Senior DevSecOps Engineer

Bankrate

Deutschland

Hybrid

EUR 112.000 - 194.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Health Insurance Coverage (medical, }
Life Insurance
Disability Insurance
Flexible Spending Accounts
Holiday Pay
401(k) with match
Employee Assistance Program
Parental Leave Benefit
Flexible PTO

Zusammenfassung

Bankrate is seeking a senior DevSecOps Engineer to own security as code and embed compliance across development lifecycles. You will oversee SOC 2 Type 2 readiness, automation pipelines, and guardrails that accelerate secure product delivery.

You’ll manage cloud posture, runtime security, and AI-assisted remediation while partnering with security and GRC teams to mature in-house security capabilities. Remote/hybrid options available. East Coast preference.

Qualifikationen

  • 5+ years in security engineering, DevSecOps, or platform/infrastructure with security focus.
  • Hands-on cloud security experience on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: integrate SAST/SCA, secret scanning, and container scanning into pipelines.
  • Experience with SOC 2 or equivalent frameworks and evidence collection.

Aufgaben

  • Own the engineering side of our compliance program (SOC 2 Type 2) and audit readiness.
  • Operate and improve the compliance automation platform, pipelines, and evidence mapping.
  • Productize compliance via policy-as-code and automated evidence generation.
  • Own cloud security posture management and runtime security tooling across the environment.
  • Triage findings against SLAs and design automated remediation and alerting.
  • Build auto-remediation workflows, including AI-assisted pipelines, with minimal human intervention.
  • Maintain CI/CD security gates: SAST/SCA, secrets, SBOM, dependencies, and container/IaC scanning.

Kenntnisse

DevSecOps
Cloud security
Terraform / IaC
CI/CD security
Vulnerability management
SOC 2
Automation / AI
Scripting

Tools

Wiz
Prisma Cloud
Snyk
Drata
Vanta

Jobbeschreibung

*This role is open to remote or hybrid candidates (East Coast preference), with hybrid being central to our New York, NY or Charlotte area offices. Must be able to work Eastern Standard Time hours.

Platform Engineering builds the foundations our product teams ship on - deployment, infrastructure, and security. We're hiring a DevSecOps Engineer to be the technical owner of our security posture and a force multiplier for every engineer at the company. This is a build-the-function role, not a ticket-taking role. You'll treat security as code, bake it into the development lifecycle, and automate the toil away so teams can ship fastand safely. You'll have unusually broad ownership and unusually high impact.

What You’ll Do:
  • Own the engineering side of our compliance program (SOC 2 Type 2): implementing controls, collecting evidence, and keeping us audit-ready.
  • Operate our compliance automation platform - integrations, evidence pipelines, and mapping controls to real implementation.
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails so passing audits doesn't slow product delivery.
  • Own cloud security posture management and runtime security tooling: posture monitoring, container and IaC scanning, and runtime coverage across our environment.
  • Triage and remediate findings against demanding SLAs, and design the automation and alerting that keeps pace with volume manual effort can't.
  • Build auto-remediation workflows - including AI-assisted pipelines - that detect, file, and (where safe) fix findings with minimal human intervention.
  • Build and maintain CI/CD security gates: SAST/SCA, secret scanning, SBOM generation, dependency management, and container/IaC scanning - implemented as reusable pipeline components and enforced through automated policy.
  • Encode security and compliance controls into infrastructure-as-code and policy-as-code so the easy path is the secure path.
  • Help close the prototype-to-production gap: turn fast-moving prototypes into production-grade, secure-by-default systems with automated guardrails.
  • Make secure-by-default the norm through our internal tooling, so the right controls are applied automatically rather than relying on engineers to remember.
  • Build the automation the team runs on - reusable modules, pipeline components, and AI/agentic tooling that turn manual security work into self-service capability.
  • Partner with corporate security and GRC functions while building and maturing our in-house security capability, so the team can make sound security decisions quickly and independently
What We’re Looking For:
  • 5+ years in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus (Staff level: 8+ years and a track record of building security functions or programs).
  • Deep hands-on cloud security experience (compute, networking, IAM, key management, logging) on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: building pipeline security controls (SAST/SCA, secret scanning, dependency and container scanning) into developer workflows.
  • Hands-on vulnerability management at scale: triage, prioritization, SLA-driven remediation, and the automation to make it sustainable.
  • Working knowledge of SOC 2 (or comparable frameworks) and what it takes to implement and evidence controls in a real engineering environment.
  • Fluency with the categories of modern cloud security tooling - CSPM, ASPM/SAST and secret scanning, compliance automation, and SIEM (e.g., tools such as Wiz, Prisma Cloud, Snyk, Drata, Vanta, or equivalents).
  • Strong coding/scripting ability to build automation, not just configure tools - you write the pipelines, modules, and tooling that scale security across many services.
  • Experience standing up or maturing an in-house security function.
  • Multi-cloud exposure and experience securing an internal developer platform.
  • Security monitoring and detection/alerting design.
  • Experience applying AI/LLM tooling to security operations - auto-remediation, evidence generation, agentic workflows.
Compensation:

This range reflects total cash compensation, which may include base salary only or base salary plus target bonus, depending on the role. Where eligible, equity may also be offered separately and not included below. Actual compensation varies based on location, experience, and qualifications.

  • Total Cash Compensation Range: $130,000 - $225,000 per year

Additionally, the following benefits are provided by Red Ventures, subject to eligibility requirements.

  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program
  • Flexible Paid Time Off (PTO): We believe time to rest and recharge is essential. That's why we offer a generous and flexible PTO policy. Full-time employees accrue 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.
Who We Are:

Bankrate is where Americans go to get the best price on life's most important financial decisions. By combining proprietary data, advanced technology, and deep market coverage, Bankrate helps consumers compare options and make confident financial choices across mortgages, credit cards, savings, and more. As a rate provider to the Federal Reserve and the benchmark relied upon by major publishers and policymakers nationwide, Bankrate's rate data is the national standard. This commitment to precision is reflected across all its products. In mortgages, proprietary auction technology puts lenders in real-time competition on price alone, consistently delivering rates in the lowest 10% in the country. For deposits, the platform features exclusively top-tier rates in the top 10% nationally, while its credit card coverage encompasses more than 90% of the market by volume. Founded by a journalist, Bankrate remains dedicated to its founding mission of transparency, honest information, and real competition - helping to make the American dream more affordable for everyone.

Red Ventures is an equal opportunity employer that does not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or any other basis protected by law. Employment at Red Ventures is based solely on a person's merit and qualifications.

We are committed to providing equal employment opportunities to qualified individuals with disabilities. This includes providing reasonable accommodation where appropriate. Should you require a reasonable accommodation to apply or participate in the job application or interview process, please contact accommodation@redventures.com.

If you are based in California, we encourage you to read this important information for California residents linked here.

At Red Ventures, we believe in real human connection. That's why we do not hire someone through text, social media, or email only. As part of the hiring process, you should expect live conversations with RV teammates before any offer is made. Also, keep an eye on the sender: we only use official @redventures.com email addresses at the portfolio level or business specific email addresses (e.g., @thepointsguy.com), not ones like redventurescareer.com. We will never ask candidates to send money, buy equipment, or share financial account info during your journey with us. You can always find our open roles on redventures.com - if you receive a message that seems suspicious, please use redventures.com to verify the opportunity.

For more, the U.S. Federal Trade Commission has published helpful articles to help individuals learn more about protecting themselves from recruiter scams. If you think you've been targeted, feel free to report it to your local authorities. Stay safe out there!

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Head of Brand & Communications
Head of Brand & Communications

Bankrate • Deutschland

Hybrid
EUR 198.000 - 302.000
Health Insurance
Life Insurance
Disability Insurance
+4
Forward Deployed Engineer | Bankrate
Forward Deployed Engineer | Bankrate

Embedded Shishya • Deutschland

Hybrid
EUR 86.000 - 168.000
Health Insurance Coverage (medical, …)
Life Insurance
Short and Long-Term Disability
+6
Forward Deployed Engineer, Federal/National Security
Forward Deployed Engineer, Federal/National Security

Red Cell Partners • Deutschland

Hybrid
EUR 157.000 - 211.000
Health insurance
Paid parental leave
Unlimited PTO
+4
Vice President, Information Security
Vice President, Information Security

Springhealth66 • Deutschland

Remote
EUR 215.000 - 250.000
Health, Dental, Vision benefits
AI Security Research & Red Team Engineer
AI Security Research & Red Team Engineer

Socket.dev • Deutschland

Hybrid
EUR 144.000 - 180.000
Equity plan
Sr./Staff Security Engineer
Sr./Staff Security Engineer

Oscilar • Deutschland

Remote
EUR 80.000 - 110.000
100% Medical/Dental for you and dependents
Stock options
Caju Card for monthly meal allowance
+2
Senior Software Engineer, Presence
Senior Software Engineer, Presence

Reddit • Deutschland

Remote
EUR 167.000 - 235.000
Comprehensive Healthcare Benefits
401k with Employer Match
Mental Health & Coaching Benefits
+1
Devsecops Team Lead
Devsecops Team Lead

Deel • Deutschland

Hybrid
EUR 90.000 - 140.000
Stock grant opportunities
Flexible working office membership
Additional perks and benefits based on
Federal Platform Engineer
Federal Platform Engineer

Horizon3 • Deutschland

Hybrid
EUR 104.000 - 164.000
Competitive compensation
Hybrid & remote work
Growth opportunities
+1
Staff Engineer (Remote)
Staff Engineer (Remote)

KnowBe4 • Deutschland

Remote
EUR 148.000 - 167.000
Company-wide bonuses
Tuition reimbursement
Certification reimbursement
+1