DevSecOps Engineer, Cloud Security

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

DevSecOps / Cloud Security Engineer securing AWS cloud estates and CI/CD pipelines. Building security operations for a beverage-industry technology provider serving distributors, bottlers, and suppliers.

Responsibilities:

  • Make code-security scanning (SAST/SCA) a required, low-friction gate in CI/CD across development teams
  • Introduce automated application testing (DAST) and secrets scanning
  • Operationalize the 15-domain cloud-agnostic security framework and CrowdStrike CSPM across all AWS estates
  • Drive cloud misconfiguration burn-down, guardrails, and workflow integration
  • Centralize AWS access through Okta, eliminate local credentials, and implement least-privilege roles
  • Define resource tagging standards for ownership and classification
  • Implement managed secrets with rotation, encryption-at-rest verification, and data-leak-prevention beyond email
  • Configure tamper-proof immutable backup tiers on Rubrik and help define recovery-time objectives with IT
  • Build paved-road patterns and developer guidance
  • Mentor the India-based junior cloud security engineer
  • Extend the security framework to newly acquired units
  • Achieve year-one goals including security checks on 100% of production releases, CSPM across every AWS account, fully Okta-federated AWS access, adopted tagging standards, immutable backups, and automated secrets rotation

Requirements:

  • 5+ years across DevOps/platform and security engineering
  • Real ownership of CI/CD systems, including Jenkins and Bitbucket/Git-based pipelines
  • AWS experience
  • Hands-on experience with SAST/DAST/SCA tooling
  • Strong AWS security knowledge, including IAM, organizations/accounts, networking, KMS, and posture management tooling
  • Infrastructure-as-code and automation fluency with Terraform/CloudFormation and Python
  • Collaborative style suited to distributed teams
  • Comfortable mentoring and working across time zones
  • Ability to pass a pre-employment drug screening and background check
  • Nice to have: Azure exposure
  • Nice to have: Experience with Okta-AWS federation, Rubrik or equivalent backup platforms, and container security
  • Nice to have: AWS Security Specialty, CCSP, or GIAC cloud certifications

Benefits:

  • Direct executive sponsorship
  • Funded security roadmap
  • All full-time job offers contingent upon passing a pre-employment drug screening and background check