Senior DevSecOps Engineer

Soni Resources Group — United States · Posted ~2 hours ago

Senior Full-time

Skills

AWS cloud security DevSecOps CI/CD GitHub GitLab ECS Fargate SAST DAST SCA container security secrets management IAM Terraform CloudFormation vulnerability management security monitoring

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A technology organization is seeking a senior DevSecOps engineer to embed security practices throughout cloud infrastructure, delivery pipelines, and containerized applications. The role covers automated security testing, identity and access governance, secrets protection, secure infrastructure as code, vulnerability remediation, monitoring, logging, alerting, and threat detection.

Highlights

Lead cloud security integration across infrastructure, CI/CD, and containers, with strong ownership of automated security controls, identity governance, infrastructure security, vulnerability remediation, and threat monitoring.

Description

We are seeking a Senior DevSecOps Engineer with strong AWS and cloud security expertise to lead the integration of security best practices across cloud infrastructure, CI/CD pipelines, and containerized application environments. Responsibilities Design and implement secure DevSecOps practices across AWS infrastructure and CI/CD pipelinesIntegrate automated security scanning and validation into GitHub and GitLab workflowsSecure containerized applications deployed in ECS Fargate environmentsImplement and manage SAST, DAST, SCA, and container vulnerability scanning solutionsDevelop and enforce secrets management and credential protection strategiesImplement IAM governance and least-privilege access controls across cloud environmentsSecure Infrastructure-as-Code deployments using Terraform and/or CloudFormationSupport vulnerability remediation, patching, and cloud security monitoring initiativesConfigure monitoring, logging, alerting, and threat detection solutionsPartner with engineering teams to improve security posture and operational resilienceSupport incident response, deployment validation, and security troubleshooting efforts Required Qualifications 6+ years of DevSecOps, Cloud Security, or Security Engineering experienceStrong AWS experience including ECS Fargate, IAM, RDS, networking, and security monitoringExperience securing CI/CD pipelines using GitHub Actions and/or GitLab CI/CDStrong understanding of SAST, DAST, SCA, container scanning, and vulnerability managementExperience securing Docker containers and Kubernetes/ECS-based workloadsStrong knowledge of secrets management, credential rotation, and least-privilege access controlsExperience securing Infrastructure-as-Code deployments using Terraform or CloudFormationExperience with security monitoring, logging, and threat detection toolsStrong troubleshooting, incident response, and risk assessment skills Preferred Qualifications Experience supporting .NET applications in AWS environmentsFamiliarity with AWS Security Hub, GuardDuty, CloudTrail, Datadog, Wiz, Prisma Cloud, or Aqua SecurityExperience supporting compliance frameworks such as SOC 2, ISO 27001, HIPAA, or PCIExperience with automated security governance and policy enforcement toolingSecurity certifications such as AWS Security Specialty, CISSP, Security+, or CKS