Overview
The DevSecOps Engineer is responsible for embedding automated security guardrails, vulnerability scanning, and compliance controls directly into our cloud platform and CI/CD pipelines. By managing security tooling platforms (SAST/DAST/SCA), automating vulnerability triage, and building secure multi-cloud integration patterns (including AWS to Google Gemini Enterprise Plus), this role ensures our core cloud infrastructure remains scalable, secure, and friction-free. This position operates as a mid-to-senior technical resource, accelerating software delivery while reducing administrative security overhead across teams.
Responsibilities
- Implement, configure, and maintain automated security scanning platforms (SAST, DAST, SCA, container scanning) across our development pipelines.
- Triage security scan findings and automate remediation workflows to streamline vulnerability management across teams.
- Partner with Architecture and Engineering to establish secure multi-cloud guardrails, including AWS-to-GCP identity federation, KMS key management, and API gateway access controls for AI platform integrations.
- Enforce Infrastructure as Code (IaC) security automation (such as Terraform, Checkov, and Trivy) to embed policy-as-code across environments.
- Serve as a Subject Matter Expert (SME) for cloud security tooling, CI/CD automation, and multi-cloud access patterns, providing technical guidance across the organization.
- Proactively tune security tools to reduce false positives and eliminate operational noise for software delivery teams.
- Serve as a secondary point of escalation for security and platform incidents, rather than participating in the primary on-call rotation.
- Coordinate technical resolution during security events and contribute to post-mortem analysis to prevent recurrence.
Essential Skills and Experience
- 3 to 5+ years of experience in DevSecOps, cloud security, or platform security engineering.
- Multi-cloud experience across public cloud platforms, with deep expertise in AWS and working experience in GCP (Google Cloud Platform).
- Deep experience with AWS core security infrastructure (IAM, KMS, Secrets Manager, VPC, EKS/ECS).
- Strong proficiency in Terraform or AWS CDK to enforce infrastructure guardrails as code across cloud environments.
- Hands-on experience integrating security testing tools (SAST/DAST/SCA/Container scanning) into CI/CD pipelines (GitHub Actions, AWS CodeBuild, or Jenkins).
- Experience establishing identity flows, OAuth configurations, and Workload/Workforce Identity Federation across multi-cloud environments (AWS and GCP).
- Hands-on experience with container security, image scanning repositories (ECR, Trivy), and containerized application runtime security.
- Proficiency in CloudWatch, SIEM log monitoring, and security findings triage.