Staff DevSecOps Engineer
New
J
JobgetherSecurity & IT
Based in United States, Availability during Eastern Standard Time working hours.Full-TimeStaff
Salary150,000 - 225,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering; 8+ years preferred for Staff-level.
- Required Skills
- CI/CDTerraformLLM
Requirements
- 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering.
- 8+ years of experience preferred for Staff-level candidates with a track record of building security programs.
- Deep hands-on experience securing cloud environments including compute, networking, IAM, and key management.
- Strong infrastructure-as-code expertise, particularly with Terraform and policy-as-code.
- Proven experience implementing CI/CD security controls such as SAST, SCA, secret scanning, and container security.
- Hands-on experience managing vulnerabilities at scale, including triage and SLA-driven remediation.
- Working knowledge of SOC 2 or comparable compliance frameworks.
- Familiarity with CSPM, application security, and SIEM tools.
- Strong coding and scripting skills for building scalable automation and security tooling.
- Experience applying AI and LLM technologies to security operations and automated remediation.
- Ability to collaborate effectively across engineering, security, and GRC teams.
Responsibilities
- Own the engineering side of the SOC 2 Type 2 compliance program, including control implementation and audit readiness.
- Operate and improve compliance automation platforms, evidence pipelines, and control mappings.
- Productize compliance through policy-as-code and security guardrails embedded into developer workflows.
- Manage cloud security posture and runtime security capabilities, including container and IaC scanning.
- Build automated, AI-assisted remediation pipelines to detect and resolve security findings with minimal manual intervention.
- Design and maintain CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, and dependency management.
- Develop reusable infrastructure modules and internal tooling to scale security operations.
View Full Description & ApplyYou'll be redirected to the employer's site