Security & DevOps Engineer

Valid8 Financial, Inc.

New York (NY)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Valid8 Financial, Inc. is seeking a Security Engineer to secure and scale our AWS-based front desk services and CRM software for state and local governments.

You will own security and infrastructure end-to-end, from threat modeling and compliance to CI/CD, observability, and cloud hardening to meet public sector data standards. You will lead security initiatives across cloud infrastructure, application security, and identity, with opportunities to influence architecture and compliance posture

Qualifications

  • 4+ years of combined experience in security engineering and DevOps / infrastructure / SRE roles.
  • Hands-on production experience with AWS, Linux, containers (Docker/ECS/EKS), and infrastructure-as-code.
  • Working knowledge of at least one major compliance framework (SOC 2, HIPAA, FedRAMP, StateRAMP, ISO 27001).
  • Strong fundamentals in application security, cloud security, and identity (OAuth/OIDC, SAML, IAM).
  • Comfortable writing code to automate security and ops workflows.

Responsibilities

  • Own our cloud security posture across AWS (ECS Fargate, Aurora PostgreSQL, SQS, CloudFront, IAM, WAF, GuardDuty, Security Hub) and harden it against evolving threats.
  • Drive our compliance programs end-to-end: SOC 2 Type II, HIPAA, StateRAMP / FedRAMP authorization, including evidence collection, policy authorship, and auditor management.
  • Design and operate CI/CD pipelines, IaC (Terraform/CDK), and deployment workflows that make the secure path the easy path.
  • Build and maintain infrastructure-as-code that codifies environments, enforces guardrails, and makes changes auditable and repeatable.
  • Lead application security: threat modeling, secure code review, dependency and container scanning, secrets management, and remediation guidance.
  • Build observability and incident response capabilities, including logging, alerting, runbooks, on-call rotations, and post-incident reviews.
  • Manage identity and access at scale, including SSO/SAML, least-privilege IAM, and tenant isolation for multi-tenant architecture.
  • Respond to customer security questionnaires, support sales on security and compliance asks from government procurement teams.

Skills

Security engineering
DevOps
AWS
Linux
Containers
IaC
OAuth/OIDC
SAML
IAM
Code automation

Tools

Terraform
CDK
Docker
ECS/EKS
CloudFront
GuardDuty

Job description

We’re helping state and local governments deliver better service to their residents with modern, AI-powered tools. As service demands grow and resources remain constrained, we’ve partnered with over 200 government departments across cities, counties, and states to dramatically improve customer service, ranging from simple Q&A to fully self-serve Voice AI guiding people through complex workflows.

Role

You’ll be part of a fast growing, collaborative and rapid paced team. You’ll secure, scale, and operate the infrastructure powering our AI front desk services and CRM Software that are transforming how local governments and organizations provide service to their communities.

You will own security and infrastructure end-to-end, from threat modeling and compliance program management to CI/CD, observability, incident response, and hardening our AWS environment to meet the bar that state and local government data demands.

If You Like

Building secure-by-default systems that protect sensitive constituent data

Seeing your work have a meaningful impact on public services

Tackling a range of challenges across cloud infrastructure, application security, and compliance

Leveraging AI as part of your engineering process

Building new things from the ground up

The flexible and fast-moving nature of a startup

Job Responsibilities

Own our cloud security posture across AWS (ECS Fargate, Aurora PostgreSQL, SQS, CloudFront, IAM, WAF, GuardDuty, Security Hub) and harden it against evolving threats

Drive our compliance programs end-to-end: SOC 2 Type II, HIPAA, and our path to StateRAMP / FedRAMP authorization, including evidence collection, policy authorship, and auditor management

Design and operate CI/CD pipelines, IaC (Terraform/CDK), and deployment workflows that make the secure path the easy path

Build and maintain infrastructure-as-code that codifies our environments, enforces guardrails, and makes infrastructure changes auditable and repeatable

Lead application security: threat modeling, secure code review, dependency and container scanning, secrets management, and remediation guidance for engineering teams

Build observability and incident response capabilities, including logging, alerting, runbooks, on-call rotations, and post-incident reviews

Manage identity and access at scale, including SSO/SAML, least-privilege IAM, and tenant isolation for our multi-tenant architecture

Respond to customer security questionnaires, support sales on security and compliance asks from government procurement teams, and represent our security program externally

Partner with engineering to embed security and reliability into the product, not bolt them on after the fact

Experience and Education

4+ years of combined experience in security engineering and DevOps / infrastructure / SRE roles

Hands-on production experience with AWS, Linux, containers (Docker/ECS/EKS), and infrastructure-as-code

Working knowledge of at least one major compliance framework (SOC 2, HIPAA, FedRAMP, StateRAMP, ISO 27001), ideally having helped take an organization through audit or authorization

Strong fundamentals in application security, cloud security, and identity (OAuth/OIDC, SAML, IAM)

Comfortable writing code to automate security and ops workflows

Bonus: experience in govtech, healthcare, fintech, or other regulated industries; familiarity with FedRAMP/StateRAMP 3PAO process; CISSP, OSCP, or AWS Security certifications

Apply for this job

First name

Last name

Email address

Location

Phone number

Resume Attach resume

Attach another file Attach file

What is your Linkedin Profile URL?

Are you authorized to work in the United States? Are you authorized to work in the United States?

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security & Compliance Analyst U.S. Remote
Lead Security & Compliance Analyst U.S. Remote

Parachute Health, LLC • United States

Hybrid
USD 80,000 - 135,000
Remote-first culture
Health insurance
401(k) plan
+2
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic • San Diego (CA)

On-site
USD 140,000 - 210,000
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD
CLOUD SECURITY ENGINEER - AWS GOVCLOUD / MULTI-CLOUD

Zermount, Inc. • Arlington (VA)

Hybrid
USD 155,000 - 190,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Credence • McLean (VA)

On-site
USD 150,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

ShorePoint • Herndon (VA)

On-site
USD 120,000 - 180,000
Health insurance
401k
Education assistance
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Credence • Illinois

On-site
USD 150,000 - 180,000
Sr Software Development Engineer, SRE (US Federal)
Sr Software Development Engineer, SRE (US Federal)

Workday, Inc. • Reston (VA)

On-site
USD 140,000 - 170,000
Security Engineer
Security Engineer

Talanto • Austin (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Competitive salary
Bonus program
Flexible time off
+9
Staff Site Reliability Engineer, Government
Staff Site Reliability Engineer, Government

sentinellabs • United States

On-site
USD 150,000 - 210,000