DevSecOps Engineer

Posted 2 Days Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
145K-155K Annually
Junior
Software • Automation
The Role
As a DevSecOps Engineer, you will build and maintain a secure SaaS platform on AWS, integrating security measures into the CI/CD pipeline, managing vulnerability scanning, and ensuring compliance. You will work with engineering teams to implement security best practices and automate security tasks, monitoring alerts and collaborating on security infrastructure.
Summary Generated by Built In

Description

As a DevSecOps Engineer at Authorium, you'll play a vital role in building and maintaining our secure and scalable SaaS platform hosted on AWS by bridging the gap between development and security, implementing robust application security measures aligned with NIST 800-53, and engineering secure infrastructure. You'll work closely with developers, security experts, and other operations teams to ensure our platform's security, reliability, and performance.

  • Application Security:
    • Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
    • Manage vulnerability and code scanning tools to ensure adequate coverage and efficient vulnerability remediation.
    • Conduct security reviews of code, APIs, and infrastructure designs.
    • Partner with the engineering team to implement security measures and remediate any discovered vulnerabilities.
  • Security Infrastructure Engineering:
    • Design, build, and deploy secure infrastructure on AWS Commercial and AWS GovCloud using Infrastructure as Code (IaC) technologies like Terraform.
    • Oversee management of security controls within the AWS ecosystem, including IAM roles and policies, VPCs, security groups, and encryption.
    • Automate security tasks and configuration management.
    • Monitor and analyze security alerts to identify and respond to potential threats.
    • Collaborate with the DevOps team to integrate security considerations into CI/CD pipelines.
      • Defence in Depth
      • High-Availability/Disaster Recovery/Business Continuity
      • Drift Detection/Remediation
      • E2EE (end to end encryption)
      • Role-based access controls (RBAC)
      • Incident Response
      • Least Privilege
    • Familiarity with the following technologies: 
      • Linux
      • Kubernetes
      • Helm
      • CircleCI
      • Git
      • GitHub Actions
      • AWS tools and services: 
        • AWS Security Hub
        • Amazon GuardDuty
        • Amazon Inspector
        • Amazon CloudWatch
        • AWS CloudTrail
        • AWS WAF & Shield
        • AWS Key Management Service (KMS)
        • AWS Systems Manager Parameter Store
        • AWS Secrets Manager
        • AWS Lambda
        • AWS IAM
        • Amazon EC2
        • Amazon ECR
        • Amazon ECS
        • Amazon EKS
        • Amazon EFS
        • Amazon S3
        • Amazon RDS
  • General DevSecOps:
    • Collaborate with development and security teams to define and implement DevSecOps principles and best practices.
    • Manage and automate security testing procedures within the CI/CD pipeline.
    • Stay informed about new DevSecOps tools and technologies.
    • Communicate effectively with technical and non-technical stakeholders.
Requirements
  • Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
  • Minimum of 2 years of experience in information security or a related field.
  • Working knowledge of FedRAMP/StateRAMP requirements and compliance frameworks.
  • Experience with continuous monitoring tools and techniques.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.

Nice to Have:

  • Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS, etc.).
  • Knowledge of scripting languages (e.g., Python, Bash) is a plus.

Employees located within 30 miles of our hub cities—San Francisco, Sacramento, and (coming soon) Washington, D.C. —are required to work onsite from Tuesday to Thursday. Remote work is available on other days.

Benefits
  • Salary Range: $145,000-$155,000
  • Flexible PTO
  • 100% employer-funded medical, dental and vision insurance
  • 100% remote
  • $500 home office stipend
  • 401K with Profit Sharing Plan

Top Skills

AWS
Bash
Git
Helm
Kubernetes
Linux
Python
Terraform
The Company
San Francisco, California
54 Employees
On-site Workplace
Year Founded: 2014

What We Do

Authorium is the industry leader in Document Process Automation, providing a transformative enterprise solution for city, state, and federal government agencies with complex document-centric processes. Whether in Admin, Policy, HR, Budgeting, Contracts, Grants, or Procurements, Authorium accelerates time to result while ensuring compliance, insight, and oversight

Similar Jobs

BAE Systems, Inc. Logo BAE Systems, Inc.

DevSecOps Engineer [REMOTE

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote
Hybrid
Fort Walton Beach, FL, USA
40000 Employees
76K-128K Annually

MetroStar Logo MetroStar

Sr. DevSecOps Engineer I (5541)

Information Technology • Consulting
Remote
USA
250 Employees
Remote
Dallas, TX, USA
947 Employees

Sun Life Financial, Inc. Logo Sun Life Financial, Inc.

DevSecOps Engineer

Fintech • Payments • Financial Services
Remote
17 Locations
499 Employees

Similar Companies Hiring

Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees
HERE Thumbnail
Software • Logistics • Internet of Things • Information Technology • Computer Vision • Automotive • Artificial Intelligence
Amsterdam, NL
6000 Employees
True Anomaly Thumbnail
Software • Machine Learning • Hardware • Defense • Artificial Intelligence • Aerospace
Colorado Springs, CO
131 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account