Remote Jobs RockRemote Jobs Rock

Senior DevSecOps Engineer

🕒 16 days ago
DevsecopsCloud SecurityKubernetesCI/CD

📜 Description

  • Integrate security into cloud infrastructure, Kubernetes platforms, CI/CD pipelines, and developer self-service workflows.
  • Design and implement secure-by-default patterns for IAM, workload identity, secrets management, and network security.
  • Assess the current security landscape, identify gaps and risks, and establish scalable security practices.
  • Build automated, risk-based security guardrails across source control, container builds, and application deployments.
  • Strengthen Kubernetes, container, and software supply-chain security, including cluster configuration and workload isolation.
  • Partner with engineering teams to identify, prioritize, and remediate vulnerabilities across cloud and CI/CD environments.

🛠️ Requirements

  • 5+ years of hands-on experience in DevSecOps, DevOps, Cloud Security, Platform Engineering, or a related role, with significant responsibility for security engineering and automation.
  • Strong hands-on experience securing AWS or Google Cloud, including IAM, workload identity, networking, encryption, logging, and cloud-native security controls.
  • Deep experience operating and securing Kubernetes and containerized workloads, including managed platforms such as Amazon EKS or Google Kubernetes Engine.
  • Strong hands-on experience with Terraform, including reusable modules, dependency management, policy enforcement, and safe change management.
  • Strong understanding of CI/CD and release engineering, including artifact security, deployment controls, approval gates, trusted builds, and rollback strategies.
  • Experience implementing automated security controls such as vulnerability and dependency scanning, container image scanning, secrets detection, policy-as-code, infrastructure scanning, cloud configuration assessment, and software supply-chain security.
  • Strong scripting or programming skills for automation, integrations, tooling, and operational problem-solving.
  • Experience working in regulated or audited environments and translating frameworks such as HIPAA, SOC 2, PCI DSS, HITRUST, or SOX into engineering controls.
  • Strong communication and technical leadership skills, with the ability to balance security, reliability, developer experience, maintainability, and delivery speed.
  • English: B2+ or higher.

Trusted by Remote Workers