Назад
Company hidden
17 часов назад

Senior Staff Engineer (DevSecOps)

163 000 - 231 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Staff Engineer (DevSecOps): Protecting digital infrastructure, data, and cloud applications by designing secure architectures and improving cybersecurity operations with an accent on AWS, Azure, IaC, and regulatory compliance. Focus on investigating complex incidents, integrating security scanning into GitHub pipelines, assessing vulnerabilities, and strengthening controls across enterprise systems.

Location: Alameda, California, United States

Salary: $163,000–$231,000 annually, depending on geographic market, qualifications, experience, and internal equity.

Company

hirify.global is a biotechnology company developing and supporting medicines in a regulated industry environment.

What you will do

  • Design and implement secure architectures and controls for AWS and Azure cloud environments.
  • Lead cross-functional initiatives that improve security across systems, applications, and operations.
  • Investigate and resolve complex security events, including malware outbreaks, unauthorized access attempts, and major breaches.
  • Analyze security logs, assess vulnerabilities, and develop measures against current and emerging threats.
  • Integrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines.
  • Advise leaders, internal teams, vendors, and partners on cybersecurity, incident response, and regulatory controls.

Requirements

  • Bachelor’s degree with 9 years of related experience, master’s degree with 7 years of related experience, or an equivalent combination.
  • Experience operating and implementing cybersecurity tools in an enterprise environment.
  • Experience with cloud security controls including IAM, VPC, Zero Trust, IaC, security groups, key management, SDLC, CI/CD, and network security.
  • Experience with cyber incident investigation and response, system administration, and cloud, application, and infrastructure security.
  • Knowledge of PII, PHI, sensitive data, GDPR, CPRA, SOX, FDA requirements, and related compliance controls.
  • Ability to work independently, collaborate across teams, manage changing priorities, and participate in on-call coverage for critical escalations.

Nice to have

  • CISSP, CISM, CEH, OSCP, GIAC, AWS Certified Security – Specialty, or a similar certification.
  • Experience in biotech, pharmaceutical, or other regulated industries, including GxP and SOX compliance.
  • Technical lead or management experience.

Culture & Benefits

  • Collaborative, open office environment with equipment including dual monitors and ergonomic chairs.
  • Occasional travel of approximately 5%.
  • 401(k) plan with company contributions, medical, dental, and vision coverage, life and disability insurance, and flexible spending accounts.
  • Annual bonus eligibility, company stock purchase opportunities, and long-term incentives.
  • Fifteen accrued vacation days in the first year, 17 paid holidays including a winter shutdown, and up to 10 sick days annually.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →