
DevSecOps Engineer
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in United States.
• Oversee and manage Mastercam's cloud-native application platforms, AI-powered solutions, and associated infrastructure.
• Incorporate security measures throughout the software development lifecycle, covering CI/CD pipelines, Kubernetes environments, identity and access management systems, cloud services, and AI workloads.
• Design, execute, and uphold security controls that safeguard applications, infrastructure, data, and AI services.
• Set security standards, enhance risk management practices, and advocate for secure-by-design principles.
• Protect Kubernetes-based platforms and containerized workloads.
• Enforce Kubernetes security measures, including RBAC, Network Policies, Pod Security Standards, and namespace segmentation.
• Conduct security assessments of platform architecture and application deployments.
• Develop standards for infrastructure hardening and establish security baselines.
• Integrate security controls within CI/CD pipelines and deploy automated vulnerability scanning, code analysis, and compliance checks.
• Create secure software supply chain processes and maintain security guardrails within GitOps workflows.
• Collaborate with development teams to address vulnerabilities and enhance secure coding practices.
• Ensure the security of authentication and authorization systems while implementing least-privilege access controls.
• Provide support for identity federation, SSO, OAuth2, OpenID Connect, and MFA.
• Evaluate systems for access governance and potential privileged access risks.
• Manage secrets, certificates, encryption keys, and service credentials, including automated rotation and lifecycle management of certificates.
• Secure API gateways and service-to-service communications in accordance with OWASP API Security standards.
• Implement API authentication, authorization, rate limiting, API threat protection, and Zero Trust networking controls.
• Develop security dashboards, alerts, metrics, and monitoring functionalities.
• Collaborate during security investigations and incident response initiatives.
• Analyze platform telemetry and audit logs to detect threats and identify control gaps.
• Assist in security assessments for AI and machine learning workloads.
• Aid in protection against prompt injection, sensitive data exposure, and model misuse.
• Engage in AI governance and risk assessment activities.
• Assess risks linked to LLMs, vector databases, and AI platforms.
• A Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field is required; equivalent combinations of education, military service, and relevant professional experience will also be considered.
• 4–5 years of experience in Security Engineering, DevSecOps, Cloud Security, DevOps, or Platform Engineering.
• At least 1 year of hands-on experience in supporting Kubernetes or containerized application environments.
• Proven experience in securing cloud-native applications and services.
• Familiarity with implementing vulnerability management and application security programs.
• Experience collaborating with software development teams and CI/CD pipelines.
• Experience in supporting AWS, Azure, or Google Cloud environments.
• Comprehensive knowledge of Kubernetes architecture, Pods, Deployments, Services, Ingresses, RBAC, Network Policies, container security, workload isolation, and cluster security fundamentals.
• Proficient in Docker, container image security, image scanning, vulnerability remediation, and secure image lifecycle management.
• Experience with CI/CD pipelines, source code management platforms, Git workflows, automation, and scripting.
• Understanding of SAST, DAST, dependency scanning, secret scanning, and Infrastructure-as-Code security.
• Knowledge of OAuth2, OpenID Connect, SAML, MFA, and Role-Based Access Control.
• Experience in vulnerability management, threat detection, security monitoring, incident response support, and risk assessments.
• Ability to automate security processes using Python, Bash, and PowerShell.
• Preferred certifications include Security+, CKA, CKS, AWS Certified Security Specialty, CISSP, CCSP, or GIAC Certifications.
• Competitive salary and performance-based incentives.
• Comprehensive health, dental, and vision insurance.
• Retirement plan options with employer matching.
• Opportunities for professional development and certification reimbursements.
• Flexible work schedules and remote work options.
FourEnergy GmbH
ICF
C&S Informática
Convene
Get handpicked remote jobs straight to your inbox weekly.