Senior DevSecOps Engineer

Flexhire

United States

On-site

USD 120,000 - 180,000

Full time

15 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TinyFish seeks a hands-on Senior DevSecOps Engineer to drive security across infrastructure and product engineering. You will own vulnerability management, automate security controls, and collaborate with engineering to remediate findings and close gaps.

This role focuses on translating policies, compliance requirements, and risk findings into actionable engineering work. You will partner with Infrastructure, Engineering, Product, and leadership to execute the security program.

Qualifications

  • 5+ years of hands-on DevSecOps, cloud security, or security engineering experience.
  • Experience building or operating a vulnerability-management program and remediation.
  • Strong knowledge of AWS security, IAM, VPC, KMS, logging, and multi-account setups.
  • Experience with infrastructure as code (Terraform preferred).
  • Experience securing CI/CD pipelines and artifacts (GitHub Actions).
  • Knowledge of SAST, DAST, software composition analysis, and container scanning.

Responsibilities

  • Own the vulnerability-management lifecycle across cloud infra, apps, containers, CI/CD, and production services.
  • Establish repeatable vulnerability-discovery, triage, remediation SLAs, and reporting processes.
  • Drive closure of high-severity findings with owners and escalation when needed.
  • Implement and maintain security controls across AWS (IAM, networking, encryption, key management, secrets).
  • Integrate security into the SDLC with guardrails for SAST/DAST, dependency checks, and IaC scans.
  • Review designs, perform threat modeling, and translate risks into engineering actions.
  • Improve security across APIs, authentication, service-to-service communication, and data protection.
  • Coordinate third-party pen tests and ensure findings are remediated and validated.
  • Develop incident-response playbooks and participate in security incidents and tabletop exercises.
  • Collaborate with Infra and Observability to improve security logging and detection workflows.
  • Convert policies to automated checks and engineering requirements; support audits (SOC 2, ISO 27001).
  • Create practical security guidance to help engineers ship secure systems with minimal friction.

Skills

DevSecOps
Cloud security
Application security
Security engineering
Vulnerability management
Scripting (Python/Bash)
Threat modeling
Communication skills

Tools

Terraform
GitHub Actions
SAST
DAST
IAM/KMS security

Job description

TinyFish is looking for a hands-on Senior DevSecOps Engineer to drive the execution of our security program across infrastructure and product engineering.

You will own the day-to-day vulnerability management process, implement and automate security controls, and work with engineering teams to drive findings through remediation and verified closure. You will help translate security policies, compliance requirements, penetration-test findings, and identified risks into concrete engineering work.

This is an individual-contributor role for someone who combines strong cloud and application-security fundamentals with a bias for execution. You will partner closely with Infrastructure, Engineering, Product, and company leadership. You will not be expected to single-handedly own every aspect of company security strategy, compliance, and risk acceptance.

