Remote job
DevOps Security Engineer (Trust Infra - Replacement)
Job details
About this role
Role overview A contract opportunity for a DevOps Security Engineer focused on building and operating the foundational security and reliability tooling that supports engineering teams. The work blends cloud infrastructure engineering, security best practices, and DevOps automation to keep internal platforms secure, scalable, and highly available. The team owns core trust artifacts including secrets management, authentication and authorization, cryptography, and certificate workloads inside Kubernetes and cloud environments.
Responsibilities - Design, implement, and maintain security-focused tooling and guardrails for infrastructure and service provisioning. - Collaborate with security engineering, SRE, and platform teams to embed trust principles across the engineering lifecycle. - Implement best practices for secrets management, certificate lifecycle automation, and identity and authentication controls. - Lead the design and improvement of AWS-native architectures that support secure, scalable, and resilient services. - Apply Infrastructure as Code with Terraform to standardize infrastructure patterns and manage Kubernetes cluster configurations, Helm charts, and Operator patterns. - Build internal tools and automation that reduce developer cognitive load while enforcing security standards, and monitor infrastructure health, compliance drift, and policy violations.
Requirements - 5+ years of hands-on experience operating Kubernetes and security workloads in production environments. - Deep expertise in Kubernetes resource management, Helm charts, and operator patterns centered around security workloads. - Strong understanding of Helm, including templating, dependency management, and release lifecycle practices. - Advanced troubleshooting skills for distributed systems using observability tools such as Prometheus, Grafana, and tracing systems. - Proven ability to execute complex infrastructure migrations with minimal service disruption.
Nice to have - Familiarity with CNCF ecosystem tooling and GitOps-based deployment models. - Prior experience designing and implementing secure infrastructure guardrails on Kubernetes such as external-secrets-operator and cert-manager. - Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.