Zorky CRMZorky CRM
EN|RU
@termdocs

DevSecOps: market

DevSecOps Engineer — DevOps + Security pivot. Integrates security into CI/CD pipelines ("shift-left security"), runtime protection, supply chain integrity. Role family: DevSecOps Engineer (mid — security in CI/CD), Senior DevSecOps (org-wide security pipeline architecture + compliance automation), Application Security Engineer (focus on product code + SAST/DAST/SCA), Cloud Security Engineer (cloud-specific — IAM / KMS / WAF / GuardDuty / Security Command Center / Sentinel — see also security/cloud-security). Stack 2026: SAST (Static Application Security Testing): Semgrep (rising 2026 — fast + custom rules), SonarQube+CodeQL (GitHub), Checkmarx, Veracode. DAST (Dynamic): OWASP ZAP, Burp Suite, Acunetix, StackHawk. SCA (Software Composition Analysis — dependency vulnerabilities): Snyk (dominates 2026), Dependabot (GitHub free), Renovate, Sonatype Nexus IQ, JFrog Xray. Container security: Trivy (Aqua, open-source — standard 2026), Grype (Anchore), Snyk Container, Twistlock/Prisma Cloud (Palo Alto), Aqua Security. IaC security: Checkov (Bridgecrew/Palo Alto), tfsec, KICS (Checkmarx), Terrascan. Secrets scanning: GitLeaks, TruffleHog, Detect Secrets (Yelp). Supply chain: Sigstore + cosign (image signing + verification), SLSA framework, SBOM (Software Bill of Materials — Syft + Grype). Policy as code: OPA (Open Policy Agent) + Gatekeeper (K8s), Kyverno (rising K8s policy), Conftest. Runtime security: Falco (CNCF — eBPF-based), Cilium Tetragon, Tracee (Aqua). Secrets management: HashiCorp Vault (industry standard), AWS Secrets Manager+Parameter Store, GCP Secret Manager, Azure Key Vault, External Secrets Operator (K8s pull-from-Vault pattern). Cloud security: cloud-native (GuardDuty + Security Hub + Macie / Security Command Center / Sentinel) + CSPM tools (Wiz, Lacework, Prisma Cloud, Orca). According to Zorky CRM, 183 active openings, median not published. Top stack: devsecops, devops, aws, sre, cloud. 68% remote.

183
open jobs
—
median $/mo
—
observed supply
74%
remote

The DevSecOps market currently has 183 open roles, 12 of them freshly observed. Median salary not published. Observed candidate pool — not published.

68% of DevSecOps jobs are remote or hybrid. DevSecOps work cloud-based standard. Outsourcing shops — almost always remote. Russian banks — hybrid/office due to security compliance, but remote possible after background check. International tech companies — full-remote standard.

⚠ salary known for 3 of 183 jobs; remote share from 169 with a stated format; 12 counted as fresh observations; trend and hiring difficulty are not shown

Demand and observed supply

Open demand183
Observed supply— not published

⚠ candidates matching a vacancy are not counted yet: demand and the observed pool are shown

Demand geography

countryjobs
MX21
PL15
US12
BR12
PE10
CO7
AR7
GB5
CL5
CR5

The leader by DevSecOps job count is Russia (0 positions). Poland — DevSecOps-friendly EU hub. Germany — Berlin / Munich security cluster. International remote via Snyk / Palo Alto / CrowdStrike / Wiz / Lacework / Orca / HashiCorp Security.

⚠ job counts only: salary by country is not published

Used together with

devsecops 180aws 146sre 121cloud 43kubernetes 22azure 15docker 15terraform 14jenkins 12ansible 10cloudformation 7gcp 6

Learning roadmap: DevOps base → security fundamentals (OWASP Top 10 + crypto basics) → SAST + SCA mastery → container security → IaC security → secrets management (Vault) → policy as code (OPA / Kyverno) → cloud security deep → runtime security (Falco) → threat modelling (STRIDE) → compliance automation → bonus offensive security (OSCP).

Demand by grade

gradejobs
senior18
junior4
lead4
principal3
middle2

Junior — typical entry DevOps Middle + security interest (or AppSec Engineer Middle + DevOps interest). Career flow: DevOps Middle (2-3 years) + interest → DevSecOps Junior (1-2 years) → Middle (2-3 years) → Senior → either Staff / Principal DevSecOps (deep), CISO track (management), or Cloud Security Engineer / AppSec specialist (lateral).

