
DevSecOps Engineer
Posted 4 hours ago

Posted 4 hours ago
This is a fully remote position, open to applicants in United States.
• Design and manage vulnerability scanning pipelines for both infrastructure and containers.
• Oversee CVE correlation, asset ownership mapping, and the management of remediation SLAs.
• Supervise the inventory of infrastructure fleets, policy coverage, and configuration drift.
• Create correlation logic that links vulnerabilities with business criticality and exploitability.
• Automate processes for onboarding, asset reconciliation, and exception workflows.
• Develop APIs, dashboards, and ChatOps/Slack integrations to facilitate self-service security controls.
• Establish machine-checkable security standards.
• Automatically generate audit-ready compliance evidence from system operations.
• Collaborate with SOC, Infrastructure, and Platform teams to verify production controls.
• Safeguard the developer experience while enhancing operational resilience.
• A senior platform-engineering mindset with a focus on internal tools, developer experience, and automated prevention.
• Practical experience in executing infrastructure scanning programs using tools like Nessus, Qualys, Tenable, or their equivalents.
• Proficiency in container image security utilizing Trivy or similar tools.
• Demonstrated experience with fleet inventory systems such as osquery or FleetDM.
• Familiarity with cloud platforms, preferably AWS.
• Experience in containerized and Kubernetes environments.
• Strong scripting skills in Python, Go, or Bash.
• Experience in developing custom APIs, dashboards, or system integrations.
• In-depth understanding of CVEs, CVSS/EPSS scoring, and remediation workflows.
• Nice to have: CI/CD security gates using GitLab CI or GitHub Actions.
• Nice to have: Familiarity with Kubernetes admission control and Policy-as-Code frameworks like Kyverno or OPA.
• Nice to have: Experience in automating compliance evidence for PCI DSS, SOC 2, or ISO 27001.
• Nice to have: Transitioning security functions from manual reviews to platform ownership.
• Remote-first, trust-based culture.
• Work from the location that suits you best.
• No mandatory office attendance or tracking systems.
• Optional office or coworking space access in certain locations.
• Flexible working hours without a fixed 9-to-5 schedule.
• A day off for your birthday.
• Ten personal days each year.
• Seven sick days without the need for paperwork.
• Additional time off during the Christmas and New Year period.
• Opportunities for personal development and learning.
• Coverage for role-specific events, including design conferences and marketing forums.
• Financial bonuses for marriage and welcoming a new child.
• Fully covered team offsites a few times a year.
• Provision of necessary tools and hardware to perform your job.
• Commitment to equal opportunity and a diverse, inclusive workforce.
ICF
SailPoint
Point Wild (Formerly Pango Group)
Point Wild (Formerly Pango Group)
Get handpicked remote jobs straight to your inbox weekly.