Summary
✨ AI‑Generated
Lead the integration of security throughout cloud infrastructure, delivery pipelines, and containerized applications. You will implement automated security testing, strengthen identity and secrets management, secure infrastructure-as-code, and improve monitoring, threat detection, and vulnerability remediation.
Highlights
Lead cloud security practices across infrastructure, CI/CD, containers, identity, infrastructure-as-code, monitoring, and vulnerability management.
Description
We are seeking a Senior DevSecOps Engineer with strong AWS and cloud security expertise to lead the integration of security best practices across cloud infrastructure, CI/CD pipelines, and containerized application environments.
Responsibilities
Design and implement secure DevSecOps practices across AWS infrastructure and CI/CD pipelinesIntegrate automated security scanning and validation into GitHub and GitLab workflowsSecure containerized applications deployed in ECS Fargate environmentsImplement and manage SAST, DAST, SCA, and container vulnerability scanning solutionsDevelop and enforce secrets management and credential protection strategiesImplement IAM governance and least-privilege access controls across cloud environmentsSecure Infrastructure-as-Code deployments using Terraform and/or CloudFormationSupport vulnerability remediation, patching, and cloud security monitoring initiativesConfigure monitoring, logging, alerting, and threat detection solutionsPartner with engineering teams to improve security posture and operational resilienceSupport incident response, deployment validation, and security troubleshooting efforts
Required Qualifications
6+ years of DevSecOps, Cloud Security, or Security Engineering experienceStrong AWS experience including ECS Fargate, IAM, RDS, networking, and security monitoringExperience securing CI/CD pipelines using GitHub Actions and/or GitLab CI/CDStrong understanding of SAST, DAST, SCA, container scanning, and vulnerability managementExperience securing Docker containers and Kubernetes/ECS-based workloadsStrong knowledge of secrets management, credential rotation, and least-privilege access controlsExperience securing Infrastructure-as-Code deployments using Terraform or CloudFormationExperience with security monitoring, logging, and threat detection toolsStrong troubleshooting, incident response, and risk assessment skills
Preferred Qualifications
Experience supporting .NET applications in AWS environmentsFamiliarity with AWS Security Hub, GuardDuty, CloudTrail, Datadog, Wiz, Prisma Cloud, or Aqua SecurityExperience supporting compliance frameworks such as SOC 2, ISO 27001, HIPAA, or PCIExperience with automated security governance and policy enforcement toolingSecurity certifications such as AWS Security Specialty, CISSP, Security+, or CKS