
Mid Dev Sec Ops Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Mexico.
• Take ownership of technical security measures across GCP and AWS, focusing on least-privilege IAM and RBAC, WAF, container and image security, as well as secure CI/CD processes.
• Lead the end-to-end vulnerability remediation process by assessing, prioritizing, and automating solutions.
• Collaborate with the DevOps team for the deployment of remediation in production environments.
• Integrate automated scanning and remediation into CI/CD pipelines.
• Optimize WAF policies and the OWASP Core Rule Set for applications that are publicly accessible.
• Conduct PCI DSS vulnerability scans, including quarterly external ASV assessments, and address any identified issues.
• Assist in planning and executing incident response strategies.
• Ensure that backup and recovery protocols adhere to encryption, access, and integrity standards.
• Generate and automate documentation for technical security controls.
• Maintain cloud environments linked to Drata.
• Act as a technical authority during audits, customer security evaluations, and vendor assessments concerning sensitive data.
• Over 3 years of experience in DevSecOps, security engineering, cloud security, or a related field.
• Practical knowledge of securing GCP and/or AWS, including managed Kubernetes (GKE, EKS).
• Expertise in container and vulnerability management, particularly in developing automated remediation solutions.
• Familiarity with tools such as Trivy, AWS Inspector, Amazon ECR scanning, GCP Artifact Analysis, and ZAP.
• Experience with WAF configuration and tuning the OWASP Core Rule Set.
• Proficiency in implementing least-privilege access management using IAM and RBAC across cloud services.
• Solid knowledge of Linux to address OS and package vulnerabilities in VMs and container images.
• Scripting skills in Python, Bash, or similar languages.
• Experience with CI/CD tools like GitLab CI, GitHub Actions, Jenkins, Codefresh, or equivalent.
• Background in a PCI DSS or SOC 2 setting, including the ability to produce documentation for technical controls.
• Strong written communication skills for both technical and non-technical audiences.
• Valid work authorization in Mexico.
• Preferred qualifications include low-downtime patching strategies, PCI ASV scanning experience, familiarity with compliance automation tools like Drata, serverless computing, cloud security posture management, third-party risk assessments involving PII, AI-assisted penetration testing, and relevant certifications such as OSCP, CISSP, CISM, or AWS/GCP Security Specialty.
• Equity opportunities.
• Ability to work remotely.
• Flexible scheduling to accommodate occasional work outside of regular business hours.
• Commitment to equal-opportunity employment.
• Disability support during the application process.
Innovu
BCD Travel
BCD Travel
Medtronic
Get handpicked remote jobs straight to your inbox weekly.