Overview
In this role you embed security into engineering platforms and pipelines to enable secure-by-default software delivery. You will lead hands-on security efforts across cloud-native apps, containers, and automated pipelines, partnering with engineering teams to scale secure tooling. Your work shapes developer experiences and governance, balancing security posture with velocity. This position offers impact across AWS/Azure, modern IaC, and platform-level security initiatives.
Pay / Benefits
- Health & Wellness coverage
- Flexible downtime
- Continuous learning resources
- Retirement planning and education program with student loan contribution
- Family-friendly perks
- Career development opportunities
Responsibilities
- Embed automated security controls into CI/CD pipelines across build, test, and release stages with risk-based gates and comprehensive testing (SAST, DAST, SCA, container scanning)
- Build and maintain internal DevSecOps tooling and platform extensions, including reusable pipeline libraries and security plugins
- Design paved-road security patterns and self-service tooling to streamline secure development
- Drive cloud-native security architecture for Kubernetes, containerized workloads, and IaC using modern security frameworks
- Evaluate and integrate security tools to standardize and reduce complexity while improving effectiveness
- Translate regulatory requirements into automated engineering controls and support audit readiness through automated evidence collection
- Provide technical leadership and mentorship as an embedded security SME to raise DevSecOps maturity
- Lead vulnerability management and remediation across app, pipeline, and cloud environments, participating in threat modeling and architecture reviews
Key requirements
- 8+ years in software engineering, DevOps, or DevSecOps in enterprise or regulated environments with hands-on CI/CD security experience
- Practical expertise with AWS, Azure, or Google Cloud, container tech (Docker, Kubernetes, OpenShift), and IaC tools (Terraform, CloudFormation, or Pulumi)
- Strong understanding of OWASP Top 10, secure coding practices, and experience with SAST, DAST, and SCA tools
- Proven ability to build and maintain internal tooling with scripting (Python, Go, or similar)
- Excellent technical communication and ability to articulate risks to engineering and business stakeholders
- Strong collaboration and influence, embedding within engineering teams to drive adoption
- Experience with CI/CD design, Git, and Agile methodologies
- Advanced DevSecOps platform experience and familiarity with SAST/DAST/SCA platforms (preferred)
- Cloud security expertise with CSPM/CNAPP, secrets management (HashiCorp Vault or cloud-native), zero trust or identity-centric security architectures
- Professional security certifications or cloud security credentials (preferred)
- collaboration
- influence
- clear communication
- CI/CD security
- SAST/DAST/SCA tooling
- Kubernetes security
…
