Mid Dev Sec Ops Engineer
Core
Embed security into infrastructure, CI/CD pipelines, and cloud environment to maintain PCI DSS 4.0 and SOC 2 Type II compliance.
Role type
Mid-level DevSecOps Engineer
Builds
Secure cloud environments (GCP/AWS), automated scanning/remediation pipelines, and disaster recovery testing programs.
Domain
Cloud Security / DevSecOps / Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GCP and AWS security, Kubernetes (GKE/EKS), container and vulnerability management, WAF configuration, least-privilege IAM/RBAC, Linux remediation, Python/Bash scripting, CI/CD automation, PCI DSS/SOC 2 compliance
Preferred skills
Low-downtime patching strategies, PCI ASV scanning, compliance automation platforms (Drata), serverless platforms, cloud security posture tools, agentic/AI-assisted penetration testing
Technologies
GCP, AWS, Kubernetes, Trivy, AWS Inspector, Amazon ECR, GCP Artifact Analysis, ZAP, Cloud Armor, AWS WAF, Cloudflare, GitLab CI, GitHub Actions, Jenkins, Codefresh, Drata, Tenable
Responsibilities
Own technical security controls (IAM, RBAC, WAF, container security); drive end-to-end vulnerability remediation; build automated scanning into pipelines; tune WAF policies; run PCI DSS vulnerability scans; contribute to incident response planning; produce and automate compliance evidence; serve as technical expert for audits.
Seniority
Mid-level, hands-on IC