Loading...

DevSecOps Engineer

  • Company: Get A Job.ai
  • Location: United States
  • Salary: Pay not listed

Website Get A Job.ai

Represented by Get A Job.ai

Overview

We are representing a confidential energy infrastructure organization that is building the next generation of secure, resilient power systems. Our client seeks an experienced DevSecOps Engineer to embed security throughout their cloud platforms, software delivery pipelines, and production environments. This role combines deep AWS, Terraform, Kubernetes, and automation expertise with security engineering principles to help development teams ship securely without creating unnecessary friction.

The DevSecOps Engineer will partner with software engineering, Site Reliability Engineering, platform, security, compliance, and product teams to establish secure-by-default patterns, improve visibility into risk, and ensure security controls are measurable, scalable, and operationally sustainable.

Responsibilities

How you can make an impact:

  • Cloud Security Engineering: Design, implement, and maintain security controls across AWS environments, including IAM, VPC networking, encryption, secrets management, logging, account governance, and service configuration
  • Infrastructure as Code Security: Build and maintain secure Terraform modules and policies that enforce approved infrastructure patterns, least privilege, encryption, logging, tagging, network controls, and configuration standards
  • Secure CI/CD: Integrate security checks into CI/CD pipelines, including static analysis, dependency scanning, container scanning, secrets detection, infrastructure-as-code scanning, policy validation, and deployment gates
  • Kubernetes & Container Security: Harden EKS and Kubernetes environments through secure workload configuration, RBAC, admission controls, image security, runtime protections, network policies, secrets management, and cluster lifecycle best practices
  • Identity & Access Management: Develop and enforce least-privilege IAM patterns, role-based access controls, service identities, access review processes, and automated remediation for excessive or unused permissions
  • Vulnerability Management: Establish processes and automation for identifying, prioritizing, tracking, and remediating vulnerabilities across cloud infrastructure, containers, dependencies, operating systems, and application platforms
  • Security Automation: Build Python, Bash, or other automation to detect misconfigurations, validate controls, collect evidence, remediate security findings, and reduce repetitive security operations work
  • Cloud Detection & Monitoring: Implement and improve security monitoring, logging, alerting, and detection capabilities using AWS-native and third-party tooling, including CloudTrail, GuardDuty, Security Hub, CloudWatch, and SIEM platforms
  • Software Supply Chain Security: Improve software supply chain integrity through dependency controls, artifact signing, provenance, trusted build pipelines, image registries, SBOM practices, and secure release processes
  • Secrets & Key Management: Establish secure patterns for credentials, API keys, certificates, encryption keys, and secrets using services such as AWS KMS, Secrets Manager, Parameter Store, and related tooling
  • Security Incident Response: Support investigation and response for cloud and application security incidents, including containment, root-cause analysis, evidence collection, remediation, and post-incident corrective actions
  • Compliance & Control Automation: Translate security and compliance requirements into technical controls and automated evidence collection for frameworks such as SOC 2, ISO 27001, PCI DSS, or related standards
  • Security Architecture & Reviews: Perform security reviews for infrastructure changes, new services, deployment patterns, and application architectures; identify risk and recommend practical mitigations
  • Developer Enablement: Create reusable security patterns, documentation, guardrails, and tooling that make the secure implementation the easiest implementation for engineering teams
  • Continuous Improvement: Track security posture, recurring findings, control effectiveness, and operational trends to identify opportunities for better automation, prevention, and risk reduction

What We're Looking For

Required Qualifications:

  • 3+ years of experience in DevSecOps, cloud security, DevOps, platform engineering, Site Reliability Engineering, or a related discipline, including significant responsibility for production cloud environments
  • AWS: Strong hands-on experience securing AWS services and architectures, including IAM, Organizations, VPC, EC2, S3, RDS, EKS, Lambda, Route 53, CloudTrail, KMS, GuardDuty, Security Hub, and related services
  • Terraform: Advanced proficiency with Terraform, including secure reusable modules, state management, policy enforcement, code review, drift management, and infrastructure lifecycle controls
  • Kubernetes: Strong understanding of Kubernetes and EKS security, including RBAC, pod security, admission controls, secrets, network policies, workload identity, image security, and cluster hardening
  • Security Engineering: Strong knowledge of cloud security principles, least privilege, defense in depth, encryption, network segmentation, secrets management, vulnerability management, threat modeling, and secure configuration
  • Programming & Automation: Proficiency in Python, Bash, Go, or another general-purpose language used to build security automation and operational tooling
  • CI/CD Security: Experience integrating security controls into delivery pipelines using platforms such as GitHub Actions, Jenkins, GitLab CI, Argo CD, or similar tooling
  • Security Tooling: Experience with tools for SAST, SCA, container scanning, IaC scanning, secrets detection, CSPM, SIEM, or cloud-native security monitoring
  • Linux & Containers: Strong Linux, Docker, and container fundamentals with the ability to troubleshoot security and configuration issues across hosts and workloads
  • Incident Response: Experience investigating security events or production incidents and contributing to containment, root-cause analysis, remediation, and follow-up actions
  • Compliance: Working knowledge of security control frameworks and audit expectations, including evidence collection, access reviews, logging, change controls, and technical control validation
  • Communication: Strong written and verbal communication skills, with the ability to explain security risk and recommended controls to both technical and non-technical stakeholders

