Staff DevSecOps Engineer
Staff DevSecOps Engineer designing and automating security controls across AWS infrastructure, containers, CI/CD, and platform services. Requires 7+ years of related experience plus expertise in cloud security, infrastructure as code, hardened images, vulnerability scanning, identity, and secrets management.
About the job
Responsibilities
- Design and implement security controls across AWS infrastructure and platform services.
- Build and maintain hardened container and secure base images for engineering and production workloads.
- Integrate vulnerability, dependency, container, and configuration scanning into software delivery systems.
- Automate security and compliance checks to reduce manual review and improve consistency.
- Implement secrets management, identity, and access controls across infrastructure and engineering systems.
- Build mechanisms for audit evidence, configuration validation, and compliance reporting.
- Identify security weaknesses in infrastructure, containers, and delivery systems and drive remediation.
- Translate security requirements into scalable engineering controls with Cybersecurity and Infosec teams.
- Integrate security controls with Build Engineering and Cloud Engineering while maintaining reliability and developer productivity.
- Define reusable security engineering patterns and drive adoption across multiple teams.
Requirements
- 7+ years of related experience for Staff Engineer, or equivalent education and experience.
- Experience implementing security controls in AWS or another major cloud environment.
- Experience with infrastructure as code and automated infrastructure provisioning.
- Experience securing containerized workloads and maintaining hardened container images.
- Experience integrating security tooling into CI/CD or software delivery systems.
- Experience with vulnerability management, dependency scanning, container scanning, or configuration validation.
- Experience implementing identity, secrets, and access controls in cloud or engineering environments.
- Experience automating security or infrastructure tasks using Python, Go, Bash, or a similar language.
- Ability to diagnose security and configuration issues across infrastructure, containers, and platform services.
- Experience collaborating with security and engineering teams to implement shared technical controls.
Nice-to-haves
- Experience operating systems in regulated or compliance-driven environments.
- Experience with Kubernetes security, workload identity, or container runtime controls.
- Experience building reusable hardened images or secure infrastructure baselines used across multiple teams.
- Experience with cloud security posture management, policy as code, or automated compliance tooling.
- Experience supporting audit evidence collection or continuous compliance workflows.
- Familiarity with software supply-chain security, artifact integrity, or signing and attestation workflows.
Skills
AWS, Infrastructure As Code, Docker, Kubernetes, CI/CD, Vulnerability Management, Dependency Scanning, Secrets Management, Identity And Access Management, Python, Go, Bash, Policy As Code, Cloud Security Posture Management, Supply Chain Security
Similar jobs
DevOps / SRE jobsBuild and operate high-performance customer compute environments spanning bare metal, Kubernetes, Slurm, GPUs, networking, storage, and observability. The role requires 5+ years of production Linux infrastructure experience and strong expertise in bare-metal Kubernetes, NVIDIA GPUs, virtualization, and networking.
Leads strategic production engineering initiatives that improve the reliability, scalability, observability, and security of large-scale platforms. The role requires 7+ years of relevant experience, strong coding skills, and expertise in reliability practices such as SLIs, SLOs, and incident management.
Leads the operational reliability, security, observability, deployment standards, and governance of Databricks for enterprise data workloads. Requires 12+ years in platform, SRE, or cloud data infrastructure engineering plus production Databricks experience and expertise in CI/CD, secure execution, and regulated environments.
Leads the architecture, automation, observability, and reliability of multi-region AWS infrastructure supporting high-throughput payments. Requires 10+ years of distributed-systems experience and deep expertise in cloud infrastructure, Kubernetes, infrastructure as code, and modern SRE practices.
Leads architecture, ownership, modernization, and operation of Komodo Health’s AWS and Kubernetes infrastructure and shared services. The role requires 8+ years of infrastructure experience, deep Terraform and Kubernetes expertise, regulated-environment security fluency, and the ability to establish AI-assisted engineering standards.