Lead InfoSec Engineer, DevSecOps
Core
Embed automated security controls into CI/CD pipelines and build internal DevSecOps tooling to enable secure-by-default development for cloud-native applications.
Role type
Senior IC DevSecOps Engineer
Builds
Internal DevSecOps tooling, reusable pipeline libraries, security plugins, and automation frameworks for enterprise engineering teams
Domain
Financial services / Cloud security / DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
CI/CD pipeline design, containerization (Docker, Kubernetes), infrastructure-as-code (Terraform, CloudFormation), security testing (SAST, DAST, SCA), scripting (Python, Go), cloud platforms (AWS, Azure, GCP)
Preferred skills
Internal developer platform experience, CSPM/CNAPP usage, secrets management (HashiCorp Vault), zero trust architecture, regulated industry compliance knowledge, security certifications (CISSP, CISM, CCSP)
Technologies
AWS, Azure, Google Cloud, Docker, Kubernetes, OpenShift, Terraform, CloudFormation, Pulumi, Snyk, Checkmarx, Veracode, HashiCorp Vault, Git
Responsibilities
Embed automated security controls into CI/CD pipelines; Build and maintain internal DevSecOps tooling; Champion developer-first security experiences; Drive cloud-native security architecture; Evaluate and integrate best-of-breed security tools; Support continuous compliance and governance; Provide technical leadership and mentorship; Lead vulnerability management and remediation
Seniority
Senior, hands-on IC