Senior DevSecOps Engineer

Soni Resources Group — United States · Posted ~1 hour ago

Senior Full-time

Skills

AWS Cloud security DevSecOps CI/CD GitHub GitLab ECS Fargate SAST DAST SCA Container security IAM Terraform CloudFormation

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Lead the integration of security throughout cloud infrastructure, delivery pipelines, and containerized applications. You will implement automated security testing, strengthen identity and secrets management, secure infrastructure-as-code, and improve monitoring, threat detection, and vulnerability remediation.

Highlights

Lead cloud security practices across infrastructure, CI/CD, containers, identity, infrastructure-as-code, monitoring, and vulnerability management.

Description

We are seeking a Senior DevSecOps Engineer with strong AWS and cloud security expertise to lead the integration of security best practices across cloud infrastructure, CI/CD pipelines, and containerized application environments. Responsibilities Design and implement secure DevSecOps practices across AWS infrastructure and CI/CD pipelinesIntegrate automated security scanning and validation into GitHub and GitLab workflowsSecure containerized applications deployed in ECS Fargate environmentsImplement and manage SAST, DAST, SCA, and container vulnerability scanning solutionsDevelop and enforce secrets management and credential protection strategiesImplement IAM governance and least-privilege access controls across cloud environmentsSecure Infrastructure-as-Code deployments using Terraform and/or CloudFormationSupport vulnerability remediation, patching, and cloud security monitoring initiativesConfigure monitoring, logging, alerting, and threat detection solutionsPartner with engineering teams to improve security posture and operational resilienceSupport incident response, deployment validation, and security troubleshooting efforts Required Qualifications 6+ years of DevSecOps, Cloud Security, or Security Engineering experienceStrong AWS experience including ECS Fargate, IAM, RDS, networking, and security monitoringExperience securing CI/CD pipelines using GitHub Actions and/or GitLab CI/CDStrong understanding of SAST, DAST, SCA, container scanning, and vulnerability managementExperience securing Docker containers and Kubernetes/ECS-based workloadsStrong knowledge of secrets management, credential rotation, and least-privilege access controlsExperience securing Infrastructure-as-Code deployments using Terraform or CloudFormationExperience with security monitoring, logging, and threat detection toolsStrong troubleshooting, incident response, and risk assessment skills Preferred Qualifications Experience supporting .NET applications in AWS environmentsFamiliarity with AWS Security Hub, GuardDuty, CloudTrail, Datadog, Wiz, Prisma Cloud, or Aqua SecurityExperience supporting compliance frameworks such as SOC 2, ISO 27001, HIPAA, or PCIExperience with automated security governance and policy enforcement toolingSecurity certifications such as AWS Security Specialty, CISSP, Security+, or CKS