Staff DevSecOps Engineer

🏢 Jobgether · all 1672 jobs
📍 Remote US
📅 Posted Sep 21, 2026 · via Lever
Apply on original site ↗

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff DevSecOps Engineer based in United States.

This role offers the opportunity to shape and own the security foundations that enable modern product engineering at scale. You’ll lead the engineering side of cloud security and compliance while building secure-by-default practices directly into development workflows. Rather than focusing on reactive ticket resolution, you’ll create reusable platforms, automation, and guardrails that allow engineers to move quickly without compromising security. You’ll have broad technical ownership across infrastructure, CI/CD, vulnerability management, compliance, and runtime security. The role also provides an opportunity to apply AI and agentic tooling to reduce manual security work and accelerate remediation. You’ll work closely with security and GRC partners while helping mature an internal security capability.

Accountabilities:
- Own the engineering side of the SOC 2 Type 2 compliance program, including control implementation, evidence collection, and audit readiness.

- Operate and improve compliance automation platforms, integrations, evidence pipelines, and control mappings.

- Productize compliance through policy-as-code, automated evidence generation, and security guardrails embedded into engineering workflows.

- Own cloud security posture management and runtime security capabilities, including posture monitoring, container scanning, infrastructure-as-code scanning, and runtime coverage.

- Triage, prioritize, and remediate security findings against defined SLAs while developing automation and alerting to manage security at scale.

- Build automated remediation workflows, including AI-assisted pipelines that can detect, create, and safely resolve security findings with minimal manual intervention.

- Design and maintain CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container and IaC scanning.

- Encode security and compliance requirements into infrastructure-as-code and policy-as-code so secure practices become the default path for engineering teams.

- Help transition prototypes into production-ready systems by introducing secure-by-default architectures and automated controls.

- Develop reusable infrastructure modules, pipeline components, internal tooling, and AI/agentic capabilities that turn security operations into scalable self-service functionality.

- Partner with corporate security and GRC teams while strengthening the organization’s internal security engineering capabilities and decision-making processes.

Requirements:

- 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus; Staff-level candidates should have 8+ years and a track record of building security functions or programs.

- Deep hands-on experience securing cloud environments, including compute, networking, IAM, key management, and logging on a major cloud platform.

- Strong infrastructure-as-code expertise, particularly with Terraform and policy-as-code.

- Proven experience implementing CI/CD security controls such as SAST, SCA, secret scanning, dependency scanning, and container security within developer workflows.

- Hands-on experience managing vulnerabilities at scale, including triage, prioritization, SLA-driven remediation, and automation.

- Working knowledge of SOC 2 or comparable compliance frameworks, including implementing and evidencing controls within real engineering environments.

- Familiarity with modern security tooling across CSPM, application security, SAST, secret scanning, compliance automation, and SIEM.

- Strong coding and scripting skills with the ability to build scalable automation, pipelines, infrastructure modules, and security tooling rather than simply configure existing products.

- Experience establishing or matur

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote it jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you