
DevSecOps Engineer
Towne Park3 months ago
Remote, United StatesSenior
Responsibilities
- Design, build, and maintain Azure DevOps YAML CI/CD pipelines, multi-stage release workflows, approval gates, automated rollback, branch policies, and quality gates.
- Own deployment reliability, including blue/green and canary deployments, deployment metrics, build agents, artifact feeds, and Azure Container Registry.
- Author and maintain cloud infrastructure as code using Terraform and/or Bicep, including reusable modules, state management, drift detection, environment parity, and cost-control policies.
- Define and enforce Azure Policy guardrails and policy-as-code workflows across subscriptions and management groups.
- Integrate compliance scanning with Checkov, tfsec, and PSRule and maintain audit-ready control evidence and documentation for SOC 2 and PCI DSS efforts.
- Conduct threat modeling and design secure network architectures using segmentation, private networking, web application firewalls, VPNs, private endpoints, service meshes, and zero-trust networking.
- Own vulnerability scanning, triage, remediation service levels, and closure tracking across SAST, software composition analysis, container image, and DAST findings.
- Manage Azure Key Vault, Microsoft Defender for Cloud, security monitoring, alerting, incident containment, Entra ID, RBAC, service principals, managed identities, and PIM.
- Implement feature flag infrastructure, progressive rollouts, A/B exposure controls, kill switches, and rollback mechanisms.
- Partner with application engineers and leadership to enable secure, efficient software delivery and influence technical teams without formal authority.
Requirements
- Bachelor of Science degree or major in Computer Science is required.
- At least 5 years of experience in DevOps, SRE, or platform roles, including at least 2 years of hands-on security ownership in DevSecOps, AppSec, or CloudSec.
- Deep, demonstrable Azure experience across App Services, AKS, Functions, networking, Entra ID, Key Vault, and Defender for Cloud.
- Expertise with Azure DevOps, including YAML pipelines, release management, branch policies, and artifact management.
- Production experience with Terraform or Bicep, including infrastructure module design and state management; experience with both is a plus.
- Hands-on experience with Azure Policy or equivalent policy-as-code tooling such as OPA/Rego, Sentinel, Checkov, or PSRule.
- Proficiency in at least one of PowerShell, Python, or Bash.
- Demonstrated ability to remediate security findings directly rather than only filing tickets.
- AZ-400, AZ-500, or equivalent certification is preferred.
- Strong communication skills and the ability to explain risk in business terms and influence engineers without formal authority.
Benefits
- The role offers an opportunity to make an impact at Towne Park, a hospitality services company serving patients, visitors, guests, clients, and employees.
- Travel of up to 15% may be required.
- Work is primarily performed in a climate-controlled environment, with occasional exposure to inclement weather and varying temperatures.