Summary
✨ AI‑Generated
A technology organization is seeking a senior DevSecOps engineer to embed security practices throughout cloud infrastructure, delivery pipelines, and containerized applications. The role covers automated security testing, identity and access governance, secrets protection, secure infrastructure as code, vulnerability remediation, monitoring, logging, alerting, and threat detection.
Highlights
Lead cloud security integration across infrastructure, CI/CD, and containers, with strong ownership of automated security controls, identity governance, infrastructure security, vulnerability remediation, and threat monitoring.
Description
We are seeking a Senior DevSecOps Engineer with strong AWS and cloud security expertise to lead the integration of security best practices across cloud infrastructure, CI/CD pipelines, and containerized application environments.
Responsibilities
Design and implement secure DevSecOps practices across AWS infrastructure and CI/CD pipelinesIntegrate automated security scanning and validation into GitHub and GitLab workflowsSecure containerized applications deployed in ECS Fargate environmentsImplement and manage SAST, DAST, SCA, and container vulnerability scanning solutionsDevelop and enforce secrets management and credential protection strategiesImplement IAM governance and least-privilege access controls across cloud environmentsSecure Infrastructure-as-Code deployments using Terraform and/or CloudFormationSupport vulnerability remediation, patching, and cloud security monitoring initiativesConfigure monitoring, logging, alerting, and threat detection solutionsPartner with engineering teams to improve security posture and operational resilienceSupport incident response, deployment validation, and security troubleshooting efforts
Required Qualifications
6+ years of DevSecOps, Cloud Security, or Security Engineering experienceStrong AWS experience including ECS Fargate, IAM, RDS, networking, and security monitoringExperience securing CI/CD pipelines using GitHub Actions and/or GitLab CI/CDStrong understanding of SAST, DAST, SCA, container scanning, and vulnerability managementExperience securing Docker containers and Kubernetes/ECS-based workloadsStrong knowledge of secrets management, credential rotation, and least-privilege access controlsExperience securing Infrastructure-as-Code deployments using Terraform or CloudFormationExperience with security monitoring, logging, and threat detection toolsStrong troubleshooting, incident response, and risk assessment skills
Preferred Qualifications
Experience supporting .NET applications in AWS environmentsFamiliarity with AWS Security Hub, GuardDuty, CloudTrail, Datadog, Wiz, Prisma Cloud, or Aqua SecurityExperience supporting compliance frameworks such as SOC 2, ISO 27001, HIPAA, or PCIExperience with automated security governance and policy enforcement toolingSecurity certifications such as AWS Security Specialty, CISSP, Security+, or CKS