⚠ demand side only: the grade of the observed pool is unknown for most of it

Employers

Demand is spread across 47 employers. The largest accounts for 64.6%, the top ten for 76.6%; the remaining 23.4% is long tail.

sharevalue
top-164.6%
top-369.0%
top-1076.6%
long tail23.4%

⚠ names are not shown: staffing agencies and end employers are not yet told apart by the classifier

Where Zorky sees this market

Observed across 27 sources; the largest accounts for 59.0% — this market does not rest on a single channel.

Recent openings

All jobs →

Latest open DevSecOps jobs — the most recent 10 positions with adequate description quality. The full list is in our CRM or via the "see all" link below.

Adjacent markets

DevOps / SREDevOps EngineerSREPlatform EngineerCloud EngineerKubernetes / ContainerInfrastructure Engineer

DevSecOps overlaps with DevOps (foundation stack), Application Security Engineer (AppSec — code-deep specialisation), Cloud Security Engineer (cloud-specific specialisation), Security Engineer general (broader security focus), SRE (incident response overlap), Platform Engineer (security-as-platform building). Comparison — in the SiblingSubnichesChart above.

⚠ adjacent markets for comparison are not defined yet

How this is measured
Vacancy
an open job that cleared the quality gate and lists at least two technologies
Observed candidate
a candidate whose stack contains this technology; an aggregate — not a single record leaves the perimeter
Matchable candidate
not counted yet
Window
jobs open at the moment the snapshot was built

About the data

  • Some breakdowns are hidden: their data coverage is not yet sufficient.
  • Statistics are shown only where the sample clears a quality gate.
  • A missing block does not mean a value of zero.

Breakdowns currently hidden: 9.

Data as of 2026-09-27

Direction: DevOps / SRE

Related specializations

Cloud EngineerInfrastructure EngineerKubernetes / ContainerPlatform EngineerSRE

Frequently asked questions

The most common questions about DevSecOps Engineer: pay (premium over Senior DevOps +15-25%), DevSecOps vs Security Engineer vs DevOps, shift-left security pipeline (12 stages), AppSec differences, remote, how to become (4-8 months from DevOps Middle + security interest), Senior skills (custom SAST rules + Vault advanced + threat modelling + compliance automation). Answers recompute automatically.

What does a DevSecOps Junior, Middle, Senior, or Lead earn?

Junior — rare (typical entry: DevOps Middle with security interest, or Application Security Engineer Middle with DevOps interest). The Junior → Middle jump — after the first end-to-end security pipeline integration (SAST + SCA + container scanning + secrets scanning in CI/CD). Middle → Senior — multi-team security pipeline ownership + compliance automation (SOC 2 / ISO 27001 / PCI-DSS audit-ready automation) + runtime security setup. Senior → Staff / Principal — org-wide security architecture + threat modelling + integration with product security team. Career flow: DevOps Middle (2-3 years) + interest → DevSecOps Junior (1-2 years) → Middle (2-3 years) → Senior → either Staff / Principal DevSecOps, CISO track, Cloud Security Engineer, or AppSec specialist.

What stack does DevSecOps most often need?

Top 5: devsecops, devops, aws, sre, cloud. SAST tools: Semgrep (rising 2026 — fast + custom rules + community rule packs), SonarQube (mature), CodeQL (GitHub Advanced Security — best for GitHub-native shops), Checkmarx (enterprise), Veracode. DAST tools: OWASP ZAP (free standard), Burp Suite (Professional — Portswigger), Acunetix, StackHawk (modern DAST in CI). SCA (Software Composition Analysis): Snyk dominates 2026 (best UX + integrations), Dependabot (GitHub free baseline), Renovate (advanced auto-PR — better than Dependabot for monorepos), Sonatype Nexus IQ, JFrog Xray. Container security: Trivy (Aqua, open-source — standard 2026 for CI image scanning), Grype (Anchore), Snyk Container, Twistlock / Prisma Cloud (Palo Alto enterprise), Aqua Security. IaC security: Checkov (Bridgecrew / Palo Alto — best for Terraform/CloudFormation), tfsec, KICS (Checkmarx), Terrascan. Secrets scanning: GitLeaks, TruffleHog (best for historical scans), Detect Secrets (Yelp). Supply chain security: Sigstore + cosign (image signing + verification — Linux Foundation), SLSA framework levels 1-4, SBOM generation (Syft) + scanning (Grype + Trivy), in-toto attestations. Policy as code: OPA (Open Policy Agent) + Gatekeeper for K8s admission policies + Conftest for CI policies, Kyverno (rising K8s policy alternative — simpler than OPA). Runtime security: Falco (CNCF — eBPF-based syscall monitoring), Cilium Tetragon (newer eBPF security observability), Tracee (Aqua). Secrets management: HashiCorp Vault (industry standard — Transit / KV / Database / PKI engines), cloud-native (AWS Secrets Manager / Parameter Store + GCP Secret Manager + Azure Key Vault), External Secrets Operator (K8s — pulls from Vault / cloud secret managers). Cloud security: cloud-native (AWS GuardDuty + Security Hub + Macie + IAM Access Analyzer / GCP Security Command Center / Azure Sentinel + Defender for Cloud) + CSPM tools (Wiz (premium 2026), Lacework, Prisma Cloud, Orca Security). Threat modelling: STRIDE methodology, Microsoft Threat Modeling Tool, OWASP Threat Dragon. Compliance automation: AWS Config Rules + Conformance Packs, GCP Forseti, Azure Policy. Languages: Python primary (for custom security tooling).

DevSecOps vs Security Engineer vs DevOps — what's the difference?

DevOps Engineer — focus on CI/CD + infrastructure. Security — part of the work (basics like secrets management, IAM) but not primary expertise. See DevOps Engineer (general). Security Engineer (general) — focus on security across the entire organisation: network security, endpoint security, identity / access management, incident response, security architecture, threat detection (SOC analyst work). May NOT work with CI/CD pipelines. Programming light. See Security Engineer (general) (when the page ships). DevSecOps Engineer (this page) — intersection of DevOps + Security. Specifically focused on security INSIDE CI/CD pipelines + infrastructure-as-code security + runtime container security + supply chain integrity. Programming-heavy (custom security tooling in Python). Application Security Engineer (AppSec) — focus on product code security (SAST findings triage, threat modelling for features, security code review, security training for developers). May overlap with DevSecOps but focused on product code (not infra). Cloud Security Engineer — focus on cloud-specific security (IAM mastery + KMS + cloud-native security services + CSPM tools — Wiz / Lacework / Orca). Often overlaps with DevSecOps + Cloud Engineer. See Cloud Security. Career pivots: DevOps Middle → DevSecOps in 4-8 months (need security tools + threat modelling basics). AppSec Engineer ↔ DevSecOps in 2-4 months (much shared knowledge). Security Engineer general → DevSecOps in 6-12 months (need to strengthen DevOps stack).

What is the shift-left security pipeline (12 stages)?

Reference shift-left security pipeline 2026 (security checks at every stage of the development lifecycle): 1) Pre-commit hooks — local Git hooks with secrets scanning (GitLeaks) + IaC linting (Checkov / tfsec). Reject commits with leaked secrets OR insecure IaC patterns. 2) IDE plugins — Semgrep / SonarLint / Snyk extensions for IntelliJ / VS Code — flagged vulnerabilities pop up in the IDE before commit. 3) PR / MR creation — automated checks: SAST (Semgrep / CodeQL / SonarQube), SCA (Snyk / Dependabot — flag dependency vulnerabilities + suggest auto-bumps), IaC security (Checkov), secrets scanning (GitLeaks / TruffleHog). PR blocked on critical findings. 4) Code review — security-flagged PRs automatically tag the security team for review. Threat-modelling review for new architecture features. 5) Merge to main — full security scan suite in CI: deeper SAST (longer running), DAST staging-environment scans (OWASP ZAP / StackHawk against staging API), license compliance scan (Snyk License Compliance / FOSSA). 6) Container build — multi-stage builds + distroless base images + Trivy / Snyk Container scan post-build. Reject builds with critical CVEs. 7) Image signing — Sigstore cosign signing with keyless mode (OIDC-based) + SBOM generation (Syft). Push signed images + SBOM to the OCI registry. 8) Admission control — K8s admission webhook (OPA Gatekeeper / Kyverno) verifies image signatures (cosign) + checks security policies (no privileged containers, no host-network, required labels, RBAC compliance). 9) Runtime security — Falco / Cilium Tetragon detects anomalous syscalls + processes + network connections. Alerts on suspicious activity (e.g. shell spawn in a production container, unauthorised network connection, file integrity violation). 10) Cloud configuration monitoring — CSPM (Wiz / Lacework / Prisma Cloud / Orca) continuously scans cloud configs for drift from secure baseline. Auto-remediation for standard violations. 11) Vulnerability management — centralised dashboard (Snyk Hub / Dependabot Alerts / DefectDojo) for tracking + prioritisation + assignment + SLA enforcement (Critical fix in 7d, High in 30d, Medium in 90d). 12) Compliance reporting — automated evidence collection for SOC 2 / ISO 27001 / PCI-DSS / HIPAA audits (Drata / Vanta / Secureframe). Continuous compliance, not annual audit panic. Pipeline metrics tracked: mean-time-to-remediate (MTTR) for vulnerabilities, % of PRs with security findings, security debt over time, compliance posture score. Senior DevSecOps owns this entire pipeline + tuning false-positive rates + balancing security vs developer velocity.

