Sr. DevSecOps Engineer (US)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Sr. DevSecOps Engineer (US): Leading FedRAMP authorization for cloud environment by implementing security controls and compliance automation with an accent on NIST 800-53 Rev. 5 and AWS GovCloud architecture. Focus on designing secure CI/CD pipelines, threat modeling, and managing audits with 3PAOs.
Location: US (Remote)
Salary: starting at $170,000 USD/year
Company
Leader in supplier risk intelligence using AI-powered agents on proprietary data platform for Fortune 500, government agencies, and global platforms.
What you will do
- Lead FedRAMP readiness program, define roadmap, own ATO timeline, and drive execution across stakeholders.
- Design and implement AWS GovCloud architecture meeting FedRAMP Moderate and High requirements.
- Translate NIST 800-53 Rev. 5 controls into auditable technical implementations and compliance automation tooling.
- Build secure CI/CD pipelines with security gates, secrets management, and deployment controls.
- Author System Security Plans, control statements, and audit evidence; work with auditors and 3PAOs.
- Perform threat modeling, risk assessments, security reviews, and embed controls across engineering lifecycle.
Requirements
- Direct hands-on FedRAMP ATO experience.
- Strong knowledge of NIST 800-53 Rev. 5 controls and technical implementation.
- Deep hands-on experience securing AWS environments, including AWS GovCloud.
- Advanced Terraform for auditable infrastructure.
- Experience building/hardening CI/CD pipelines for compliant deployments with security scanning and access controls.
- Worked directly with auditors and 3PAOs on evidence packages and assessments.
Nice to have
- SOC 2 Type II experience mapped to FedRAMP/NIST.
- Securing data platforms like Databricks.
- Familiarity with AI/LLM security concepts.
- Startup/lean DevSecOps environment experience.
Culture & Benefits
- Competitive salary with equity in post-Series B startup.
- Unlimited vacation.
- 99% covered health, dental, vision insurance for employees and dependents.
- 401K through Empower.
- Remote and hybrid work support across North America and Europe.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →