DevSecOps Engineer
You must be able to work from the United States — the posting restricts this role to applicants there.
Overview
We are designing the grid of the future!
We are seeking an experienced DevSecOps Engineer to strengthen the security of our cloud platforms, software delivery pipelines, and production environments. The ideal candidate will combine deep AWS, Terraform, Kubernetes, and automation expertise with a strong security engineering mindset. This role will embed security throughout the software and infrastructure lifecycle, automate security controls, reduce cloud and application risk, and help engineering teams ship securely without creating unnecessary delivery friction.
The DevSecOps Engineer will partner closely with software engineering, Site Reliability Engineering, platform, security, compliance, and product teams to establish secure-by-default patterns, improve visibility into risk, and ensure that security controls are measurable, scalable, and operationally sustainable.
Responsibilities
How you can make an impact:
-
Cloud Security Engineering: Design, implement, and maintain security controls across AWS environments, including IAM, VPC networking, encryption, secrets management, logging, account governance, and service configuration.
-
Infrastructure as Code Security: Build and maintain secure Terraform modules and policies that enforce approved infrastructure patterns, least privilege, encryption, logging, tagging, network controls, and configuration standards.
-
Secure CI/CD: Integrate security checks into CI/CD pipelines, including static analysis, dependency scanning, container scanning, secrets detection, infrastructure-as-code scanning, policy validation, and deployment gates.
-
Kubernetes & Container Security: Harden EKS and Kubernetes environments through secure workload configuration, RBAC, admission controls, image security, runtime protections, network policies, secrets management, and cluster lifecycle best practices.
-
Identity & Access Management: Develop and enforce least-privilege IAM patterns, role-based access controls, service identities, access review processes, and automated remediation for excessive or unused permissions.
-
Vulnerability Management: Establish processes and automation for identifying, prioritizing, tracking, and remediating vulnerabilities across cloud infrastructure, containers, dependencies, operating systems, and application platforms.
-
Security Automation: Build Python, Bash, or other automation to detect misconfigurations, validate controls, collect evidence, remediate security findings, and reduce repetitive security operations work.
-
Cloud Detection & Monitoring: Implement and improve security monitoring, logging, alerting, and detection capabilities using AWS-native and third-party tooling, including CloudTrail, GuardDuty, Security Hub, CloudWatch, SIEM platforms, or similar technologies.
-
Software Supply Chain Security: Improve software supply chain integrity through dependency controls, artifact signing, provenance, trusted build pipelines, image registries, SBOM practices, and secure release processes.
-
Secrets & Key Management: Establish secure patterns for credentials, API keys, certificates, encryption keys, and secrets using services such as AWS KMS, Secrets Manager, Parameter Store, and related tooling.
-
Security Incident Response: Support investigation and response for cloud and application security incidents, including containment, root-cause analysis, evidence collection, remediation, and post-incident corrective actions.
-
Compliance & Control Automation: Translate security and compliance requirements into technical controls and automated evidence collection for frameworks such as SOC 2, ISO 27001, PCI DSS, or related standards.
-
Security Architecture & Reviews: Perform security reviews for infrastructure changes, new services, deployment patterns, and application architectures; identify risk and recommend practical mitigations.
-
Developer Enablement: Create reusable security patterns, documentation, guar
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels →Get remote developer jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks — continue to the application ↗