Senior / Staff DevSecOps Engineer
Builds and owns security infrastructure including runtime security, IAM, secrets management, CI/CD hardening, and compliance for cloud/container environments. Embeds with engineering teams to enable secure-by-default development using AWS, Terraform, and policy-as-code tools. Requires 8+ years DevSecOps experience.
About the job
Responsibilities
- Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
- Design and enforce identity and access management (IAM) across AWS and internal systems — least-privilege by default.
- Own secrets and credentials management: policies, tooling, rotation, and developer workflows.
- Lead security incident response: detection, containment, root cause analysis, and durable remediation.
- Manage AWS Organization structure, account boundaries, SCPs, and guardrails.
- Harden and maintain CI/CD pipelines, embedding security scanning and policy enforcement.
- Drive compliance efforts — own the evidence, controls, and remediation work to meet relevant frameworks.
- Build and maintain secure-by-default templates for repos, pipelines, and infrastructure modules.
- Reduce friction through automation: certificate issuance, secrets access, policy-as-code, and developer-facing tooling.
- Produce lightweight, practical security guidance for engineers.
Requirements
- 8+ years in DevSecOps, platform security, or related security engineering role.
- Deep hands-on experience with AWS — IAM, SCPs, Organizations, security services (GuardDuty, Security Hub, CloudTrail).
- Strong IaC experience with Terraform; enforce security controls, policy-as-code (OPA, Checkov, tfsec), continuous compliance (AWS Config Rules).
- Experience owning secrets management end-to-end in production.
- Proven track record designing and hardening CI/CD pipelines (GitHub Actions).
- Hands-on with container security, including image scanning and runtime controls.
- Experience leading or contributing to compliance program; CMMC Level 2 or NIST SP 800-171 preferred.
- Run incident response — on call, post-mortem, shipped fixes.
- Strong communication skills to drive security adoption.
Nice To Haves
- Experience growing a DSO or security engineering function.
- Familiarity with observability tooling (LGTM stack) for security signals.
- Background in configuration management (Ansible).
- Experience with developer-facing security platforms or internal tooling.
- Interest in growing into lead or manager role.
Tech Environment
- Cloud: AWS, Terraform, Ansible
- Containers: Docker, Docker Compose
- CI/CD: GitHub Actions
- Vulnerability scanning: Trivy
- Observability: Grafana, Loki, Tempo, Mimir
- Alerting: PagerDuty
- Languages: Go, TypeScript/Node, React, Python
Skills
AWS, Terraform, IAM, Scps, Guardduty, Security Hub, Cloudtrail, Opa, Checkov, Tfsec, GitHub Actions, Docker, Trivy, Ansible, Pagerduty
Similar jobs
DevOps / SRE jobsStaff-level site reliability engineer responsible for safely deploying and operating safeguards infrastructure across model releases and cloud platforms. The role emphasizes production change management, high-stakes incident response, and automating manual launch and validation processes.
Staff Infrastructure Engineer responsible for designing and operating scalable infrastructure for growth systems, including onboarding, referrals, and user acquisition. The role requires 7+ years of production infrastructure experience, strong reliability instincts, and independent judgment in a high-autonomy environment.
Leads the architecture, development, and operation of cloud, Kubernetes, on-premises, and hybrid infrastructure, while building developer platforms and CI/CD automation. Requires at least six years of infrastructure or related engineering experience, deep Kubernetes expertise, strong programming skills, and technical leadership.
Own the network architecture and standards for a multi-cloud enterprise AI platform deployed across Kubernetes environments and customer-controlled networks. The role requires deep cloud and Kubernetes networking expertise, strong security fundamentals, and the judgment to establish scalable, supportable connectivity patterns.
Staff Platform Engineer will build and improve automated delivery pipelines, developer environments, infrastructure, and release systems across the engineering organization. The role requires 6+ years of engineering experience, a bachelor’s degree, and expertise with CI/CD, cloud infrastructure, containers, and infrastructure as code.