5 months ago
Arlington, VA, USASenior / Staff+
Base Salary
$159k - $263k/yr
Responsibilities
- Own runtime security and vulnerability management across cloud and container environments, including triage, prioritization, and remediation tracking.
- Design and enforce identity and access management across AWS and internal systems using least-privilege principles.
- Own secrets and credentials management, including policies, tooling, rotation, and developer workflows.
- Lead security incident response, including detection, containment, root cause analysis, and durable remediation.
- Manage AWS Organizations structure, account boundaries, service control policies, and security guardrails.
- Harden and maintain CI/CD pipelines with security scanning and policy enforcement.
- Drive compliance efforts, including evidence, controls, and remediation work.
- Build secure-by-default templates for repositories, pipelines, and infrastructure modules.
- Automate certificate issuance, secrets access, policy-as-code, and developer-facing security tooling.
- Produce practical security guidance for engineering teams.
- Shape the DevSecOps function and contribute to hiring and team building as the organization grows.
Requirements
- 8+ years of experience in DevSecOps, platform security, or a closely related security engineering role.
- Deep hands-on AWS experience, including IAM, SCPs, Organizations, GuardDuty, Security Hub, and CloudTrail.
- Strong Terraform infrastructure-as-code experience and experience applying policy-as-code or continuous compliance checks using tools such as OPA, Checkov, tfsec, or AWS Config Rules.
- End-to-end production experience owning secrets management.
- Experience designing and hardening CI/CD pipelines, including GitHub Actions.
- Hands-on container security experience, including image scanning and runtime controls.
- Experience leading or substantially contributing to a compliance program; CMMC Level 2 or NIST SP 800-171 experience is strongly preferred.
- Experience running incident response, participating in on-call work, leading post-mortems, and shipping remediation.
- Strong communication skills and the ability to drive security adoption through enablement.
- Experience growing a DevSecOps or security engineering function is preferred.
- Familiarity with observability tooling and security-signal analysis using the LGTM stack is preferred.
- Experience with configuration-management tools such as Ansible is preferred.
- Experience building developer-facing security platforms or internal tooling is preferred.
- Interest in growing into a lead or manager role is preferred.
- U.S. citizenship is required, and eligibility to obtain and maintain a U.S. Government security clearance is required.
Benefits
- Medical, dental, and vision plan options, plus life/AD&D and disability coverage options.
- Paid parental leave for eligible full-time employees, including 12 weeks for birthing parents, 4 weeks for non-birthing parents, and 6 weeks for adoptive, foster, or intended parents through surrogacy.
- Paid holidays and flexible PTO.
- 401(k) with pre-tax and Roth options, HSA/FSA options, and dependent-care FSA.
- Full-time, onsite role in Arlington, Virginia.