Mid Dev Sec Ops Engineer

🏒 Peek · all 17 jobs
πŸ“ Mexico
πŸ’° MXN 75,000 - 85,000 / monthly
πŸ“… Posted Sep 23, 2026 Β· via Himalayas
🏷 Middle DevOps Engineer, Mid Level DevOps Engineer, Mid Level Security Engineer, Security DevOps Engineer, Devsecops Engineer, DevOps Security Engineer
Apply on original site β†—

Peek is the operating system powering the experiences industry - from museums and attractions to tours and activities. With over $7B in bookings, Peek ’s AI-powered platform has helped thousands of merchants to increase revenues, save time, and deliver seamless guest experiences. Customers include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park & Looping Group. The company has raised over $150 million from institutional investors Westcap, Goldman Sachs, and SpringCoast Partners. Learn more at .

As a remote-first company recognized by Forbes as one of America's Best Startup Employers and by Built In as a 2025 and 2026 Best Place to Work, we are a global team of " Peek sters" who "Obsess Over Our Customers," "Accomplish Big Things," "Collaborate With Purpose," and "Get Better Every Day.

We're looking for a hands-on DevSecOps Engineer to embed security into our infrastructure, CI/CD pipelines, and cloud environment. You'll own the technical controls and evidence that keep us PCI DSS 4.0 and SOC 2 Type II compliant, drive vulnerability remediation across our container and VM fleet, and build out the disaster recovery testing program. This is a role for someone who's comfortable moving between hands-on technical remediation, audit-facing documentation, and cross-functional work with engineering, IT, and procurement.

Our team is 100% remote, however, we prefer candidates in the same time zones as the greater United States (UTC-10 to UTC-4).

We will occasionally require you to work outside of normal business hours on infrastructure upgrades and maintenance. We are committed to working with you to keep a healthy and balanced schedule.
About the Team

We’re a small DevOps team supporting the whole Engineering organization, building applications on top of GCP and AWS. We own all aspects of the SDLC but strive to automate self-service wherever possible. Being a small team, we also practice SRE, continuously improving our observability and building with Infrastructure-as-Code. Security and compliance best practices are integral to our workflows, ensuring systems are secure by design and meet regulatory and organizational standards. Our team is remote but highly organized to meet the demand of a fast-paced environment. Our primary business language is English, and we emphasize strong communication skills.
About You

You're a security-minded engineer who's as comfortable in a Kubernetes cluster or CI/CD pipeline as you are explaining a control to an auditor. You own remediation end to end, like automating away repetitive security work, and are energized by helping a growing company scale security without slowing the business down.
What You'll Do

-
Own technical security controls across GCP and AWS: least-privilege IAM and RBAC, WAF, container and image security, and secure CI/CD.

-
Drive vulnerability remediation end to end: triage, prioritize, and automate fixes, partnering with the rest of the DevOps team on production rollout.

-
Build automated scanning and remediation into our pipelines.

-
Tune WAF policies and the OWASP Core Rule Set to protect public-facing applications without blocking legitimate traffic.

-
Run PCI DSS vulnerability scanning, including quarterly external ASV scans, and drive remediation of findings.

-
Contribute to incident response planning and exercises, and ensure backups and recovery processes meet security requirements for encryption, access, and integrity.

-
Produce and automate evidence for technical controls, and keep our cloud environments connected to our compliance platform (Drata).

-
Serve as technical expert for audits, customer security reviews, and vendor assessments involving sensitive data.

Requirements

-
3+ years in DevSecOps, security engineering, cloud security, or a closely related role

-
Hands-on experience securing GCP and/or AWS, including managed Kubernetes (GKE, EKS)

-
Container and vulnerability management, including building automated remediation (tools

Flights + hotels

This role requires you to be in Mexico. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels β†’

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs β†’
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you