DevSecOps Engineer

Compunnel

$100K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in DevSecOps and CI/CD pipeline architecture.
  • In-depth knowledge of AWS and cloud-native application deployment.
  • Proficiency in YAML for pipeline development and Infrastructure as Code.
  • Hands-on expertise with Terraform, CloudFormation, and Ansible for automation.
  • Experience integrating security controls within CI/CD workflows.
  • Strong grasp of permissions management and compliance frameworks.
  • Familiarity with containerization technologies like Docker and Kubernetes.

Responsibilities

  • Design and implement secure CI/CD pipelines using various development tools.
  • Integrate security practices including SAST, DAST, and IaC scanning into pipelines.
  • Support deployment of containerized applications on AWS ECS Fargate and Kubernetes.
  • Create reusable templates for cloud-native and commercial deployments.
  • Automate application and infrastructure provisioning workflows.
  • Develop monitoring and observability solutions using platforms like Prometheus and Grafana.
  • Collaborate with cross-functional teams to ensure secure cloud operations.

Benefits

  • Flexible work schedule and remote work options.
  • Professional development and training opportunities.
  • Access to the latest tools and technologies for optimal performance.
  • Collaborative team environment with emphasis on innovation.
  • Health, dental, and retirement benefits.
Full Job Description
Job Summary

We are seeking a highly skilled DevSecOps Engineer to design, build, and operationalize secure, automated delivery pipelines and cloud infrastructure supporting large-scale cloud transformation initiatives. This role will be responsible for driving the transition from manual operational processes to fully automated, pipeline-driven delivery using modern DevSecOps practices. The ideal candidate will possess strong expertise in AWS, Terraform, YAML-based pipeline development, cloud security, Infrastructure as Code (IaC), CI/CD automation, and compliance-driven engineering practices.

Key Responsibilities

  • Design, develop, and maintain secure CI/CD pipelines using tools such as AWS CodePipeline, CodeBuild, CodeDeploy, GitHub Actions, GitLab CI, Jenkins, or similar technologies.
  • Implement Git-based development workflows, branching strategies, signed commits, and automated quality gates.
  • Integrate security controls into CI/CD pipelines, including:
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Secret Scanning
  • Dependency Scanning
  • Infrastructure as Code (IaC) Scanning
  • Build and support deployment pipelines for containerized applications running on AWS ECS Fargate, Kubernetes, or related platforms.
  • Develop reusable pipeline templates that support cloud-native applications, open-source solutions, and commercial off-the-shelf (COTS) software deployments.
  • Implement automated testing frameworks and quality controls using tools such as JUnit, pytest, SonarQube, and vendor-specific testing platforms.
  • Design and implement blue-green and canary deployment strategies with automated rollback capabilities.
  • Automate application packaging, configuration management, and deployment workflows.
  • Leverage AI-assisted development tools for code analysis, test generation, pipeline optimization, and delivery acceleration.
  • Implement enterprise secrets management solutions using AWS Secrets Manager, CyberArk, HashiCorp Vault, or similar platforms.
  • Enforce infrastructure security through policy-driven controls, IaC scanning, and automated compliance validation.
  • Implement container image security scanning and vulnerability management processes.
  • Integrate identity and access management solutions such as Okta, CyberArk, Microsoft Entra ID (Azure AD), or similar platforms into deployment workflows.
  • Develop automated compliance and governance controls aligned with organizational security requirements.
  • Design, implement, and maintain Infrastructure as Code solutions using Terraform, CloudFormation, and Ansible.
  • Establish Git-based Infrastructure as Code workflows and automated deployment pipelines.
  • Convert legacy infrastructure environments into modern Infrastructure as Code implementations.
  • Build reusable infrastructure modules, templates, and self-service provisioning solutions.
  • Implement infrastructure drift detection, configuration validation, and compliance monitoring.
  • Automate cloud account provisioning, project onboarding, and infrastructure lifecycle management.
  • Develop monitoring, alerting, observability, and operational automation solutions using:
  • Amazon CloudWatch
  • Prometheus
  • Grafana
  • Elastic Stack
  • Datadog
  • PagerDuty
  • New Relic
  • Apply AI and machine learning capabilities to predictive alerting, log correlation, anomaly detection, and incident response automation.
  • Collaborate with infrastructure, security, application development, and operations teams to support secure and reliable cloud operations.


Required Qualifications

  • Strong experience designing and implementing CI/CD pipelines across multiple toolchains and platforms.
  • Extensive experience with YAML-based pipeline development and configuration management.
  • Hands-on experience with AWS services, cloud-native architectures, and containerized application deployments.
  • Strong proficiency with Terraform, AWS CloudFormation, and Ansible.
  • Experience integrating SAST, DAST, dependency scanning, container security, and IaC security controls into CI/CD workflows.
  • Strong understanding of secrets management, identity integration, authentication, authorization, and compliance-driven DevSecOps practices.
  • Experience automating infrastructure provisioning, configuration management, and deployment processes.
  • Strong knowledge of cloud security principles, governance frameworks, and operational best practices.
  • Experience with Git-based workflows, version control systems, and infrastructure automation.
  • Experience working with containerization technologies and orchestration platforms.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication and collaboration abilities.

Preferred Qualifications

  • Experience with AWS services including:
  • CloudFront
  • S3
  • Cloud Map
  • DataSync
  • CloudTrail
  • App Mesh
  • SQS
  • GuardDuty
  • AWS Inspector
  • Route 53
  • IAM
  • VPC Endpoints
  • Security Groups
  • Network ACLs
  • AWS WAF
  • Experience migrating legacy applications and middleware to AWS ECS, EKS, or containerized environments.
  • Experience supporting COTS application deployment automation.
  • Knowledge of Open Policy Agent (OPA) and policy-as-code frameworks.
  • Experience implementing multi-cloud Infrastructure as Code solutions across AWS, Azure, and GCP.
  • Experience with AI-assisted DevOps, observability platforms, automated remediation, and operational intelligence solutions.
  • Experience implementing FinOps, cloud cost optimization, and governance controls.
  • Familiarity with Site Reliability Engineering (SRE) principles and practices.


Certifications

  • AWS Certified Solutions Architect - Preferred
  • AWS Certified DevOps Engineer - Preferred
  • AWS Certified Security Specialty - Preferred
  • AWS Advanced Networking Certification - Preferred
  • HashiCorp Terraform Associate - Preferred
  • Certified Kubernetes Administrator (CKA) - Preferred
  • Certified Kubernetes Application Developer (CKAD) - Preferred
  • Site Reliability Engineering (SRE) Certification - Preferred

Similar Jobs

More Jobs at Compunnel

  • Security Analyst III
    $90K — $120K *
    Toronto, ON M3C 0E3
    Information Technology
    In-Person
  • DevSecOps Engineer
    $100K — $130K *
    Richmond, VA 23223 (Richmond City County)
    Information Technology
    In-Person
  • Agile Development Lead
    $110K — $140K *
    San Antonio, TX 78228 (Bexar County)
    Enterprise Technology
    In-Person
  • HPE NonStop Systems Administrator
    $90K — $120K *
    Richmond, VA 23223 (Richmond City County)
    Technical Services
    In-Person
  • Data Architect
    $100K — $130K *
    Aliso Viejo, CA 92656 (Orange County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar DevSecOps Engineer jobs: