Send this job to your inbox!
Seeking a highly motivated and skilled DevSecOps Engineer to champion the integration of security throughout our development and operations lifecycle. This role is central to bridging the gap between our engineering and security teams, automating security controls, and ensuring continuous compliance within our cloud environment. The ideal candidate will have deep, hands-on experience in cloud infrastructure, CI/CD pipeline development, and mandated security frameworks.
Secure CI/CD Implementation: Design, implement, and manage continuous integration and deployment (CI/CD) pipelines (e.g., GitHub Actions, GitLab CI, CircleCI) that include automated testing and mandatory security gates (SAST, DAST, SCA).
Infrastructure as Code (IaC): Design and manage secure cloud infrastructure using IaC tools like Terraform to provision and maintain scalable, cost-optimized environments, primarily within AWS.
Cloud Security and Compliance: Ensure continuous adherence to security standards and frameworks such as NIST 800-53, FedRAMP, or similar regulatory requirements. Collaborate with security teams to integrate Zero Trust principles, encryption, access control, and audit logging.
Containerization & Orchestration: Implement and maintain security practices for containerized applications using technologies like Docker and orchestration platforms such as ECS/EKS (Kubernetes).
Monitoring and Observability: Integrate and manage monitoring and observability tools (e.g., CloudWatch, Datadog, Prometheus) to detect and respond to security and performance issues in real-time.
Security Automation: Automate the identification, analysis, and remediation of vulnerabilities across code, infrastructure, and deployment artifacts.
Minimum of 3+ years of professional experience focused on DevSecOps or Cloud Security Engineering.
Deep practical knowledge of DevSecOps practices, secure software development lifecycle (SDLC), and containerization.
Expertise with Infrastructure as Code (IaC) tools, particularly Terraform.
Proven ability to implement and manage CI/CD pipelines for automated deployments and security scans.
Experience with a major cloud provider, with hands-on proficiency in core AWS services.
Familiarity with compliance frameworks like NIST 800-53, FedRAMP, or similar government/industry security standards.
Proficiency in one or more backend languages (e.g., Python, Go, Java) for scripting and tool development.
Phone Number
Job Type
Remote Status
Get notified about new listings!
Can't find the job you want?
Submit a general applicationLoading Jobs...