Security Engineer
Senior DevSecOps Engineer responsible for securing AWS and Kubernetes platforms, embedding automated security controls into CI/CD pipelines, leading threat modeling and incident response, and translating compliance requirements into scalable engineering guardrails. Requires 7+ years of security or cloud infrastructure experience.
About the job
Responsibilities
- Lead hands-on threat modeling assessments for new features across AWS services.
- Build, maintain, and enforce automated SAST, DAST, and SCA testing frameworks in AWS delivery pipelines.
- Design and manage security guardrails across AWS environments, Kubernetes clusters, Docker containers, and infrastructure-as-code deployments.
- Implement policy-as-code and compliance guardrails for ISO 27001, SOC 2, and TX-RAMP requirements.
- Evaluate and integrate AI-assisted tools for code reviews, log analysis, and vulnerability triage; establish secure usage guidelines for developer AI tools.
- Lead security incident investigations and root-cause analyses.
- Mentor developers on secure coding, threat identification, and vulnerability remediation.
Requirements
- 7+ years of experience in security engineering, DevSecOps, software development, or cloud infrastructure security.
- Proven experience securing multi-account AWS environments and infrastructure-as-code deployments.
- Expertise in IAM/Identity Center, network security, encryption, Docker, ECS/Fargate, Terraform, CloudFormation/CDK, Security Hub, and GuardDuty.
- Strong experience integrating security tools into CI/CD pipelines.
- Ability to write automation scripts in Python or Bash.
- Experience using AI tools such as automated code reviewers, LLM tools, or AI-driven security scanners.
- Experience securing AI systems, AI supply chains, or AI-assisted workflows.
- Proven ability to assess application architectures and mitigate OWASP Top 10 vulnerabilities.
- Understanding of translating compliance requirements into automated checks without slowing software releases.
Nice-to-haves
- CISSP, AWS Certified Security – Specialty, or Certified Kubernetes Security Specialist (CKS) certification.
- Experience securing video-streaming architectures or high-scale backend services.
- Experience implementing policy-as-code frameworks in regulated SaaS environments.
Compensation
- Annual salary: $150,000.
Skills
AWS, Kubernetes, Docker, Terraform, CloudFormation, Aws Cdk, Python, Bash, CI/CD, SAST, DAST, Sca, Threat Modeling, Policy-As-Code, Owasp Top 10
Similar jobs
Security Engineering jobsBuild and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
Own Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.