TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions.
The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.
Position Summary
We are seeking a Sr. Security Engineer to lead the integration of security across the software
development lifecycle (SDLC). This role sits at the intersection of engineering, cloud infrastructure, and
application security, driving automation, scalability, and secure-by-default development practices.
You will design and implement security-first CI/CD pipelines, embed automated security testing, and
partner with engineering teams to ensure applications are built, deployed, and operated securely—at
scale
Key Responsibilities
Security Automation & CI/CD Integration (Core Focus)
• Embed security controls and scanners (SAST, SCA, DAST, IaC, Container Security) into CI/CD
pipelines
(GitHub Actions, Jenkins, GitLab CI, Azure DevOps)
• Design and maintain automated security workflows across build, test, and deploy stages
• Implement security gates, policy enforcement, and compliance checks within pipelines
Cloud Security (AWS Focus)
• Secure cloud-native architectures across AWS (IAM, VPC, ECS/EKS, Lambda, S3, API Gateway)
• Integrate and operationalize CNAPP/CSPM tools (e.g., Wiz, Prisma Cloud)
• Enforce least privilege access, secrets management, and runtime protections
Core Skills & Capabilities
• Deep expertise in CI/CD pipelines (GitHub Actions, Jenkins)
• Strong hands-on experience with AWS cloud security
• Proficiency in application security tooling and integration
• Experience with container security (Docker, Kubernetes)
• Strong scripting/programming skills (Python, JavaScript)
• Understanding of modern DevSecOps and shift-left security practices
• Excellent collaboration skills across engineering, security, and DevOps teams
Based on 1,207 disclosed DevOps salaries on RoleSuite, the role pays a median of $142K/year, with most offers between $115K and $174K (10th–90th percentile: $100K–$210K).
See the full DevOps salary breakdown →