DevSecOps Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: New York, NY; on-site; U.S. citizenship required. The role requires eligibility to obtain and maintain a U.S. Government security clearance and may involve work in a controlled environment.
Base salary: $159,000–$195,000 per year. Estimated total compensation: $204,000–$263,000, including target bonus and estimated equity value.
Company
, founded in 2024 and headquartered in Arlington, Virginia, develops offensive cyber operations capabilities for the United States and its allies.
What you will do
- Own runtime security and vulnerability management across cloud and container environments.
- Design and enforce IAM, AWS Organizations structures, account boundaries, SCPs, and security guardrails.
- Manage secrets and credentials, including policies, tooling, rotation, and developer workflows.
- Lead security incident response, including detection, containment, root cause analysis, and remediation.
- Harden CI/CD pipelines and build secure-by-default templates for repositories, infrastructure, and delivery workflows.
- Drive compliance evidence and controls while shaping the DSO function and contributing to hiring.
Requirements
- 8+ years of experience in DevSecOps, platform security, or a related security engineering role.
- Deep hands-on AWS experience, including IAM, SCPs, Organizations, GuardDuty, Security Hub, and CloudTrail.
- Strong Terraform and policy-as-code experience using tools such as OPA, Checkov, tfsec, or AWS Config Rules.
- Experience with production secrets management, CI/CD hardening, GitHub Actions, container security, and image scanning.
- Experience leading incident response and contributing to compliance programs; CMMC Level 2 or NIST SP 800-171 experience is strongly preferred.
- U.S. citizenship and eligibility to obtain and maintain a U.S. Government security clearance are required.
Nice to have
- Experience growing a DevSecOps or security engineering function.
- Familiarity with the LGTM observability stack, Ansible, and developer-facing security platforms.
- Interest in growing into a lead or manager role.
Culture & Benefits
- Security is treated as a force multiplier for engineering, with an emphasis on automation and enablement over manual policy enforcement.
- Medical, dental, vision, life, AD&D, and disability coverage options.
- Paid parental leave, including leave for birthing, non-birthing, adoptive, foster, and intended parents through surrogacy.
- Paid holidays, flexible PTO, 401(k) options, HSA/FSA, and dependent care FSA.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →