DevSecOps Engineer / AWS Cloud Engineer (Serverless, CI/CD, IaC, ECS Fargate) | San Diego, CA

CaVU Consulting, Inc.

San Diego (CA)

On-site

USD 145,000 - 175,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision
401K match
Life insurance
11 paid holidays
Vacation & sick leave
Discounts

Job summary

CaVU Consulting, Inc. is seeking a highly skilled DevSecOps Engineer / AWS Cloud Engineer in San Diego, CA. You will design, build, and maintain secure, automated cloud environments on AWS, focusing on serverless APIs, event-driven workflows, and containerized services with strong security and governance.

You will partner with application engineers, architects, and security stakeholders to deliver reliable, scalable solutions with observability and security baked in at every stage.

Qualifications

  • Hands-on experience building serverless solutions on AWS (Lambda, API Gateway, Step Functions).
  • Proficient in provisioning with CloudFormation or IaC tooling.
  • Strong CI/CD experience with GitLab pipelines and automation.
  • Container experience with ECS Fargate and Docker.
  • Experience securing AWS environments (IAM, encryption, logging).
  • Scripting in Python or Bash to automate workflows.

Responsibilities

  • Design and implement secure, scalable cloud-native architectures on AWS.
  • Develop serverless APIs and event-driven workflows.
  • Build and maintain IaC for dev/test/prod environments.
  • Create reliable CI/CD pipelines with automated security checks.

Skills

AWS Lambda
API Gateway
Step Functions
ECS Fargate
CloudFormation
GitLab CI/CD
IAM & Encryption
Python / Bash
Terraform
AWS CDK

Tools

Terraform
AWS CDK

Job description

DevSecOps Engineer / AWS Cloud Engineer (Serverless, CI/CD, IaC, ECS Fargate) | San Diego, CA

Team CaVU

Our name is derived from the aviation acronym "Ceiling and Visibility Unlimited". Team CaVU embodies this positive vibe as we bring creative, powerful and innovative solutions to clients and partners. CaVU is the provider of choice for our clients, crafting best-value support across a wide spectrum of functional areas. We are defined by integrity, technical excellence and commitment to our clients, people and partners. We consistently make a lasting, positive impact on our community- we make things better!

Job Description

We are seeking a highly skilled AWS Cloud / DevSecOps Engineer to design, build, and maintain secure, scalable, highly automated cloud-native environments on AWS. This role will lead the engineering of production-grade serverless APIs, event-driven workflows, and containerized services, while embedding security and operational excellence into every stage of the delivery lifecycle (infrastructure, pipelines, runtime, and monitoring). You will partner closely with application engineers (frontend and backend), architects, and security stakeholders to deliver mission-critical systems with strong reliability, performance, and governance.

Key Responsibilities
Cloud architecture & delivery
  • Design and implement cloud-native architectures on AWS, emphasizing serverless-first patterns where appropriate.
  • Build and maintain production-ready serverless APIs using AWS Lambda, API Gateway, and related integration patterns (authorizers, throttling, request validation, WAF integration as needed).
  • Create event-driven workflows and orchestration using AWS Step Functions, including retries, error handling, idempotency, and observability.
  • Design and maintain containerized workloads using Docker and Amazon ECS on Fargate, including task definitions, scaling, service discovery, and secure networking.
Infrastructure as Code (IaC) & environment management
  • Develop and manage infrastructure using AWS CloudFormation (and/or complementary IaC practices as applicable), ensuring reusability, composability, and environment parity (dev/test/prod).
  • Implement guardrails for consistent provisioning: tagging standards, baseline security controls, secrets handling, and standardized logging/monitoring.
  • Manage VPC, subnets, routing, security groups, NACLs, endpoints, and connectivity patterns for secure, least-privilege architectures.
CI/CD & automation (DevSecOps)
  • Build and maintain GitLab CI/CD pipelines for automated testing, security checks, deployments, and rollbacks across multiple environments.
  • Automate release workflows for serverless and container platforms (blue/green or canary strategies where applicable).
  • Implement pipeline-integrated security controls (e.g., dependency scanning, container scanning, IaC scanning, policy-as-code where applicable) and ensure audit-ready traceability.
Security engineering (built-in, not bolted-on)
  • Architect secure AWS environments leveraging IAM (least privilege, role-based access, permission boundaries where useful), encryption (KMS), and secure secrets management.
  • Implement logging and detection best practices using services such as CloudWatch Logs/Metrics/Alarms, CloudTrail, and centralized log aggregation patterns.
  • Ensure secure configuration and operational readiness: patching/immutability strategies, secure image practices, runtime hardening, and incident response readiness.
Data & persistence
  • Design and maintain MySQL / Amazon RDS environments, including backups, parameter tuning, maintenance windows, read replicas (if needed), and secure connectivity.
  • Support application teams with data-access patterns, migrations, and reliability considerations (connection management for serverless, pooling/proxy patterns where applicable).
Required Qualifications
  • Hands‑on expertise building serverless solutions with AWS Lambda, API Gateway, and Step Functions in production.
  • Strong experience with AWS CloudFormation for provisioning and managing environments.
  • Strong CI/CD experience, specifically building and operating GitLab CI/CD pipelines.
  • Strong container expertise with Docker and running workloads on ECS Fargate (services, tasks, scaling, networking).
  • Demonstrated experience architecting secure AWS environments using IAM, VPC/networking, encryption, and logging/auditing best practices.
  • Experience designing/operating MySQL / Amazon RDS in production.
  • Strong scripting/automation skills (e.g., Python and/or Bash) to streamline workflows and reduce toil.
  • Ability to collaborate effectively with frontend/backend engineering teams and translate requirements into secure, automated platform capabilities.
  • Security+ or higher certification
  • AWS Cloud Practitioner certification or higher
  • TS security clearance or the ability to obtain one
Preferred Qualifications (Nice to Have)
  • Familiarity with AWS CDK or Terraform (even if CloudFormation remains primary).
  • Experience with API security patterns: OAuth/OIDC integration, JWT authorizers, rate limiting/throttling, WAF, mTLS (where required).
  • Experience with secrets management (e.g., AWS Secrets Manager / SSM Parameter Store) and key management (KMS).
  • Observability stack experience beyond basics: structured logging, tracing (e.g., X-Ray/OpenTelemetry patterns), metrics-driven alerting.
  • Experience implementing policy‑as‑code and governance (e.g., SCPs/Organizations, config rules, control frameworks).
  • Experience with performance/cost optimization for serverless and Fargate workloads.
  • Prior experience in regulated environments requiring audit evidence and secure SDLC controls.
Core Skills & Competencies
  • DevSecOps mindset: security and automation as first‑class design principles.
  • Systems thinking: understands tradeoffs across reliability, latency, cost, and security.
  • Engineering rigor: version control, reviews, testing, change management, and documentation.
  • Operational ownership: can carry systems from build -> run with strong on‑call hygiene.
  • Clear communication: able to explain architecture decisions to technical and non‑technical stakeholders.
Comprehensive Compensation & Benefits Package:

Salary at CaVU is determined by various factors, including but not limited to location, education, training, certificates, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The expected salary range for this position is $145,000.00 - $175,000. To drive fair pay practices for employees, CaVU conducts regular comparisons across our employee groups and the industry. The above salary range represents a general guideline; however, CaVU considers a number of factors when determining salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.

At CaVU, our offerings include:
  • 100% company-paid health, dental, and vision (to include individual, employee + significant other, or family)
  • 401K match with immediate vesting the date of hire with CaVU
  • Employer paid $100,000 life insurance policy
  • 11 paid holidays
  • 10 days of vacation with graduating accruals every two years and5 days of sick leave
  • Access to corporate discountson retail/travel/entertainment
  • Highly competitive compensation and opportunities for bonuses
EEO Commitment

CaVU is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ancestry, physical or mental disability, medical condition, marital status, genetics, age, or veteran status or any other applicable legally protected status or characteristic.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise - Senior Software Engineer - DevSecOps, Vu, FastAPI
Enterprise - Senior Software Engineer - DevSecOps, Vu, FastAPI

Erias Ventures, LLC • Virginia (MN)

On-site
USD 150,000 - 265,000
Above Market Pay
401k with vesting
Spot Bonuses
+11
Senior Security Engineer (FedRAMP)
Senior Security Engineer (FedRAMP)

Veeam • San Jose (CA)

On-site
USD 180,000 - 230,000
Unlimited PTO
Parental leave
Medical coverage
+3
Network Engineer | Patuxent River, MD
Network Engineer | Patuxent River, MD

CaVU Consulting, Inc. • Patuxent Highland (MD)

On-site
USD 130,000 - 160,000
100% company-paid health, dental, and vision
401K match with immediate vesting
Employer paid life insurance policy
+3
DevSecOps Engineer (TS/SCI)
DevSecOps Engineer (TS/SCI)

Vantor Inc. • Colorado Springs (CO)

On-site
USD 124,000 - 182,000
401(k) with company match
Mental health resources
Student loan repayment assistance
Enterprise - Agile Developer - DevSecOps, AWS, Java
Enterprise - Agile Developer - DevSecOps, AWS, Java

Erias Ventures, LLC • Maryland

On-site
USD 190,000 - 265,000
Above Market Hourly Pay
Roth 401k with Immediate Vesting
Spot Bonuses for Growth
+2
DevSecOps Engineer
DevSecOps Engineer

Vantor Inc. • Herndon (VA)

On-site
USD 145,000 - 215,000
401(k) match
Student loan repayment
Adoption reimbursement
+1
Senior DevOps Engineer - Cloud Platform Engineering
Senior DevOps Engineer - Cloud Platform Engineering

UST • Norfolk (VA)

On-site
USD 122,000 - 183,000
401(k) matching
Medical, dental and vision insurance
Paid time off
DevSecOps Engineer (TS/SCI)
DevSecOps Engineer (TS/SCI)

Vantor Inc. • Herndon (VA)

On-site
USD 137,000 - 269,000
401(k) with company match
Student loan repayment assistance
Adoption reimbursement
+1
Enterprise - Agile Developer - DevSecOps, AWS, Java 9/3/2026 Annapolis Junction, MD MD - LOU
Enterprise - Agile Developer - DevSecOps, AWS, Java 9/3/2026 Annapolis Junction, MD MD - LOU

Erias Ventures, LLC • Annapolis (MD), Northern (KY)

Hybrid
USD 190,000 - 265,000
Above Market Pay
401k with Immediate Vesting
Spot Bonuses
+1
Software Engineer
Software Engineer

Calfus Inc. • San Francisco (CA)

On-site
USD 90,000 - 110,000
Health coverage
401k retirement plan
Paid time off
+1