Preferred Qualifications:

  • AWS security-focused certifications such as AWS Certified Security - Specialty, AWS Certified Solutions Architect - Professional, or AWS Certified DevOps Engineer - Professional
  • Experience with policy-as-code tools such as Open Policy Agent (OPA), Conftest, Sentinel, Kyverno, or Gatekeeper
  • Experience with CSPM/CNAPP platforms, vulnerability scanners, SIEM platforms, or cloud security posture management tooling
  • Familiarity with supply chain security technologies and standards such as SBOMs, SLSA, artifact signing, provenance, and Sigstore/cosign
  • Experience with GitOps practices and tools such as Argo CD or Flux
  • Knowledge of security frameworks and standards such as CIS Benchmarks, NIST CSF, NIST 800-53, SOC 2, ISO 27001, or PCI DSS

Location & Work Arrangement:

  • Remote position within the United States
  • Occasional travel may be needed (10% or less)

How We Work With You

Our talent team at Get A Job.ai represents qualified candidates to our client for this confidential opening. Here's how the process works:

  • Apply through Get A Job.ai with your resume and relevant portfolio or work samples
  • Our recruiting team will review your application and conduct an initial screening call with qualified candidates
  • We will submit strong matches to our client for consideration
  • Please do not contact the client directly—all communication should go through Get A Job.ai to ensure a smooth process

Pay

Compensation details will be discussed during the screening process and are competitive with market rates for this level of experience and responsibility.

Equal Employment Opportunity: Get A Job.ai is committed to providing equal employment opportunities to all applicants regardless of race, color, religion, sex, national origin, age, disability, veteran status, or any other protected characteristic under applicable law.

Apply with Get A Job.ai

A recruiter will review your profile and submit you to the client. Do not contact the client directly.

More options

Apply with Get A Job.ai

Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.

Apply through Get A Job.ai. A recruiter will review your profile and submit you.

Working in United States

The United States of America (USA), also known as the United States (U.S.) or America, is a country primarily located in North America. It is a federal republic consisting of 50 states and a federal capital district, Washington, D.C. The 48 contiguous states border Canada to the north and Mexico to the south, with the semi-exclave of Alaska in the northwest and the archipelago of Hawaii in the Pacific Ocean. The United States also asserts sovereignty over five major island territories and various uninhabited islands in Oceania and the Caribbean. It is a megadiverse country, with the world's th

🇺🇸 Relocation safety for US: Exercise Normal Cautionvia Warnely, CC BY 4.0

National unemployment rate in US: 4.2%via World Bank

National job openings rate: 4.4%via BLS JOLTS

Private-sector wage growth (year over year): 3.1%via FRED

National quits rate: 2.0%via FRED (BLS JOLTS)

Weekly initial unemployment claims: 206,000via FRED

GDP per capita in US: $90,027via World Bank

Consumer price inflation in US: 2.9% (annual) — via World Bank

Real GDP growth in US: 2.2% (annual) — via World Bank

Average hours worked per year in US: 1,800via OECD

    Market context

    • Similar listings in United States 1

    Job details above are provided by the employer/source. The sections on this page are compiled from public data sources with AI assistance.

    Accommodations: if you need a workplace accommodation to apply for or perform this job, see ADA.gov or EEOC.gov for guidance on your rights and how to request one.

    Add application deadline to calendar

    Listing facts

    • Role DevSecOps Engineer
    • Employer Get A Job.ai
    • Location United States
    • Type Full Time
    • Pay (from listing) Pay not listed
    • Posted September 17, 2026
    • Apply by October 18, 2026
    • Country United States
    • Overview Full job description on this page (1,034 words)

    Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.

    Limited public data for this employer

    We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.

    Explore related openings

    Occupation family: DevSecOps Engineer

    Keep exploring on Get A Job.ai

    Not quite the right fit? Your next opportunity is a click away.

    Hiring instead? Post a job and reach candidates searching right now.

    DevSecOps Engineer Get A Job.ai · United States