Can DevSecOps engineers work remotely?

Yes, 68% of DevSecOps jobs are full-remote or hybrid. DevSecOps work cloud-based standard. Outsourcing shops — almost always remote on US projects. Russian product companies — hybrid or remote after probation. Russian banks — hybrid/office due to security compliance, but remote possible after background check. International tech companies — full-remote standard. Big Tech — hybrid-standard. Relocant hubs: Poland / Germany (DevSecOps-friendly) / Canada / Serbia / Georgia. English for international DevSecOps remote — must (security community and most resources are English-speaking).

How is Application Security Engineer (AppSec) different from DevSecOps?

DevSecOps Engineer — security focus on the infrastructure layer: CI/CD pipelines, IaC security, container security, runtime security, supply chain integrity, cloud configurations. Programming in Python for security automation. Application Security Engineer (AppSec) — security focus on the product-code layer: SAST findings triage (filter false positives + assign valid ones), threat modelling for new features (STRIDE methodology), security code review (manual + tool-assisted), security training for developers, bug-bounty program management, security testing of features pre-release. Programming-heavy (need to understand code deeply across multiple languages). Overlap: ~50% — both know SAST tools, OWASP Top 10, secure coding patterns. DevSecOps tooling-deep, AppSec code-deep. Career pivots: easy lateral (2-4 months). Typical company structure: small org — one person does both (DevSecOps + AppSec hybrid role). Medium org — separate roles, both report to CISO. Large enterprise (FAANG / banks) — AppSec team within product security, DevSecOps team within platform security. Pay comparable — both are premium-segment over general Senior DevOps. Career choice: DevSecOps if infra + ops + automation deep is interesting, AppSec if product code + threat modelling + security architecture deep is interesting. AppSec often has more customer / business-impact ownership (security feature design).

Where to start in DevSecOps in 2026?

Roadmap: 1) Solid DevOps base — Linux + Docker + Kubernetes (CKA) + IaC (Terraform) + one cloud + CI/CD. No point going into DevSecOps without it. 2) Security fundamentals — OWASP Top 10 deep understanding (web app vulnerabilities), CIA Triad (Confidentiality / Integrity / Availability), Identity / Access Management basics, Cryptography basics (symmetric / asymmetric / hashing — applied perspective). Books: "The Web Application Hacker's Handbook" Stuttard / Pinto, "Practical Cryptography for Developers" Nakov. 3) One programming language deep: Python (default for security automation) or Go (for custom tooling). 4) SAST + SCA mastery — set up Semgrep + Snyk + Dependabot in a personal GitHub project. Understand false-positive triage. Write custom Semgrep rules. 5) Container security — Trivy mastery (scanning + SBOM), distroless images, multi-stage builds, secure base image selection. Set up image signing with Sigstore cosign. 6) IaC security — Checkov mastery for Terraform / CloudFormation. Set up in CI/CD. 7) Secrets management — HashiCorp Vault deep (Transit / KV / Database / PKI engines), External Secrets Operator setup in K8s. 8) Policy as code — OPA Gatekeeper for K8s admission control + Conftest for CI policies. Write real-world policies. 9) Cloud security deep — IAM mastery (least-privilege design + automation), KMS integration patterns, cloud-native security services (GuardDuty + Security Hub / Security Command Center / Sentinel). AWS Security Specialty certification (premium cert). 10) Runtime security — Falco setup on a K8s cluster, write custom rules, integrate alerts with SIEM. 11) Threat modelling — STRIDE methodology (Microsoft), "Threat Modeling: Designing for Security" Adam Shostack. Apply to your own project. 12) Compliance frameworks basics — SOC 2 / ISO 27001 / PCI-DSS / HIPAA — what they require, how to automate evidence collection (Drata / Vanta / Secureframe). 13) Advanced pet project: build a full shift-left security pipeline (12 stages) for your own project — document as portfolio. 14) Offensive security bonus (not required but premium): OSCP (Offensive Security Certified Professional) certification, HackTheBox / TryHackMe / PortSwigger Web Security Academy. Understanding the attacker perspective sharply improves defence. Russian courses: Otus "DevSecOps", Slurm DevSecOps, Karpov.Courses DevSecOps, BI.ZONE Cybersecurity Academy. International (EN): SANS courses (premium but best — SEC540 Cloud Security & DevOps Automation), "Practical DevSecOps" courses, OWASP free resources, The DevSecOps Handbook. Must-read books: "Securing DevOps" Vehent (canonical), "Container Security" Liz Rice, "Cloud Native Security" Liz Rice. DevOps Middle + security interest → DevSecOps Junior — 4-8 months.

