Staff DevSecOps Engineer

Shield AI

San Mateo (CA)

On-site

USD 170,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Excellent Medical Coverage
Mental Health Employee Assistance Plan
Paid Parental Leave
Pet Insurance
Flexible Work Hours
Onsite Gym (DC)
Gym Discount (San Diego)
Free Parking
Competitive Compensation
Stock Benefits
401K Services and Match

Job summary

Shield AI in San Mateo, CA seeks a hands-on DevSecOps Engineer to design, build, and automate security controls across cloud infrastructure, software delivery systems, and containerized workloads.

You will partner with Cybersecurity, Infosec, Build Engineering, and product teams to translate security requirements into practical engineering controls and repeatable configurations, balancing security with developer productivity.

Qualifications

  • Experience implementing security controls in AWS or another major cloud environment.
  • Experience with vulnerability management, dependency scanning, container scanning, or configuration validation.
  • Ability to diagnose security and configuration issues across infrastructure, containers, and platform services.
  • Experience working with security and engineering teams to implement shared technical controls.
  • Experience automating security or infrastructure tasks using Python, Go, Bash, or a similar language.
  • Experience implementing identity, secrets, and access controls in cloud or engineering environments.
  • Experience securing containerized workloads and building or maintaining hardened container images.
  • Experience integrating security tooling into CI/CD or software delivery systems.
  • Familiarity with software supply-chain security, artifact integrity, or signing/attestation workflows.

Responsibilities

  • Design and implement security controls across AWS infrastructure and platform services.
  • Build and maintain hardened container images and secure base images for engineering and production workloads.
  • Integrate vulnerability, dependency, container, and configuration scanning into software delivery systems.
  • Automate security and compliance checks to reduce manual review and improve consistency.
  • Identify security weaknesses in infrastructure, containers, and delivery systems and drive remediation with owning teams.

Skills

IaC
AWS security
Vulnerability scanning
Container security
CI/CD security
Secrets management
Python
Go
Kubernetes security

Tools

Terraform
CI/CD tooling
Docker / containers

Job description

  • Cloud Engineering builds and operates the infrastructure and environments that support Shield AI’s software products and platforms
  • As a DevSecOps Engineer, you will design, build, and automate security controls across cloud infrastructure, software delivery systems, and containerized workloads
  • You will partner with Cybersecurity, Infosec, Build Engineering, and product teams to turn security and compliance requirements into practical engineering controls
  • This is a hands-on engineering role focused on making secure configurations repeatable and maintainable
  • You will work across infrastructure, containers, CI/CD systems, and platform services to reduce security risk without creating unnecessary friction for engineering teams
  • Design and implement security controls across AWS infrastructure and platform services
  • Build and maintain hardened container images and secure base images for engineering and production workloads
  • Integrate vulnerability, dependency, container, and configuration scanning into software delivery systems
  • Automate security and compliance checks to reduce manual review and improve consistency
  • Implement secrets management, identity, and access controls across infrastructure and engineering systems
  • Build mechanisms for audit evidence, configuration validation, and compliance reporting
  • Identify security weaknesses in infrastructure, containers, and delivery systems and drive remediation with owning teams
  • Partner with Cybersecurity and Infosec to translate security requirements into scalable engineering controls
  • Work with Build Engineering and Cloud Engineering to integrate security controls without compromising reliability or developer workflows
  • At the Staff level, Define reusable patterns and drive adoption of security engineering practices across multiple teams
Benefits
  • Excellent Medical Coverage
  • Mental Health Employee Assistance Program
  • Paid Parental Leave
  • Pet Insurance
  • Flexible Work Hours
  • Onsite Gym (DC)
  • Gym Discount (San Diego)
  • Free Parking
  • Competitive Compensation
  • Stock Benefits
  • 401K Services and Match

Experience with infrastructure-as-code and automated infrastructure provisioning5+ years of related experience for Senior Engineer or 7+ years for Staff Engineer, or equivalent education and experienceExperience implementing security controls in AWS or another major cloud environmentExperience with vulnerability management, dependency scanning, container scanning, or configuration validationAbility to diagnose security and configuration issues across infrastructure, containers, and platform servicesExperience working with security and engineering teams to implement shared technical controlsExperience automating security or infrastructure tasks using Python, Go, Bash, or a similar languageExperience implementing identity, secrets, and access controls in cloud or engineering environmentsExperience securing containerized workloads and building or maintaining hardened container imagesExperience integrating security tooling into CI/CD or software delivery systemsExperience operating systems in regulated or compliance-driven environmentsExperience with Kubernetes security, workload identity, or container runtime controlsExperience building reusable hardened images or secure infrastructure baselines used across multiple teamsExperience with cloud security posture management, policy-as-code, or automated compliance toolingExperience supporting audit evidence collection or continuous compliance workflowsFamiliarity with software supply-chain security, artifact integrity, or signing/attestation workflows

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer (R5824)
Staff DevSecOps Engineer (R5824)

AI Chopping Block • San Mateo (CA), Northern (KY)

Hybrid
USD 170,000 - 240,000
Staff DevSecOps Engineer (R5824)
Staff DevSecOps Engineer (R5824)

AI Chopping Block • San Diego (CA)

On-site
USD 160,000 - 230,000
Staff Cloud Engineer
Staff Cloud Engineer

Shield AI • San Diego (CA)

On-site
USD 150,000 - 190,000
Excellent Medical Coverage
Paid Parental Leave
Stock Benefits
+2
Staff Cloud Engineer
Staff Cloud Engineer

Shield AI • San Mateo (CA)

On-site
USD 180,000 - 240,000
Excellent Medical Coverage
Mental Health EAP
Paid Parental Leave
+8
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation
Staff DevSecOps Engineer: Secure Cloud & CI/CD Automation

AI Chopping Block • San Mateo (CA), Northern (KY)

Hybrid
USD 170,000 - 240,000
Staff DevSecOps Engineer: Cloud Security & Automation
Staff DevSecOps Engineer: Cloud Security & Automation

Shieldai • San Diego (CA)

On-site
USD 140,000 - 210,000
Staff DevSecOps Engineer: Secure Cloud & Container
Staff DevSecOps Engineer: Secure Cloud & Container

Shield AI • San Mateo (CA), Northern (KY)

Hybrid
USD 180,000 - 280,000
Staff DevSecOps Engineer: Cloud Security & Automation
Staff DevSecOps Engineer: Cloud Security & Automation

Shield AI • San Diego (CA)

On-site
USD 150,000 - 230,000
Bonus
Benefits
Equity
Staff DevSecOps Engineer (R5824)
Staff DevSecOps Engineer (R5824)

Shieldai • San Mateo (CA)

On-site
USD 150,000 - 240,000
Staff DevSecOps Engineer: Secure Cloud & CI/CD Architect
Staff DevSecOps Engineer: Secure Cloud & CI/CD Architect

AI Chopping Block • San Diego (CA)

On-site
USD 160,000 - 230,000