Назад
Company hidden
обновлено 5 дней назад

Senior DevSecOps Engineer (Fintech)

130 000 - 205 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior DevSecOps Engineer (Fintech): Building and automating the security posture and compliance frameworks for a financial platform with an accent on policy-as-code and automated remediation. Focus on integrating security gates into CI/CD pipelines, ensuring SOC 2 compliance, and developing AI-assisted security operations.

Location: United States; remote or hybrid with an East Coast preference. Hybrid work is centered around offices in New York, NY or the Charlotte area. Must be able to work Eastern Standard Time hours.

Total cash compensation: $130,000–$205,000 per year.

Company

Bankrate provides financial comparison and rate data products covering mortgages, credit cards, savings, and other major consumer financial decisions as part of hirify.global.

What you will do

  • Own the engineering side of the SOC 2 Type 2 compliance program, including controls, evidence collection, and audit readiness.
  • Operate and improve compliance automation, evidence pipelines, policy-as-code, and automated guardrails.
  • Manage cloud security posture, runtime security, container and infrastructure-as-code scanning, and security monitoring.
  • Build CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container scanning.
  • Design vulnerability triage, SLA-driven remediation, alerting, auto-remediation, and AI-assisted security workflows.
  • Develop reusable security modules, pipeline components, and internal tooling while partnering with corporate security and GRC functions.

Requirements

  • 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus.
  • Hands-on cloud security experience covering compute, networking, IAM, key management, and logging on a major cloud provider.
  • Strong infrastructure-as-code and policy-as-code skills, especially Terraform.
  • Experience building CI/CD security controls, managing vulnerabilities at scale, and designing monitoring and detection systems.
  • Working knowledge of SOC 2 or comparable compliance frameworks and experience implementing and evidencing controls.
  • Must be authorized to work in the United States; visa sponsorship or transfer of visa sponsorship is not available, including for H1-B, F-1, OPT, STEM-OPT, and TN visas. Corp-to-corp arrangements are not available.

Nice to have

  • Staff-level experience building security functions or programs.
  • Multi-cloud exposure and experience securing an internal developer platform.
  • Experience applying AI or LLM tooling to security operations, including auto-remediation and agentic workflows.

Culture & Benefits

  • Remote or hybrid work options with flexible paid time off.
  • Medical, dental, and vision insurance.
  • Life insurance, short- and long-term disability insurance, and flexible spending accounts.
  • 401(k) with employer match and paid parental bonding benefits.
  • Full-time employees accrue 20 PTO days annually, increasing to 25 days after five years.

Hiring process

  • Expect live conversations with hirify.global teammates before an offer is made.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →