Senior DevSecOps Engineer
DFO Referrals23 days ago
Base Salary
$170k - $230k/yr
Responsibilities
- Design, deploy, and secure scalable AWS and Azure environments and cloud-native infrastructure.
- Build governed cloud foundations with infrastructure as code, landing zones, guardrails, and automation.
- Embed security-by-design across the SDLC through automated controls, threat modeling, and secure design practices.
- Build and maintain secure CI/CD pipelines with automated security testing, policy gates, secret detection, and supply-chain protections.
- Implement SBOMs, signed artifacts or images, provenance verification, and artifact governance.
- Secure AWS and Azure workloads across identity, networking, compute, storage, data protection, encryption, retention, DLP, and logging.
- Operate AWS KMS and Azure Key Vault, including key rotation, auditing, and envelope encryption.
- Harden AKS and EKS with pod security, OPA/Gatekeeper, network policies, secrets management, and runtime protections.
- Centralize security telemetry and integrate cloud, pipeline, code, and Kubernetes signals into Microsoft Defender for Cloud.
- Secure AI/LLM development and inference platforms and implement LLM guardrails.
- Support reliability engineering, monitoring and telemetry, incident response, compliance, and continuous optimization.
Requirements
- Bachelor’s degree or diploma in Cybersecurity, Computer Science, Information Technology, or a related discipline.
- 10+ years of experience in DevSecOps or cloud engineering delivering and securing production AWS and Azure environments.
- At least three years of hands-on experience operating enterprise-scale platforms, including reliability engineering, monitoring and telemetry, and incident response.
- Advanced Terraform expertise; CloudFormation and Bicep experience is preferred.
- Experience building and securing CI/CD automation with GitLab and/or Azure DevOps, including automated security testing and supply-chain controls.
- Strong Kubernetes security experience with AKS and EKS, including policy enforcement and runtime protection.
- Expertise in cryptographic key management, encryption, and data security controls using AWS KMS and Azure Key Vault.
- Experience securing AI/LLM systems and inference platforms including AI Foundry, AWS Bedrock, and vLLM, with knowledge of OWASP LLM Top 10 and LLM guardrails.
- Strong proficiency across Linux and Microsoft ecosystems, including identity, hardening, patching, and operational practices.
- Scripting experience with Python, Bash, and PowerShell; Java, .NET, and JavaScript including React.js are a plus.
- Familiarity with Microsoft Defender for Cloud, AWS SCPs/RCPs, Azure Policy, and OPA/Gatekeeper.
- Strong ownership, collaboration, communication, synthesis, confidentiality, and discretion.
Benefits
- 100% company-paid medical premiums.
- 17 company-paid holidays.
- Friday summer hours.
- Monthly community happy hours.
- Hybrid work environment, primarily reporting from the New York City office.
- Free catered food services on in-office days.
- Generous PTO offering.
- Casual dress code.
- 401(k) matching with a stated $15,000 match limit.
- Gym reimbursement, backup childcare services, insurance, financial services, and legal services.