Full Job Description
The DevSecOps Engineer secures the platform that hardware engineering teams trust to ship every day. You'll own the security engineering layer of Duro's modern stack-cloud security posture, detection and threat hunting, security telemetry, and the security infrastructure that protects multi-tenant, dedicated, and regulated (GovCloud/ITAR) environments. This is a security-first role on a small, fast-moving team reporting into the CISO organization, where you'll partner closely with platform engineering, product, and compliance to make security an accelerator rather than a gate. We're looking for an engineer who thinks in adversaries and systems, automates relentlessly, and leverages modern AI-augmented workflows to build defenses that scale. This is a hybrid role based in Los Angeles, CA (3 days per week in office).
A day in the life of our DevSecOps Engineer:
- Cloud Security Engineering: Design and operate the security posture of Duro's AWS commercial and GovCloud environments-IAM and least-privilege access models, KMS/encryption policy, VPC segmentation, network controls, and secure-by-default guardrails across accounts and tenants.
- Threat Detection & Hunting: Proactively hunt across cloud, application, and identity telemetry for anomalous and adversarial behavior. Build and tune detections as code, reduce false positives, and turn hunt findings into durable, automated coverage.
- Threat Intelligence: Operationalize threat intelligence-integrate feeds, contextualize indicators and TTPs against Duro's attack surface, and drive proactive hardening ahead of emerging threats.
- Logging, Monitoring & Reporting: Architect and administer centralized logging, SIEM, and security monitoring across the stack. Own alerting pipelines, dashboards, and the security metrics and reporting that inform leadership, customers, and compliance evidence.
- Security Infrastructure Implementation & Administration: Implement, administer, and continuously improve the security tooling estate-CSPM, vulnerability management, endpoint and workload protection, secrets management, and cloud-native security services (GuardDuty, Security Hub, CloudTrail, Config, WAF, Inspector).
- Application & Pipeline Security: Embed security into the SDLC and CI/CD-secure GitHub Actions pipelines, integrate SAST/DAST/SCA, enforce secrets hygiene, and secure container and Kubernetes workloads from build through runtime.
- Security as Code: Build reproducible, version-controlled security infrastructure and guardrails using Terraform, policy-as-code, and containerization-so controls are enforced automatically and drift is caught early.
- Compliance-Driven Controls: Partner with CISO leadership to implement and evidence controls mapped to SOC 2, ITAR, and GovCloud requirements, translating framework obligations into concrete technical enforcement.
- AI-Driven Security Engineering: Leverage AI-augmented workflows to accelerate detection engineering, triage, and control implementation while maintaining rigorous validation and review standards.
- Incident Response: Support detection, investigation, containment, and post-incident hardening-reducing mean time to detect and respond, and feeding lessons learned back into automated coverage.
Qualifications
Required:
- 7+ years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure
- Bachelor's degree in Computer Science or related field (or equivalent practical experience)
- Deep AWS security expertise-IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF-including hands-on experience across commercial and GovCloud environments
- Demonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code
- Experience operationalizing threat intelligence to drive proactive defense
- Strong background in logging, monitoring, and security reporting-centralized logging, SIEM design and administration, alerting, dashboards, and metrics
- Experience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection)
- Application and pipeline security experience-securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads
- Infrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls
- An innovative, adversarial mindset-you anticipate how systems break and automate the defense before it's needed
- Strong systems thinking and the ability to design scalable, secure, maintainable controls
- Excellent written and verbal communication skills
- Comfort operating in autonomous, fast-paced environments
Nice to Have:
- Relevant certifications (AWS Security Specialty, CISSP, OSCP, GCIH/GCIA/GCFA, or similar)
- Experience with DuploCloud or similar tenant/cloud management platforms
- Knowledge of compliance frameworks such as SOC 2, FedRAMP, ITAR, or CMMC
- Experience building security for PLM, PDM, or hardware/manufacturing industry software
- Background supporting compliance-driven or regulated (GovCloud, on-premises) deployments
- Incident response, digital forensics, or purple-team experience
- Familiarity with observability tooling such as Datadog, PostHog, or Sentry, and event-driven systems (NATS, Redis, Kafka)
- PostgreSQL and Kubernetes operational familiarity sufficient to secure and reason about those workloads
How We Build
We don't just ship features. We build platforms that make shipping inevitable-and secure by default.
At Duro, AI is integrated into our engineering and security workflows. Engineers leverage AI-powered environments to orchestrate tasks, structure context, and accelerate delivery and defense while maintaining high standards of operational and security excellence.
We value:
Adversarial intuition - understanding how systems fail and how attackers think before building the defense Detection over hope - coverage you can measure, tune, and trust, expressed as code Precision in communication - clear control design produces reliable, auditable systems Pattern recognition - knowing when to abstract, automate, or simplify Operational discipline - building controls that are observable, resilient, and self-healing Intellectual curiosity - continuously improving how we secure and scale
We optimize for engineers who can build security that fades into the background-enabling teams to deploy daily with confidence, not friction.
Additional Information
The expected annual pay range for this position is $150,000-$160,000. This position is also eligible for bonus opportunities. Please note that final offer amount will be dependent on geographic location, applicable experience, and skillset of the candidate.
Renesas offers a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, and pet insurance. In addition to elective benefit options, benefited employees receive company-paid life insurance and AD&D, LTD, short term medical benefits as well as paid sick time, paid holidays, and accrued paid vacation. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.
Videos To Watch
https://youtu.be/k-zs4tB6nNc?si=KECt1k8yn4Fo1-gZ