Senior DevSecOps Engineer - NYC ( onsite/ remote all of August)
We’re looking for a Senior DevSecOps Engineer to join a high-performing engineering organisation within a leading financial services environment.
This is a hands‑on, high‑ownership IC role for someone who enjoys building security into engineering platforms rather than simply identifying security findings.
You’ll take ownership of security engineering across CI/CD, AWS, Kubernetes, identity and authentication, software supply chain security, and an emerging AI platform.
As the Senior DevSecOps you will be responsible for:
- Define and own security engineering strategy for internal developer platforms and shared infrastructure
- Build automated vulnerability management and remediation tooling that engineering teams actually adopt
- Own secrets, identity, authentication and workload identity tooling
- Secure CI/CD across GitHub Actions, ArgoCD and related platforms
- Implement software supply-chain security including SBOM, SLSA, cosign/sigstore, dependency and container scanning
- Design AWS security governance covering SCPs, IAM, KMS, secrets and workload identity
- Build secure-by-default Terraform modules and reusable platform patterns
- Strengthen EKS/Kubernetes security, including admission control, network policies, image/runtime security and tenant isolation
- Help shape security architecture for AI/ML platforms, including model access, agent security, data boundaries and AI supply chains
- Use AI-assisted engineering tools to dramatically increase engineering productivity
- Partner with InfoSec, AppSec and engineering teams to turn security requirements into practical engineering solutions
As the DevSecOps you will have the following experience:
- Solid hands‑on engineering experience, including security-focused roles
- Proven experience building security tooling/platforms adopted by engineering teams
- Strong AWS security expertise — IAM, SCPs, KMS, workload identity and secrets management
- Deep CI/CD and software supply-chain security experience
- Strong Kubernetes/EKS security experience
- Hands‑on programming experience with Python, Go, Bash or similar
- Strong Linux and distributed-systems experience
- Experience with Terraform and infrastructure automation
- A strong threat‑modelling and adversarial mindset
- Experience with AI-assisted development tools such as Claude Code, GitHub Copilot or autonomous agents
We are offering a competitive package+ benefits .
The roles are onsite ( remote all of August)