HCM - Senior DevSecOps Engineer
Core
Drive execution of security program across infrastructure and product engineering, owning vulnerability management and automating security controls.
Role type
Senior IC DevSecOps Engineer
Builds
Automated security controls, vulnerability management processes, and secure CI/CD pipelines for an AI-powered web automation platform
Domain
Cloud security and application security
Deliverable
production ML models | product features | infrastructure
Required skills
vulnerability management lifecycle, AWS security (IAM, VPC, KMS), Infrastructure as Code (Terraform), CI/CD security (GitHub Actions), SAST/DAST/SCA/container scanning, threat modeling, incident response, compliance frameworks (SOC 2, ISO 27001), Python/Bash scripting
Preferred skills
containerized workloads (ECS, EKS, Kubernetes), AWS Security Hub/GuardDuty, SIEM/detection engineering, compliance automation (Vanta), penetration test coordination, security certifications (CISSP, CISM, OSCP)
Technologies
AWS, Terraform, GitHub Actions, Python, Bash, SAST, DAST, SCA, container scanners, SOC 2, ISO 27001
Responsibilities
Own vulnerability-management lifecycle across cloud infrastructure and code; Establish repeatable processes for vulnerability discovery, triage, and remediation; Implement and maintain security controls across AWS; Integrate security into SDLC via SAST, DAST, and IaC checks; Review security-sensitive designs and perform threat modeling; Coordinate third-party penetration tests and validate findings; Develop incident-response playbooks and participate in security incidents; Partner with Infrastructure teams to improve security logging and alerting; Translate security policies into technical requirements and automated checks; Support SOC 2 and ISO 27001 initiatives; Maintain reporting on security posture and remediation performance
Seniority
Senior, hands-on IC