to enable secure and automated software delivery.
- Develop and maintain DevSecOps pipelines that incorporate security scanning, code analysis, and compliance checks.
- Implement automated security testing including:
- Static Application Security Testing (SAST)
- Software Composition Analysis (SCA)
- Container image scanning
- API security testing
- Integrate and operationalize code security capabilities including code scanning, secret detection, and dependency vulnerability monitoring.
- Implement and maintain API security controls using tooling to monitor and protect enterprise APIs.
- Support container security practices including image scanning, artifact security, and repository management (e.g., Sonatype Nexus or equivalent).
- Work with development teams to remediate vulnerabilities identified through automated security tooling and penetration testing.
- Implement security best practices for cloud-native architectures, including infrastructure-as-code security validation.
- Support cloud security posture management (CSPM) initiatives to ensure cloud environments remain compliant with security policies and regulatory requirements.
- Develop automation scripts and tooling to support DevSecOps processes.
- Collaborate with security, infrastructure, and development teams to maintain secure deployment pipelines and reduce application security risk.
- Provide guidance and training to development teams on secure coding practices and DevSecOps principles.
Job Specific Qualifications
- BS degree or higher with 4+ years of professional experience in DevOps Engineering or DevSecOps Engineering.
- In place of a degree, candidates with 8+ years of hands-on experience working with DevSecOps tooling, methodologies, and processes will be considered.
- CI/CD Pipeline Security: Proven track record building, securing, and maintaining Continuous Integration and Continuous Deployment (CI/CD) pipelines with integrated security controls.
- CI/CD Platforms: Proficiency with major CI/CD platforms (e.g., Jenkins, GitHub Actions, GitLab CI/CD, Azure DevOps).
- Application Security Testing: Direct experience with Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.
- API Security: Demonstrated ability implementing API security solutions and protecting application endpoints.
- Container & Artifact Security: Expertise in container security (e.g., Docker, Kubernetes) and managing secure artifact repositories (e.g., JFrog Artifactory, Nexus).
- Cloud Security: Deep background working with public cloud platforms (AWS, Azure, or GCP) and securing cloud infrastructure.
- CSPM: Familiarity with Cloud Security Posture Management (CSPM) tools (e.g., Wiz, Prisma Cloud, Orca Security).
- Core Competencies: Strong professional communication, cross-functional collaboration, and team-building skills.
Â
Desired SkillsÂ
- Prior work with Infrastructure as Code (IaC) tools, such as Terraform, CloudFormation, or Ansible.
- Ability to write scripts and automation workflows using Python, Bash, or similar programming languages.
- Familiarity with automated code scanning, dependency scanning, and secret detection / secret management tools.
- Direct exposure to Software Composition Analysis (SCA) tools and open-source vulnerability scanning.
- History of supporting and scaling Secure Software Development Lifecycle (SSDLC) initiatives.
- Practical knowledge supporting IT compliance and cloud governance frameworks, including NIST, CIS Benchmarks, or SOC 2.
- Collaborative background interfacing with Vulnerability Management infrastructure or Penetration Testing teams.
Some positions at PSEG require access to information covered by the Department of Energy’s regulation 10 CFR 810 (Part 810). If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a “Generally Authorized” destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a “Protected Individual” under the Immigration and Naturalization Act (8 U.S.C 1324b(a)(3)).
As an employee of PSEG Long Island, you should be aware that during storm/outage restoration efforts, you may be required to perform functions different from normal operations and work extended hours beyond your regular work schedule. You may also be required to work on premise or in an alternate location as directed by the company.
Â
For all roles, PSEGLI’s drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing.Â
Employees who are hired or transfer into a federally regulated role (including positions covered by USDOT, PHMSA, or NRC regulations) are subject to random drug and alcohol testing, inclusive of marijuana. Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and medically, the use of these products are prohibited for employees in federally regulated roles. Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for a positive result.
If you are a current PSEG employee and offered an opportunity with PSEG Long Island, you will be treated as a new hire. Â Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires. Â Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits will change and generally be consistent with other similarly situated new hires of that company.Â
PSEGLI is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.Â
PSEGLI is committed to providing reasonable accommodations to individuals with disabilities. Â If you have a disability and need assistance applying for a position, please call 973-430-3845 or email accommodations@pseg.com.
If you need to request a reasonable accommodation to perform the essential functions of the job, email accommodations@pseg.com. Â Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.
ADDITIONAL EEO INFORMATION (Click link below)
Know your Rights: Workplace Discrimination is Illegal
Learn more about this Employer on their Career Site
