Remote job
DevSecOps Engineer
Job details
About this role
Role overview Build and strengthen the security foundation across cloud infrastructure, CI/CD systems, application delivery workflows, and internal engineering operations. The role sits at the intersection of security, DevOps, and platform engineering, making environments secure by default, continuously validated, and resilient as systems scale.
Responsibilities - Own security across cloud infrastructure, CI/CD pipelines, Kubernetes environments, and platform operations. - Design secure-by-default infrastructure, deployment, and access control patterns, and harden cloud workloads, secrets handling, IAM configurations, and network boundaries. - Integrate security checks into CI/CD, including code scanning, dependency scanning, secret scanning, container scanning, and policy enforcement. - Build and maintain security guardrails for Terraform, Kubernetes, cloud services, and application deployment workflows. - Monitor, investigate, and respond to security findings across infrastructure, pipelines, containers, and production systems, partnering with engineering teams on remediation. - Define policies for secrets management, least-privilege access, environment separation, and secure service-to-service communication, and support incident response, forensic investigation, and post-incident hardening.
Requirements - Significant experience owning security for cloud infrastructure, CI/CD, and Kubernetes-based platforms. - Strong background in DevSecOps, application security, or platform security engineering. - Hands-on experience hardening cloud environments, IAM, secrets, and network boundaries. - Skill integrating automated security checks into build and deployment pipelines. - Experience with infrastructure-as-code tools such as Terraform and policy enforcement in cloud and Kubernetes environments. - Ability to support incident response and forensic investigation across infrastructure and production systems.
Nice to have - Experience turning security practices into practical, developer-friendly systems and guardrails. - Familiarity with regulated environments and healthcare-adjacent data protection.