Description
We are seeking a DevSecOps Engineer to join our Engineering team.
This role is critical to securing, hardening, and scaling the infrastructure that powers our platform across cloud-hosted production environments.
This engineer will work closely with platform, infrastructure, and security stakeholders to improve the security and operational maturity of our AWS and Kubernetes environments, support compliance and audit readiness, and help ensure our systems are reliable, secure, and maintainable as we grow.
This role will also support environments serving regulated and security-sensitive customer needs, including an environment we host for a Government organization.
The ideal candidate combines strong hands-on infrastructure expertise with sound security judgment and a practical, execution-focused mindset.
They should be comfortable working across cloud infrastructure, Kubernetes, operating systems, compliance controls, and production operations.
Core Responsibilities
Responsibilities include collaborating with the platform and engineering teams to secure and improve production infrastructure, harden cloud and host configurations, and build repeatable operational practices across environments.
Key responsibilities include:
Design, implement, and maintain secure, scalable infrastructure in AWSManage, secure, and improve Kubernetes-based environments, including production workloadsBuild and maintain infrastructure as code using TerraformHarden production systems across cloud, compute, container, identity, and network layersDevelop and maintain secure baseline configurations for infrastructure and platform servicesSupport vulnerability management, patching, remediation, and configuration compliance efforts across environmentsConfigure, administer, and patch both Linux and Windows VMsSupport identity and access management practices, including least privilege, role design, and privileged access controlsContribute to administration and integration of Active Directory domains where neededPartner with engineering teams to improve security within CI/CD pipelines, deployment workflows, and operational processesSupport compliance initiatives, audits, evidence collection, and technical control validationDevelop and maintain documentation, operational runbooks, technical standards, and playbooksMonitor, troubleshoot, and resolve complex infrastructure and security issues with clear and timely communicationParticipate in incident response and post-incident analysis when infrastructure or platform issues ariseStay current on cloud, infrastructure, and security best practices that can improve platform resilience and delivery
Required Qualifications
Minimum of 5 years of experience in DevOps, DevSecOps, Infrastructure Engineering, Platform Engineering, or Security EngineeringStrong hands-on experience with AWS in production environmentsProven experience with Kubernetes, preferably in productionStrong experience with Terraform and infrastructure-as-code practicesExperience hardening production environments and implementing secure configuration standardsExperience supporting compliance frameworks, audit preparation, evidence gathering, and control validationExperience with vulnerability remediation, system patching, and operational security practicesExperience configuring and maintaining both Linux and Windows virtual machinesStrong understanding of IAM, secrets management, network security, logging, monitoring, and operational controlsProven experience improving or securing CI/CD pipelines and deployment workflowsExcellent troubleshooting and problem-solving skills in complex production environmentsStrong communication skills with the ability to explain technical concepts to both technical and non-technical stakeholdersMust live/work in the U.S.
Preferred Qualifications
Experience supporting environments with regulated, compliance-driven, or security-sensitive requirementsFamiliarity with compliance or security frameworks such as SOC 2, NIST, ISO 27001, CMMC, or similarExperience with EKS or other managed Kubernetes platformsExperience configuring or supporting Active Directory Domain Services, Group Policy, or hybrid identity environmentsExperience with automation and configuration management tools such as Ansible, PowerShell, or similarExperience with PostgreSQL, cloud storage platforms, and production networking patternsScripting experience in Python, Bash, or PowerShellExperience with security tooling related to container security, vulnerability management, or policy enforcementExperience supporting customer-facing or mission-critical production infrastructureSecurity+ CertificationTop Secret Security Clearance
About Istari Digital
Istari is a digital engineering software company building open, scalable infrastructure for engineering data.
Our platform lets customers simply and securely integrate engineering models across disciplines, organizations, and security levels โ whether they're designing prototypes, performing virtual testing, or training AI and autonomy for complex systems.
Focus is rewarded.
Finish is remembered.
Facts are friendly.
Even when they are not fun.
Fellowship is fundamental.
Make others successful.