Key Responsibilities
  • Own the vulnerability-management lifecycle across cloud infrastructure, application code, dependencies, containers, CI/CD systems, and production services.
  • Establish repeatable processes for vulnerability discovery, triage, severity assessment, ownership, remediation SLAs, exceptions, verification, and reporting.
  • Drive critical and high-severity findings through closure by partnering with service owners and escalating unresolved risks when necessary.
  • Implement and maintain security controls across AWS, including IAM, networking, encryption, key management, secrets, logging, and workload isolation.
  • Integrate security into the software-development lifecycle through practical guardrails such as SAST, DAST, dependency scanning, secret detection, container scanning, and infrastructure-as-code checks.
  • Review security-sensitive designs and changes, perform threat modeling, and provide concrete recommendations to engineering teams.
  • Improve security across public APIs, authentication and authorization, service-to-service communication, customer credentials, sensitive data, and software-supply-chain workflows.
  • Coordinate third-party penetration tests and ensure findings are assigned, prioritized, remediated, and validated.
  • Develop and maintain incident-response playbooks, participate in security incidents, facilitate tabletop exercises, and track corrective actions after incidents.
  • Partner with Infrastructure and Observability teams to improve security logging, alerting, investigation workflows, and threat detection.
  • Translate security policies and compliance controls into technical requirements, automated checks, and engineering work.
  • Support SOC 2, ISO 27001, and other applicable assurance or regulatory initiatives through control implementation, evidence collection, and remediation of audit findings.
  • Maintain clear reporting on security posture, vulnerability backlog, remediation performance, control coverage, and overdue risks.
  • Create practical security guidance and documentation that helps engineers ship secure systems without unnecessary friction.
Ideal Experience
  • 5+ years of hands-on experience in DevSecOps, cloud security, application security, security engineering, or a related role.
  • Demonstrated experience building or operating a vulnerability-management program and driving findings through verified remediation.
  • Strong knowledge of AWS security, including IAM, VPC networking, KMS, secrets management, logging, monitoring, and multi-account environments.
  • Production experience with infrastructure as code, preferably Terraform.
  • Experience securing CI/CD pipelines, preferably GitHub Actions, including identity, permissions, secrets, dependencies, and build artifacts.
  • Practical experience with security tooling such as SAST, DAST, software-composition analysis, secret detection, container scanning, cloud-security posture management, and infrastructure-as-code scanning.
  • Solid understanding of common application-security risks, secure coding practices, authentication and authorization patterns, and the OWASP Top 10.
  • Experience reviewing technical designs, conducting threat models, and turning identified risks into actionable engineering recommendations.
  • Experience supporting security incident response, root-cause analysis, and corrective-action tracking.
  • Familiarity with SOC 2, ISO 27001, CIS Benchmarks, or similar security and compliance frameworks.
  • Ability to automate security workflows using Python, Bash, or another scripting language.
  • Strong written and verbal communication skills, including the ability to explain risk, priorities, and remediation requirements to both engineers and leadership.
  • A pragmatic, risk-based approach and a strong bias toward measurable execution.
Nice to Have
  • Experience securing containerized or isolated workloads running on ECS, EKS, Kubernetes, or similar platforms.
  • Experience with AWS Organizations, Control Tower, Security Hub, GuardDuty, AWS Config, CloudTrail, and IAM Identity Center.
  • Experience securing distributed systems, public APIs, browser automation infrastructure, or systems that handle customer credentials and session data.
  • Experience with SIEM, centralized security logging, and detection engineering.
  • Experience automating compliance evidence collection or working with platforms such as Vanta.
  • Experience coordinating penetration tests, red-team exercises, or customer security reviews.
  • Security certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or OSCP.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer Hybrid (Los Altos, CA; Ho Chi Minh City, Viet Nam)
Senior DevSecOps Engineer Hybrid (Los Altos, CA; Ho Chi Minh City, Viet Nam)

S27a • Los Altos (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Remote work environment
Async-friendly
Competitive compensation
Senior DevSecOps Engineer: Cloud Security & Automation
Senior DevSecOps Engineer: Cloud Security & Automation

Flexhire • United States

On-site
USD 120,000 - 180,000
Senior DevSecOps Engineer - Cloud Security Lead (Remote)
Senior DevSecOps Engineer - Cloud Security Lead (Remote)

S27a • Los Altos (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Remote work environment
Async-friendly
Competitive compensation
Senior Security Program Manager
Senior Security Program Manager

Flexhire • United States

On-site
USD 140,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation
Senior DevSecOps Lead: Secure Cloud CI/CD & Automation

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevOps Engineer
DevOps Engineer

Stellar IT Solutions LLC • St. Louis (MO)

On-site
USD 96,000 - 179,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

West Search Partners, LLC • Longmont (CO)

On-site
USD 100,000 - 140,000
DevSecOps Engineer
DevSecOps Engineer

Yugal Tech Academy • United States

Remote
USD 100,000 - 130,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000