Senior DevSecOps Engineer

Campminder

Boulder (CO)

On-site

USD 165,000 - 196,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work option
Hybrid office in Boulder
Annual bonus program
$500 employer HSA contribution

Job summary

Campminder is seeking a Senior DevSecOps Engineer to own end-to-end data protection, shaping security architecture and PCI/SOC2 compliance. You’ll lead security across CI/CD, cloud-native environments, and container hardening from our Boulder office or work 100% remotely within the United States.

You will partner with DevOps, IT, and engineering to embed security in pipelines, manage secrets, run audits, and drive remediation within SLA timelines.

Qualifications

  • Experienced in security engineering or DevSecOps with ownership of both pipeline- and infrastructure-level security.
  • Experience configuring IAM and SSO platforms (Okta, Auth0) with cloud-native identity controls.
  • Ability to embed security into CI/CD workflows with scanning, secrets management, and policy-as-code.
  • Track record of hardening containerized and cloud-native environments (Kubernetes, image scanning).
  • Experience with PCI, SOC2 or similar compliance controls (scans, SAQs, evidence).
  • Familiarity with centralized cybersecurity solutions, endpoint security, and DLP.

Responsibilities

  • Partner with DevOps to integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and drive remediation before production.
  • Configure, tune, and harden WAF rules across web applications.
  • Collaborate with platform and IT to implement EDR, DLP, vulnerability scanning and SIEM/XDR tooling.
  • Manage secrets and credentials in build pipelines with vault-based storage and least-privilege accounts.
  • Execute PCI, SOC2, and ISO technical controls: SAQ completion, ASV scans, disaster recovery.
  • Harden cloud-native environments and containers, including image scanning and Kubernetes config.
  • Coordinate pen testing engagements and remediation within SLA timelines.
  • Run security awareness training and AI governance initiatives.

Skills

Security engineering
DevSecOps
IAM & SSO
CI/CD security
Kubernetes hardening
PCI/SOC2 controls
EDR/DLP/SIEM
Security training
AI governance
Communication

Tools

SAST
DAST
SCA
Vault/Secrets mgmt
Kubernetes image scanning

Job description

Ideal start timeline: August 2026

Role status: Exempt

Compensation: Our target hiring range is $165,000-$196,000 plus participation in our Annual Bonus Program with eligibility for $12,000 bonus. Actual compensation will be commensurate with experience and skills.

Campminder’s Flexible Working Location: Our employees have the option to work 100% remotely within the United States or their choice of days at home and at our office in Boulder, Colorado. We host a variety of all-company hybrid meetings and social events. We require anybody working remotely to have a very reliable, high-speed internet connection.

We know the best people can choose to work anywhere.

This role’s mission & overview:

Camps trust Campminder to keep their data safe, and that trust is what lets them focus on running a great summer. You'll own how we protect that data end to end: architecting and hardening our security infrastructure, carrying our PCI and SOC2 programs through every audit, and setting the roadmap that keeps us ahead of real threats. You'll be the person the engineering org comes to on security and the one who defines what good looks like at Campminder.

As a Senior DevSecOps Engineer on our Engineering team, you will:
  • Partner with the DevOps team to Integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and drive remediation before code reaches production
  • Configure, tune, and harden WAF rules across our web applications
  • Partner with platform and IT to implement and maintain EDR, DLP, vulnerability scanning and remediation, and SIEM/XDR tooling across servers and endpoints
  • Manage secrets and credentials in build pipelines, including vault-based storage, rotation, and least-privilege service accounts
  • Execute PCI, SOC2, and ISO technical controls: SAQ completion, quarterly ASV scans, and disaster recovery implementation
  • Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration
  • Coordinate pen testing engagements and drive remediation against SLA timelines
  • Run security awareness training programs (KnowBe4, Security Journey) and maintain AI usage oversight, including approved tooling, code-gen governance, and supply‑chain monitoring
We think a successful candidate will bring:
  • Experienced in security engineering or DevSecOps, with hands‑on ownership of both pipeline‑level and infrastructure‑level security
  • Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud‑native identity controls like Azure conditional access
  • Comfort embedding security directly into CI/CD workflows through security and dependency scanning tooling, secrets management, and policy‑as‑code
  • A track record of hardening containerized and cloud‑native environments, including Kubernetes and image scanning
  • Experience executing PCI, SOC2 or similar compliance technical controls (scans, SAQs, evidence prep); program ownership isn't required, but you know how to translate auditor requirements into engineering work
  • Familiarity administering centralized cybersecurity solutions, endpoint security, and data loss protection
  • Strong judgement on how to balance security risk with employee experience and velocity, how to build trust through balanced approaches to security risk mitigation, and knowledge of when to elevate versus fix directly
  • Experience running or supporting security awareness and training programsExposure to AI tooling governance, such as MCP inventories, code‑gen release gating, or supply‑chain monitoring for AI‑assisted development
  • Strong communication skills, with the ability to communicate technical concepts to technical and non‑technical people
  • A track record of working collaboratively with engineers and supporting them in learning and implementing security best practices
  • A track record of empowering delivery teams to move quickly and unblock themselves
  • A growth‑oriented mindset
Our Interview Process:
  1. 45 min - interview with People & Culture
  2. 60 min - interview with Hiring Manager
  3. Phase 3
    1. 60 min - Technical interview
    2. 30 min - Peer interview
    3. 30 min - Interview with our CTO
A few of the benefits we are proud to offer:
  • Robust medical, dental, and vision coverage options with generous employer contributions, plus a $500 employer HSA contribution for HSA‑compatible plans
  • Ability to choose where you work - remotely, in the office, or a mix!
  • A variety of resources to support mental health and emotional well‑being
  • 12 weeks of 100% paid parental leave for all new parents, including via adoption, surrogacy, and foster care
  • 401(k) with 4% company matching
  • Trust‑Based (flexible) PTO (and yes, we use it!)
  • $900/year wellness allowance
  • Company‑paid subscriptions, training, and support for using AI professionally and personally. We have a team dedicated to enabling our AI capabilities for our team members and our customers!
We encourage people of all backgrounds to apply:

We're actively taking steps to make sure our culture is inclusive and that our processes and practices promote equity for all, including people of color, people from working‑class backgrounds, women, and members of the LGBTQ+ community. We welcome and encourage applications from people with these identities or members of other historically marginalized groups.

Research shows that women and people of color tend not to apply to jobs unless they believe they are 100% qualified and apply to fewer senior‑level positions. With that in mind, we encourage you to apply if you're not sure whether you meet our qualifications. We'd love to have the opportunity to consider you!

We encourage applications from parents, parents‑to‑be, and those responsible for the caretaking of others. We offer paid parental leave for birthing and non‑birthing parents (including for adoption, surrogacy, and foster care placement) and paid loss leave to recover from miscarriage or stillbirth. The company's HSA and wellness allowance contributions may be used toward childcare, eldercare, adoption fees, and fertility treatments like IVF, among other expenses.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

Campminder • Boulder (CO)

Hybrid
USD 175,000 - 215,000
Robust medical, dental, and vision coverage
Flexible PTO
12 weeks paid parental leave
+2
Senior Product Marketing Manager
Senior Product Marketing Manager

Campminder • Boulder (CO)

Hybrid
USD 150,000 - 166,000
Comprehensive medical, dental, and vision coverage
12 weeks paid parental leave
401(k) with 4% matching
+2
Client Support Representative
Client Support Representative

Doist • Boulder (CO)

Hybrid
USD 43,000 - 52,000
Manager, Security Engineering, Cloud & AppSec
Manager, Security Engineering, Cloud & AppSec

Horizon3 AI • United States

On-site
USD 149,000 - 185,000
Health, vision & dental insurance
Flexible vacation policy
Generous parental leave
+2
Senior Security Engineer
Senior Security Engineer

Silversmith Capital Partners • United States

Hybrid
USD 126,000 - 154,000
HDHP + telehealth
Calm subscription
LinkedIn Learning
+3
Staff AI Security Engineer
Staff AI Security Engineer

Spring Health • San Francisco (CA)

On-site
USD 239,000 - 270,000
Health, Dental, Vision insurance
401(k) match
Paid time off
+5
Staff AI Security Engineer
Staff AI Security Engineer

Spring Health • Seattle (WA)

Hybrid
USD 208,000 - 252,000
Health, Dental, Vision benefits
401(k) match
Paid time off
+2
Manager, Security Engineering
Manager, Security Engineering

Cohere • United States

On-site
USD 120,000 - 160,000
Inclusive culture
Weekly lunch stipend
Full health and dental benefits
+2
Senior DevOps Engineer I
Senior DevOps Engineer I

Springhealth66 • Seattle (WA)

Hybrid
USD 159,000 - 191,000
Health, Dental, Vision benefits
Employer sponsored 401(k) match
Yearly allotment of no-cost therapy visits
+3
Senior Security Operations Engineer
Senior Security Operations Engineer

Cohere • San Francisco (CA)

Hybrid
USD 130,000 - 170,000
Open and inclusive culture
Cutting-edge AI research
Weekly lunch stipend
+5