← Все вакансии/Senior/jobgether
SeniorRemoteUS

DevSecOps Security Engineer

J
jobgether
Зарплата
$15,900–$21,600
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a DevSecOps Security Engineer based in the United States.

Responsibilities
  • Architect and automate security workflows across CI/CD and compliance operations, reducing manual effort in vulnerability analysis, security inventory audits, and continuous monitoring.
  • Integrate and monitor security tooling within automated pipelines, including scan ingestion, finding triage, evidence generation, and security reporting.
  • Build automation for compliance and ATO artifacts, including continuous monitoring reports, SPIAs, and control evidence mapped to NIST 800-53 and NIST 800-171.
  • Develop automated inventory reconciliation, delta analysis, and configuration drift detection across cloud accounts to maintain an accurate and auditable security posture.
  • Establish and implement security standards for AWS Cloud and container environments, including logging, monitoring, audit correlation, and secure configuration practices.
  • Support Infrastructure as Code security by developing and scanning Terraform and CloudFormation configurations for security and compliance requirements.
  • Use Generative AI engineering tools such as Claude, Gemini, and Copilot to accelerate security automation, compliance reporting, and IaC scanning workflows.
  • Partner with development and platform teams to resolve complex security, configuration, and performance challenges while promoting a strong DevSecOps culture.
  • Mentor junior and mid-level engineers, share modern security practices, and help drive technical consensus across the team.
  • Lead the creation and maintenance of technical documentation, processes, procedures, and engineering standards.
Requirements
  • 8+ years of relevant experience, ideally supported by a bachelor's degree in a related discipline or an equivalent combination of education and professional experience.
  • Direct, hands-on experience managing the security component of a DevSecOps pipeline within a continuous ATO (cATO) environment, including automated security gates, control evidence, and continuous authorization activities.
  • Strong experience automating compliance workflows such as vulnerability scan ingestion, finding triage, evidence generation, and continuous monitoring reporting.
  • Hands-on knowledge of AWS security services, particularly AWS GovCloud tools such as Security Hub, Inspector, GuardDuty, and Config, as well as security platforms such as Qualys, CrowdStrike, Nexus/Sonatype, SonarQube, and Datadog.
  • Strong Infrastructure as Code security experience with Terraform and/or CloudFormation.
  • Knowledge of NIST 800-53 and/or NIST 800-171, including control implementation and evidence mapping, with familiarity with FedRAMP and IAM.
  • Strong scripting and automation capabilities using Python, Bash, or similar languages, together with Linux/Unix administration experience; RHEL or CentOS knowledge is advantageous.
  • Active Security+ certification or an equivalent DoD 8570/8140 baseline certification.
  • Experience with continuous monitoring automation, proactive compliance management, security audits, and large-scale evidence collection is highly desirable.
  • Strong critical thinking and problem-solving skills, with the ability to develop practical solutions to complex security and compliance challenges.
  • Excellent communication and collaboration skills, with the ability to explain technical security concepts clearly to both engineering teams and program stakeholders.
  • Demonstrated ability or strong interest in mentoring engineers, influencing technical decisions, and serving as a technical anchor for a team.
  • A continuous-learning mindset and commitment to engineering excellence, process improvement, and modern security practices.
  • Experience with security product development, DevSecOps tooling, or security analytics platforms such as Databricks is a plus.
  • U.S. citizenship is required, and candidates must be able to satisfy the applicable background/public-trust requirements.
Conditions
  • Competitive compensation: Expected salary range of $191,250–$258,750, depending on experience, location, and contractual requirements.
  • Fully remote work: Work from any U.S. location with a full-flex work model designed to support autonomy and work-life balance.
  • Comprehensive healthcare: Medical plan options, including plans with Health Savings Accounts, plus dental and vision coverage.
  • Retirement benefits: 401(k) plan with a competitive company match and pre-tax/post-tax contribution options.
  • Paid time off: Vacation, sick and personal leave, holidays, and additional leave programs designed to support rest and personal needs.
  • Family support: Paid parental and family leave, including up to 160 hours of paid family leave in a rolling 12-month period for eligible employees.
  • Additional protection: Disability, life, accidental death and dismemberment, critical illness, personal accident, and other insurance options.
  • Professional development: Paid advanced certifications, higher education opportunities, and dedicated technical development programs.
  • Career mobility: Access to internal mobility and growth opportunities.
Стек и навыки

С чем работаем