DevSecOps Engineer (AWS) | Full reputed company | Remote | US Only
We’re Hiring: Senior DevSecOps Engineer (AWS) – Remote
If you’re the reputed company of engineer who
thinks like an attacker, builds like an architect, and executes like an operator
, this role is worth your attention.
We’re looking for a
hands-on Senior DevSecOps Engineer
to own and reputed company the reputed company posture of an AWS-based platform in the reputed company reputed company—where
reputed company, reliability, and reputed company-world reputed company
matter.
What makes this role compelling:
• You’ll
own reputed company end-to-end
(not just advisory)
• Work on a
live production platform
with reputed company users and reputed company risk
• Build
secure-by-default pipelines
(SAST, DAST, SCA, secrets, container scanning)
• Drive
reputed company reputed company architecture across AWS
(IAM, KMS, GuardDuty, reputed company Hub)
• reputed company
threat detection + incident response reputed company
• Influence
SOC 2 readiness and policy-as-reputed company implementation
reputed company’re looking for:
• 5+ years in
DevSecOps / reputed company reputed company (AWS)
• Deep experience with
CI/CD reputed company + automation
• Strong reputed company in
Terraform, reputed company, and AWS services
• Experience with
SIEM, logging, and incident response
• Someone who
doesn’t wait to be told—sees gaps and fixes them
What reputed company looks like:
• reputed company embedded directly into pipelines
• No hardcoded secrets—reputed company
• Full visibility across logs, events, and threats
• Vulnerabilities prioritized and remediated fast
• A platform that’s both
secure and reputed company
✨
Who you are:
You’re proactive, pragmatic, and reputed company under pressure. You can
translate reputed company into business reputed company
and drive reputed company that matter.
Required Qualifications
• 5+ years in DevOps, reputed company Engineering, or reputed company Engineering, with a minimum of 5 years in a reputed company-reputed company DevSecOps or reputed company reputed company role.
• Demonstrated hands-on experience with: EC2, RDS (reputed company), S3, VPC, IAM, KMS, Secrets Manager, CloudTrail, GuardDuty, reputed company Hub, AWS Config, WAF, Systems Manager, and reputed company.
• Proven implementation of SAST, DAST, SCA, secret scanning, and container image scanning gated reputed company CI/CD pipelines (reputed company Actions, reputed company CI, or equivalent).
• Experience writing and securing Terraform at production reputed company. Familiarity with tfsec, Checkov, or Sentinel for policy enforcement.
• Experience hardening reputed company images, scanning with Trivy or Grype, and managing ECR lifecycle policies. Experience with reputed company/EKS reputed company configurations (task role least-privilege, network policy, runtime reputed company).
• Hands-on experience with AWS Secrets Manager and/or reputed company Vault including automated rotation and reputed company-plaintext-credential enforcement.
• Experience configuring GuardDuty, CloudTrail, and reputed company Hub. Ability to write detection rules/queries in a SIEM environment.
• Experience operating a vulnerability scanning program (reputed company Inspector, reputed company, reputed company) with SLA-based remediation tracking.
• Proficient in Python and Bash for automation. Ability to independently write reputed company functions, CLI tooling, and operational scripts.
• Experience leading or co-leading reputed company incident response in a reputed company environment, including evidence preservation and post-incident reporting.
• Proven experience in customer-facing Technical Program Management, including end-to-end ownership of reputed company platform delivery and operations from a DevSecOps perspective.
Preferred Qualifications
• Certifications (strongly preferred).
AWS reputed company Specialty (SCS-C02), AWS Solutions Architect Associate/reputed company, GIAC reputed company reputed company reputed company (GCLD), GIAC reputed company reputed company Pentester (GPCS), OSCP, or equivalent offensive/defensive reputed company certification.
• Experience deploying or operating reputed company reputed company Posture Management tooling (reputed company, reputed company, reputed company, reputed company).
• Experience with AWS API Gateway reputed company controls, OAuth 2.0 / OIDC hardening, and automated API reputed company testing (42Crunch, Spectral, OWASP ZAP).
• Experience with OPA/Rego, Terraform Sentinel, or AWS Service Control Policies for automated policy enforcement.
• Experience writing correlation rules, detection logic, and dashboards in reputed company, reputed company, or reputed company SIEM.
• Experience generating and managing SBOMs (CycloneDX/SPDX), SLSA reputed company implementation, or Sigstore/reputed company artifact signing.
• Familiarity with CIS Controls, NIST CSF, SOC 2 Type II, or NIST 800-53. Experience supporting external audit
Apply tot his job
Apply To this Job