Назад
Company hidden
6 дней назад

Staff DevSecOps Engineer (Fintech)

150 000 - 225 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff DevSecOps Engineer (Fintech) (Cloud Security/Compliance): Building security automation, compliance controls, and secure-by-default developer platforms for Bankrate with an accent on cloud security, infrastructure-as-code, CI/CD protection, and SOC 2 readiness. Focus on designing AI-assisted remediation workflows, scaling vulnerability management, and embedding policy-as-code and runtime security across internal platforms.

Location: United States; remote or hybrid, with an East Coast preference. Hybrid work is centered around the New York, NY and Charlotte-area offices. Must be able to work Eastern Standard Time hours.

Salary: $150,000–$225,000 total cash compensation per year

Company

Bankrate, part of hirify.global, provides financial rate data and comparison products covering mortgages, credit cards, savings, and other consumer financial decisions.

What you will do

  • Own the engineering side of the SOC 2 Type 2 compliance program, including controls, evidence collection, and audit readiness.
  • Operate compliance automation through integrations, evidence pipelines, and control mapping.
  • Build policy-as-code, automated evidence generation, security guardrails, and secure-by-default internal tooling.
  • Manage cloud security posture, runtime security, container and infrastructure-as-code scanning, and security monitoring.
  • Build CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container and IaC scanning.
  • Develop automated vulnerability remediation, including AI-assisted and agentic workflows, while partnering with corporate security and GRC functions.

Requirements

  • 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering; Staff-level candidates should have 8+ years and experience building security functions or programs.
  • Hands-on cloud security experience covering compute, networking, IAM, key management, and logging on a major cloud provider.
  • Strong infrastructure-as-code skills, especially Terraform, including policy-as-code.
  • Experience building CI/CD security controls, vulnerability management programs, security monitoring, and detection or alerting systems at scale.
  • Working knowledge of SOC 2 or comparable compliance frameworks and experience implementing and evidencing controls.
  • This role does not offer visa sponsorship or transfer of visa sponsorship and is not available for corp-to-corp work.

Nice to have

  • Multi-cloud experience and experience securing an internal developer platform.
  • Experience standing up or maturing an in-house security function.
  • Experience applying AI or LLM tooling to security operations, including auto-remediation and evidence generation.
  • Familiarity with CSPM, ASPM, SAST, secret scanning, compliance automation, and SIEM tools such as Wiz, Prisma Cloud, Snyk, Drata, or Vanta.

Culture & Benefits

  • Full-time employment with medical, dental, and vision insurance.
  • Life insurance, short- and long-term disability insurance, and flexible spending accounts.
  • 401(k) with company match and an employee assistance program.
  • Paid parental bonding benefits and flexible paid time off.
  • Full-time employees accrue 20 PTO days annually, increasing to 25 days after five years.

Hiring process

  • Expect live conversations with hirify.global teammates before an offer is made.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →