We are seeking a Senior DevSecOps Engineer with strong AWS and cloud security expertise to lead the integration of security best practices across cloud infrastructure, CI/CD pipelines, and containerized application environments.
Responsibilities- Design and implement secure DevSecOps practices across AWS infrastructure and CI/CD pipelines
- Integrate automated security scanning and validation into GitHub and GitLab workflows
- Secure containerized applications deployed in ECS Fargate environments
- Implement and manage SAST, DAST, SCA, and container vulnerability scanning solutions
- Develop and enforce secrets management and credential protection strategies
- Implement IAM governance and least-privilege access controls across cloud environments
- Secure Infrastructure-as-Code deployments using Terraform and/or CloudFormation
- Support vulnerability remediation, patching, and cloud security monitoring initiatives
- Configure monitoring, logging, alerting, and threat detection solutions
- Partner with engineering teams to improve security posture and operational resilience
- Support incident response, deployment validation, and security troubleshooting efforts
Required Qualifications- 6+ years of DevSecOps, Cloud Security, or Security Engineering experience
- Strong AWS experience including ECS Fargate, IAM, RDS, networking, and security monitoring
- Experience securing CI/CD pipelines using GitHub Actions and/or GitLab CI/CD
- Strong understanding of SAST, DAST, SCA, container scanning, and vulnerability management
- Experience securing Docker containers and Kubernetes/ECS-based workloads
- Strong knowledge of secrets management, credential rotation, and least-privilege access controls
- Experience securing Infrastructure-as-Code deployments using Terraform or CloudFormation
- Experience with security monitoring, logging, and threat detection tools
- Strong troubleshooting, incident response, and risk assessment skills
Preferred Qualifications- Experience supporting .NET applications in AWS environments
- Familiarity with AWS Security Hub, GuardDuty, CloudTrail, Datadog, Wiz, Prisma Cloud, or Aqua Security
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, HIPAA, or PCI
- Experience with automated security governance and policy enforcement tooling
- Security certifications such as AWS Security Specialty, CISSP, Security+, or CKS