Назад
Company hidden
1 день назад

DevSecOps Engineer

159 000 - 195 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Engineer (AWS/Terraform): Building and operating secure-by-default infrastructure, access controls, secrets management, CI/CD security, and compliance foundations for offensive cyber operations with an accent on runtime security, cloud governance, and developer enablement. Focus on hardening AWS environments and delivery pipelines, automating security controls, leading incident response, and reducing friction through secure engineering tooling.

Location: On-site in Arlington, Virginia, United States. U.S. citizenship required; eligibility to obtain and maintain a U.S. Government security clearance is required, although no active clearance is required at the start.

Base salary: $159,000–$195,000 per year. Estimated total compensation: $204,000–$263,000, including target bonus and estimated equity value.

Company

hirify.global is a cybersecurity startup founded in 2024 that develops offensive cyber operations capabilities for the United States and its allies.

What you will do

  • Own runtime security and vulnerability management across cloud and container environments.
  • Design and enforce least-privilege IAM, AWS Organizations structures, account boundaries, SCPs, and security guardrails.
  • Manage secrets and credentials, including policies, tooling, rotation, and developer workflows.
  • Lead security incident detection, containment, root cause analysis, post-mortems, and remediation.
  • Harden CI/CD pipelines and embed security scanning, policy enforcement, and compliance controls into delivery workflows.
  • Build secure-by-default templates, policy-as-code automation, developer tooling, and practical security guidance.

Requirements

  • 8+ years of experience in DevSecOps, platform security, or a closely related security engineering role.
  • Hands-on AWS experience with IAM, SCPs, Organizations, GuardDuty, Security Hub, and CloudTrail.
  • Strong Terraform and infrastructure-as-code experience, including policy-as-code or continuous compliance checks.
  • Experience with production secrets management, CI/CD hardening using GitHub Actions, container security, image scanning, and runtime controls.
  • Experience leading or contributing to compliance programs and handling security incidents, on-call work, and post-mortems.
  • U.S. citizenship and eligibility to obtain and maintain a U.S. Government security clearance are required.

Nice to have

  • CMMC Level 2 or NIST SP 800-171 experience.
  • Experience growing a DevSecOps or security engineering function.
  • Familiarity with the LGTM observability stack, Ansible, or developer-facing security platforms.
  • Interest in progressing into a lead or manager role.

Culture & Benefits

  • Security is treated as an engineering force multiplier, with an emphasis on automation and enablement over manual policy enforcement.
  • Medical, dental, vision, life, AD&D, and disability coverage options.
  • Paid parental leave, including support for birthing, non-birthing, adoptive, foster, and intended parents through surrogacy.
  • Paid holidays, flexible PTO, 401(k) pre-tax and Roth options, HSA, and FSA programs.
  • The role may involve work in a controlled environment.

Hiring process

  • Role scope and compensation are calibrated through the interview process and benchmarked against competitive market data.
  • Benefits and full plan details are provided during the interview and offer process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →