Senior DevSecOps Engineer

360Learning

United States

Remote

USD 134,000 - 202,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Work From Home stipend
Lunch vouchers
Medical insurance
Gym subscription
1 month parental leave

Job summary

360Learning is seeking a Senior DevSecOps Engineer to make our infrastructure secure by design, detectable by default, and provable at audit time. You will bridge security and platform engineering, working hands-on with Azure, AKS, and automation to harden environments and support ISO 27001:2022 and SOC 2 Type II.

The role emphasizes greenfield work, vulnerability management, and automation, with remote-friendly work and an emphasis on security operations and infra governance.

Qualifications

  • 5+ years in infrastructure, cloud or platform engineering with a strong security focus.
  • Production experience with Kubernetes: RBAC, network policies, admission controllers, secrets handling.
  • Infrastructure as code: Terraform, GitOps workflows, CI/CD pipelines.
  • Scripting and automation: Python or Go, plus shell.
  • Log analysis and investigation across cloud audit logs and sources.
  • Fluent English (US/UK) / B2 level or equivalent.

Responsibilities

  • Be autonomous on AKS and Azure environment and handle infrastructure related alerts end to end.
  • Ship concrete hardening or automation improvements in production.
  • Own infrastructure scope of vulnerability management from triage to remediation.
  • Manage detection content as code with tested rules and runbooks.

Skills

Kubernetes
Azure
Terraform
GitOps
Python
Go
CI/CD
Log analysis
Security automation
English fluent

Tools

AKS
Cloud platforms
CI/CD tooling

Job description

Our Security and IT team keeps the 360Learning platform secure, compliant and auditable for the 1,500 organisations that learn on it every day. As a Senior DevSecOps Engineer, your mission is to make our infrastructure secure by design, detectable by default, and provable at audit time. 360Learning runs its learning platform on Azure and Kubernetes, certified ISO 27001:2022 and SOC 2 Type II. Over the past two years the technical security workload has grown on every front: a larger and more regulated customer base sending their own scans and security assessments, a wider detection and response scope, more infrastructure to keep hardened and auditable, and a growing backlog of security engineering projects that never reach the top of the queue. We are creating this position to add real technical capacity on the infrastructure side of security, and to move part of our security posture from manual effort to automated guardrails. You will be the bridge between security and platform engineering: deep enough in infrastructure to fix things yourself, and close enough to security operations to know what to look for. “Ours is a small, senior team with a broad scope: information security, compliance, infrastructure governance and internal tooling, with dual audit accountability on ISO 27001:2022 and SOC 2 Type II. That means direct impact and no layers between you and the decision. Roughly half of this role is greenfield build work you will own end to end.” Guillaume Seigneuret, CISO and Hiring Coach.

Within 1 month, you will:
  • Complete our onboarding and learn how we work through our own platform and our Convexity culture
  • Map our Azure and AKS environment, our detection and logging coverage, and our ISO 27001 and SOC 2 control scope with the CISO and the Security Engineer
  • Meet the DevOps, platform engineering and IT teams you will work with daily
  • Shadow alert triage and one customer security assessment end to end
Within 3 months, you will:
  • Be autonomous on our AKS and Azure environment and handle infrastructure related alerts end to end
  • Have shipped at least one concrete hardening or automation improvement in production
  • Own the infrastructure scope of vulnerability management, from triage to remediation follow up
Within 6 months, you will:
  • Have the honeypot live and producing high fidelity alerts
  • Have measurably widened SIEM connector coverage, with documented log sources and retention
  • Run infrastructure vulnerability remediation on a predictable cycle with SLA reporting
Within 12 months, you will:
  • Manage detection content as code, with reviewed and tested rules and documented runbooks
  • Have largely automated audit evidence on the infrastructure scope
  • Have eliminated long lived credentials on the critical paths, so engineering teams ship on secure defaults they did not have to think about
The Skill Set:
  • 5+ years in infrastructure, cloud or platform engineering with a strong security focus, or in security engineering with hands on infrastructure practice
  • Production experience with Kubernetes: RBAC, network policies, admission controllers, secrets handling, workload identity, runtime security
  • Solid cloud experience, ideally Azure. Strong AWS or Google Cloud experience with a genuine interest in converting works too
  • Infrastructure as code: Terraform, GitOps workflows, CI/CD pipelines
  • Scripting and automation: Python or Go, plus shell. Comfortable reading and writing code, and opening pull requests on repositories owned by other teams
  • Log analysis and investigation: cloud audit logs, query languages, correlation across identity, network and application sources
  • Fluent English (US/UK) / B2 level or equivalent (FR).
  • Enthusiasm for our working environment explained here: https://bit.ly/Convexity360L
What we offer:
  • Compensation: Package includes base salary, a variable component and equity
  • Benefits/Perks : Work From Home stipend, RTT, lunch vouchers, medical insurance, gym subscription, 1 month parental leave for the second parent.
  • Balance: Flexible hours, full remote work possible anywhere in France
  • Diversity, Equity, and Inclusion : We have 6 active ERGs including Mental Health, Environmental/Sustainability, Women, Parents, LGBTQIA2S+, and Ethnic Diversity. Each group has at least one executive team member serving as a member of the group, bringing greater awareness to each group’s activities and providing a quick path to impact
  • Corporate Social Responsibility : Review our CSR Charter: 360learning.com/blog/corporate-social-responsibility-charter
  • Culture: A framework that will help you make an impact - envision our way of working and our Convexity Culture: https://bit.ly/Convexity360L & find out more about the teams, product and processes https://bit.ly/42H1ggC
Interview Process:

Phone Screen with our Talent Acquisition Manager Discovery Meeting with our Head of Security Live exercise with our Head of Security and our Head of Devops: investigation of an insecure infrastructu

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

devops engineer infrastructure security
devops engineer infrastructure security

360Learning • United States

Remote
USD 180,000 - 240,000
Work From Home stipend
Medical insurance
Gym subscription
+3
Senior DevSecOps Engineer (Fully Remote)
Senior DevSecOps Engineer (Fully Remote)

360Learning • United States

Remote
USD 140,000 - 190,000
Base salary
Equity
Remote work in France
+6
Senior Security Engineer
Senior Security Engineer

Entegrata • Indianapolis (IN)

On-site
USD 120,000 - 180,000
Medical insurance
401k plan with match
Unlimited paid time off
+1
Senior DevSecOps Engineer - Remote France, Flexible Hours
Senior DevSecOps Engineer - Remote France, Flexible Hours

360Learning • United States

Remote
USD 140,000 - 190,000
Base salary
Equity
Remote work in France
+6
Cybersecurity Lead
Cybersecurity Lead

Coverflex • United States

Remote
USD 74,000 - 108,000
Stock options
All Coverflex benefits apply
Cloud Security Engineer - Remote within UK
Cloud Security Engineer - Remote within UK

Immersive • United States

Remote
USD 110,000 - 170,000
Flexible/Remote work
Birthday off
Private healthcare
+2
Senior DevOps Engineer
Senior DevOps Engineer

Pelico • Paris (TX)

On-site
USD 140,000 - 190,000
Office in Paris & Miami
Stock options
Remote flexibility
+5
Senior Devops Engineer
Senior Devops Engineer

Physitrack Limited • United States

Remote
USD 77,000 - 103,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Virtuous Management • Phoenix (AZ)

On-site
USD 120,000 - 180,000
Bonusly
401(k) with company match
Unlimited PTO
+2
Sr. Security Engineer
Sr. Security Engineer

VELOCITOR SOLUTIONS • Charlotte (NC)

On-site
USD 120,000 - 160,000
Health insurance
Paid time off
Retirement savings plan
+1