← Back to jobs

Remote job

DevSecOps Engineer

DevOps Full-time Permanent Panama

Job details

Not specified Salary
Panama Eligibility
Principal Experience
Full-time Employment

About this role

Role overview A DevSecOps Engineer role responsible for executing security engineering across cloud infrastructure, CI/CD pipelines, and production applications. The position reports to a Principal Security Engineer and focuses on implementing and continuously validating security controls, delivering infrastructure and application improvements, supporting continuous audit readiness, and translating security and compliance requirements into practical engineering solutions.

Responsibilities - Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications, with a focus on continuous audit readiness. - Author and maintain infrastructure as code in Terraform or similar tools across QA, staging, and production environments. - Deliver production code that addresses authentication, single sign-on, authorization, session security, and vulnerability remediation, including work on OAuth 2.0, OpenID Connect, SAML, and identity lifecycle automation. - Manage vulnerability remediation end to end across static and dynamic application security testing, dependency scanning, and container scanning, and address penetration test findings with evidence-based responses. - Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence, and maintain cryptographic compliance across TLS, DNS, and certificate posture. - Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and AI-assisted workflows, and maintain security architecture documentation such as authorization boundaries and data flow diagrams. - Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, supply chain security, logging coverage, and user access reviews.

Requirements - Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or equivalent combination of education and experience. - At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering. - Production software development experience in Go, Python, TypeScript, or a comparable modern language, plus scripting and automation using Python, shell, SQL, or similar tools. - Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting. - Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration, plus experience with Terraform or a similar infrastructure as code platform in production. - Demonstrated experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation, and using agentic AI development tools to support coding, integrations, and workflow automation. - Strong written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks.

Nice to have - Experience working in regulated or compliance-driven environments and familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar frameworks. - Familiarity with FIPS 140-2 or FIPS 140-3, fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling. - Certifications such as CISSP, CCSP, GCP Professional Cloud Security Engineer, or AWS Certified Security Specialty.

Benefits and work setup - Employer-paid life and health insurance, competitive bonus structure, home office reimbursement, and technology allowance. - Certification reimbursement, personalized career coaching, and a discount loyalty program. - Generous paid time off, paid office closure from December 25 to January 1, and summer hours.

Skills detected in the listing

TypeScriptPythonGoSQLInformation SecurityAWSGCPAzureTerraform
Detected Oct 2, 2026
Last verified Oct 6, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight