About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We are seeking a Senior DevSecOps Engineer with deep expertise in Microsoft Azure to embed security into every stage of our clients' software development lifecycle. This is a client-facing consulting role. You will be embedded with a dedicated Echelon client for an extended engagement, serving as the key liaison between Echelon's Security Team and the client's application development team. You will design and maintain secure, automated CI/CD pipelines, harden cloud infrastructure, and connect development, operations, and security. This is a hands-on engineering role for someone who thinks like an attacker, builds like a developer, and operates like an SRE. As the engagement matures, there will be opportunities to contribute to additional application security engagements across Echelon's client portfolio.
Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment
This is a remote position from anywhere in Mexico.
What You Will Do:
Client Partnership & Liaison:
- Serve as the primary technical liaison between Echelon's Security Team and the client's application development team, embedded with a dedicated client on an extended engagement.
- Build trusted working relationships with client developers, DevOps engineers, architects, and engineering leadership; become the person they bring problems to before decisions get made.
- Translate Echelon security requirements into practical engineering guidance the client's teams can implement within their existing sprint cadence and release schedule.
- Represent Echelon in client ceremonies including sprint planning, architecture reviews, change advisory boards, and security design reviews.
- Escalate risks, blockers, and scope changes to Echelon leadership early, and keep client stakeholders informed through consistent status communication.
- Document decisions, standards, and remediation guidance so the work is transferable and the client retains value beyond the engagement.
- Contribute to additional application security engagements across Echelon's client portfolio as opportunities arise.
Secure SDLC & Application Security:
- Design, build, and maintain secure CI/CD pipelines in Azure DevOps and GitHub Actions, integrating SAST, DAST, SCA, and container scanning at every stage.
- Partner with client development teams to shift security left, embedding threat modeling, secure coding practices, and secrets management into daily workflows.
- Triage and prioritize scanner findings alongside developers, separating real risk from noise so remediation effort goes where it matters.
- Support secure code review, application threat modeling, and secure design guidance for new and existing client applications.
- Define and track application security metrics that demonstrate measurable improvement in the client's posture over the life of the engagement.
Cloud Security Engineering:
- Architect and manage secure infrastructure-as-code (IaC) using Terraform, Bicep, or ARM templates, applying security-by-design principles.
- Implement and manage Azure security services: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Key Vault, Azure Policy, Entra ID Conditional Access, and Network Security Groups.
- Build and maintain container security practices for Azure Kubernetes Service (AKS), including image scanning, admission controls, and runtime protection.
- Develop and enforce IAM best practices, least-privilege access models, and secrets rotation policies using Key Vault and Managed Identities.
- Extend the same security practices into AWS where client workloads are multi-cloud or mid-migration.
Automation, Monitoring & Response:
- Automate vulnerability management, patching workflows, and compliance checks across cloud and hybrid environments.
- Create and maintain security monitoring, logging, and alerting using Azure Monitor, Log Analytics, and SIEM integrations.
- Lead incident response efforts related to pipeline, cloud, or infrastructure security events.
- Mentor client and Echelon engineers, champion DevSecOps culture, and stay current on emerging threats, Azure security features, and compliance frameworks (SOC 2, ISO 27001, NIST, CIS Benchmarks).
Your knowledge, skills, and abilities:
Consulting & Client-Facing Experience:
- Experience delivering in a consulting, professional services, or managed services environment is required. This role sits inside a client's engineering organization, and success depends as much on client trust, communication, and judgment as on technical depth.
- Demonstrated ability to work as an embedded resource on a long-running client engagement, operating within the client's tools, processes, and release cadence rather than imposing your own.
- Comfort influencing without authority, driving security outcomes through developers and engineering leaders