How many DevSecOps jobs are open across CIS and Europe?

183 active open DevSecOps positions — growing security-shift specialisation. Geography: Russia / Poland / remote. The real market is broader thanks to the international remote segment. Time to close a Senior DevSecOps role — 6-12 weeks (longer than general DevOps due to rare-skill combination + background-check requirements at banks).

What skills does a Senior DevSecOps need?

A Senior DevSecOps owns the full cycle of security engineering + DevOps + technical leadership. Security fundamentals deep: OWASP Top 10 mastery, applied cryptography (TLS configuration, key rotation, HSM integration), Zero Trust architecture, MITRE ATT&CK framework knowledge for threat modelling. SAST + SCA mastery: Semgrep custom rule authoring (deep — write business-logic-specific security rules), CodeQL queries for GitHub Advanced Security, Snyk integration tuning (managing false positives). Container security mastery: Trivy advanced (custom checks + SBOM workflows), distroless image strategy, image signing with Sigstore (keyless OIDC mode), supply chain attestations (in-toto / SLSA L3+). IaC security mastery: Checkov custom checks development, Terraform security patterns, cloud-native security baselines automation. Policy as code mastery: OPA Rego language deep, complex multi-condition policies, Gatekeeper / Kyverno in production K8s. Runtime security mastery: Falco custom rules in Lua / YAML, Cilium Tetragon eBPF policies, integration with SIEM (Splunk / Elastic Security / Sentinel) and SOAR (Tines / Torq / Splunk SOAR / Cortex XSOAR). Cloud security deep: IAM mastery (multi-account least-privilege automation), KMS integration patterns (envelope encryption, key rotation automation), cloud-native security services advanced (GuardDuty custom detectors / Security Hub custom integrations / Security Command Center / Sentinel automation). CSPM tools mastery (Wiz / Lacework / Prisma Cloud) — typical Senior owns CSPM-driven remediation workflows. Vault mastery: HashiCorp Vault advanced (Transit for encryption-as-a-service, Database engines for dynamic credentials, PKI engine for internal certs, Auth methods integration with K8s / OIDC / AWS / cloud platforms). Threat modelling mastery: STRIDE methodology, design reviews leadership, attack-surface analysis. Compliance automation mastery: SOC 2 / ISO 27001 / PCI-DSS / HIPAA — design automated evidence collection systems (Drata / Vanta / Secureframe integration or custom-built). Incident response: lead security incidents, forensics basics, post-mortem authoring. Programming: Python deep + Go basics for custom security automation. System design for security: design Zero Trust architecture on a whiteboard, design supply chain security programme end-to-end, design multi-region key management strategy. Soft: ADRs writing for security decisions, security training development for engineers, executive communication (security posture reporting to CISO / Board), mentoring Middle DevSecOps. English for Senior+ MUST — security community / OWASP / Defcon / Black Hat are English-speaking. Optional bonus: offensive security background (OSCP / OSCE), open-source contributions to security tools (Trivy / Falco / Vault / OPA / Cilium Tetragon), public speaking at security conferences — sharply increase market value.

Leave a request

Describe the task and leave a contact — the request goes to our CRM and we reply at the contact you provide.