Staff DevSecOps Engineer

Bankrate

United States

Hybrid

USD 150,000 - 225,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance
Life Insurance
Disability Insurance
FSAs
Holiday Pay
401(k) Match
Employee Assistance Program
Parental Bonding
Flexible PTO

Job summary

Bankrate is seeking a DevSecOps Engineer to own security across our platform, bake security into the development lifecycle, and automate toil away so teams can ship fast and safely.

This is a build-the-function role with broad ownership and high impact. You will manage SOC 2 controls, CI/CD security gates, and multi-cloud tooling, enabling auto-remediation and policy-as-code. Remote or hybrid candidates are welcome, with East Coast preference and EST hours.

Qualifications

  • 8+ years in security engineering with a track record of building security functions or programs.
  • Deep hands-on cloud security experience on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: building pipeline security controls into developer workflows.
  • Hands-on vulnerability management at scale: triage, prioritization, SLA-driven remediation, and automation.
  • Working knowledge of SOC2 (or comparable frameworks) and evidencing controls in an engineering environment.
  • Experience applying AI/LLM tooling to security operations - auto-remediation and evidence generation.

Responsibilities

  • Own the engineering side of our SOC 2 Type 2 compliance program.
  • Operate our compliance automation platform - integrations, evidence pipelines, and mapping controls to real implementation.
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails for faster audits.
  • Own cloud security posture management and runtime security tooling across our environment.
  • Triage and remediate findings with SLA-driven processes and automation.

Skills

Cloud security
CI/CD security
Vulnerability management
SOC2 familiarity
Automation / AI remediation
Policy as code
Multi-cloud security
Incident response
Scripting / coding

Tools

Terraform
Wiz
Prisma Cloud
Snyk
Drata
Vanta

Job description

This role is open to remote or hybrid candidates (East Coast preference), with hybrid being central to our New York, NY or Charlotte area offices. Must be able to work Eastern Standard Time hours.

Platform Engineering

Platform Engineering builds the foundations our product teams ship on - deployment, infrastructure, and security. We're hiring a DevSecOps Engineer to be the technical owner of our security posture and a force multiplier for every engineer at the company. This is a build-the-function role, not a ticket-taking role. You'll treat security as code, bake it into the development lifecycle, and automate the toil away so teams can ship fast and safely. You'll have unusually broad ownership and unusually high impact.

What You'll Do:
  • Own the engineering side of our compliance program (SOC 2 Type 2): implementing controls, collecting evidence, and keeping us audit-ready.
  • Operate our compliance automation platform - integrations, evidence pipelines, and mapping controls to real implementation.
  • Productize compliance: policy-as-code, automated evidence generation, and guardrails so passing audits doesn't slow product delivery.
  • Own cloud security posture management and runtime security tooling: posture monitoring, container and IaC scanning, and runtime coverage across our environment.
  • Triage and remediate findings against demanding SLAs, and design the automation and alerting that keeps pace with volume manual effort can’t.
  • Build auto-remediation workflows - including AI-assisted pipelines - that detect, file, and (where safe) fix findings with minimal human intervention.
  • Build and maintain CI/CD security gates: SAST/SCA, secret scanning, SBOM generation, dependency management, and container/IaC scanning - implemented as reusable pipeline components and enforced through automated policy.
  • Encode security and compliance controls into infrastructure-as-code and policy-as-code so the easy path is the secure path.
  • Help close the prototype-to-production gap: turn fast-moving prototypes into production-grade, secure-by-default systems with automated guardrails.
  • Make secure-by-default the norm through our internal tooling, so the right controls are applied automatically rather than relying on engineers to remember.
  • Build the automation the team runs on - reusable modules, pipeline components, and AI/agentic tooling that turn manual security work into self-service capability.
  • Partner with corporate security and GRC functions while building and maturing our in‑house security capability, so the team can make sound security decisions quickly and independently.
What We’re Looking For:
  • 8+ years in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus (Staff level: 8+ years and a track record of building security functions or programs).
  • Deep hands-on cloud security experience (compute, networking, IAM, key management, logging) on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Proven CI/CD security experience: building pipeline security controls (SAST/SCA, secret scanning, dependency and container scanning) into developer workflows.
  • Hands-on vulnerability management at scale: triage, prioritization, SLA-driven remediation, and the automation to make it sustainable.
  • Working knowledge of SOC2 (or comparable frameworks) and what it takes to implement and evidence controls in a real engineering environment.
  • Fluency with the categories of modern cloud security tooling - CSPM, ASPM/SAST and secret scanning, compliance automation, and SIEM (e.g., tools such as Wiz, Prisma Cloud, Snyk, Drata, Vanta, or equivalents).
  • Strong coding/scripting ability to build automation, not just configure tools - you write the pipelines, modules, and tooling that scale security across many services.
  • Experience standing up or maturing an in-house security function.
  • Multi-cloud exposure and experience securing an internal developer platform.
  • Security monitoring and detection/alerting design.
  • Experience applying AI/LLM tooling to security operations - auto-remediation, evidence generation, agentic workflows.
Compensation:

Total Cash Compensation Range: $150,000 - $225,000 per year

Actual compensation varies based on location, experience, and qualifications.

Benefits:
  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program
  • Flexible Paid Time Off (PTO): We believe time to rest and recharge is essential. That's why we offer a generous and flexible PTO policy. Full-time employees accrue 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.
Who We Are:

Bankrate is where Americans go to get the best price on

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer | Bankrate
Staff DevSecOps Engineer | Bankrate

Socket.dev • United States

Hybrid
USD 150,000 - 225,000
Health Insurance Coverage (medical, 3)
Life Insurance
Disability Insurance
+4
Staff DevSecOps Engineer - Remote/Hybrid Platform Security
Staff DevSecOps Engineer - Remote/Hybrid Platform Security

Socket.dev • United States

On-site
USD 150,000 - 225,000
Health Insurance Coverage (medical, 3)
Life Insurance
Disability Insurance
+4
Senior DevSecOps Engineer - Remote, Build Security at Scale
Senior DevSecOps Engineer - Remote, Build Security at Scale

Bankrate • United States

Hybrid
USD 150,000 - 225,000
Health Insurance
Life Insurance
Disability Insurance
+6
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Greenboard • New York (NY)

Hybrid
USD 165,000 - 240,000
Salary + equity
401(k) match
Medical/Dental/Vision
+3
Member of Technical Staff, Security Engineer
Member of Technical Staff, Security Engineer

Wintermeyer Ventures • New York (NY)

On-site
USD 150,000 - 250,000
On-site in NYC
Foundational security leadership role
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Lead Security Engineer
Lead Security Engineer

Worky • Redwood City (CA)

On-site
USD 180,000 - 350,000
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

Hybrid
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Product Security Engineer
Product Security Engineer

GoMining • Georgia

Hybrid
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
DevSecOps Engineer
DevSecOps Engineer

Kavaliro • Salt Lake City (UT)

Hybrid
USD 150,000 - 170,000
Equity
Annual bonus
Employer matched retirement plan
+1