Senior DevSecOps Engineer - Remote | AWS, Terraform, Docker, PCI DSS

Remotely
Full-time

Are you a seasoned DevSecOps Engineer passionate about integrating security throughout the entire development lifecycle? We're seeking an experienced Senior DevSecOps Engineer to join our team and lead critical infrastructure security initiatives. In this role, you'll implement cutting-edge security practices, ensure PCI DSS compliance, and develop secure infrastructure architectures for both cloud and on-premises environments.


About The Role

As our Senior DevSecOps Engineer, you'll bridge the gap between development, operations, and security, ensuring that security best practices are embedded at every stage of our development pipeline.


Key Responsibilities:

- Design and develop robust security architectures aligned with PCI DSS requirements and industry-leading security standards.

- Establish and refine security processes, including defining clear role delineation for code review procedures and security assessment workflows.

- Implement and customize CI/CD security tools including GitLab, Static Application Security Testing (SAST) tools, HashiCorp Vault, and other security scanning solutions.

- Develop secure infrastructure code for AWS cloud and on-premises environments with a security-first mindset.

- Create and maintain security automation through Infrastructure as Code (IaC) using Terraform (v1.5+) and Ansible.

- Collaborate with development teams to build security into applications from the ground up.

- Monitor, audit, and continuously improve security posture across all systems and applications.

- Respond to and remediate security incidents and vulnerabilities efficiently.

- Provide security guidance and training to development and operations teams.

- Perform regular security assessments and compliance checks.


Required Skills and Experience:

- Proven experience (5+ years) in DevOps or DevSecOps roles with a strong focus on security implementation.

- Expert knowledge of containerization with Docker and container security best practices.

- Advanced Linux system administration skills with emphasis on security hardening techniques.

- Mastery of infrastructure automation using Terraform (1.5+) and configuration management with Ansible.

- Practical experience with Agile methodologies including Scrum and Kanban.

- Strong proficiency with AWS cloud services and AWS security controls (including IAM, Security Groups, WAF, GuardDuty).

- Solid understanding of database systems and SQL, including security considerations.

- Fluency in scripting with Bash for automation and security testing.

- Experience implementing and maintaining CI/CD pipelines with integrated security controls.

- Knowledge of network security principles and practices.

- Strong problem-solving abilities and analytical thinking.

- Excellent communication skills and ability to explain complex security concepts to non-technical stakeholders.


Nice to Have:

- Hands-on experience with PCI DSS compliance requirements and implementation.

- Certification in security (CISSP, CEH, AWS Security Specialty, or equivalent).

- Programming skills in Go (Golang) or Python for security automation and tooling.

- Experience with Kubernetes and Kubernetes security.

- Knowledge of additional cloud platforms (Azure, GCP).

- Familiarity with threat modeling and security risk assessment.

- Experience with security monitoring tools and SIEM solutions.

- Background in penetration testing or security assessments.


Why Join Our Team:

Working with us means joining a forward-thinking organization that values security as a fundamental aspect of our technology strategy. You'll have the opportunity to implement modern security practices, work with cutting-edge tools, and make a significant impact on our security posture. We offer competitive compensation, flexible remote work arrangements, continuous learning opportunities, and the chance to collaborate with talented professionals who are passionate about security and technology excellence.


If you're ready to take security to the next level and build resilient, secure systems that protect our business and customers, we want to hear from you.