
Senior DevOps Engineer
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Colorado, +7 more states.
• Design, develop, and manage secure CI/CD pipelines that incorporate SAST, DAST, SCA, secrets scanning, and container image scanning.
• Strengthen and automate AWS and/or Azure infrastructure utilizing infrastructure-as-code while enforcing security policies through OPA, Sentinel, or native policy engines.
• Take ownership of container and orchestration security for Docker and Kubernetes, which includes image provenance, runtime protection, network policies, and admission controls.
• Execute and fine-tune cloud security posture management, vulnerability management, and threat detection capabilities.
• Collaborate with engineering teams to address and resolve security findings.
• Create and maintain secrets management, identity, workload identity, service mesh mTLS, and least-privilege access strategies.
• Lead threat modeling sessions and secure design reviews for new services and architectures.
• Respond to security incidents and conduct post-incident analyses, enhancing detection, alerting, and runbook procedures.
• Design and oversee cloud networking, including VPC/VNet architectures, subnetting, routing, NAT, peering, transit gateways, private endpoints, and hybrid connectivity.
• Manage edge and traffic-layer security, encompassing load balancers, API gateways, WAF, DDoS protection, CDN configuration, DNS management, and TLS certificate lifecycle/PKI automation.
• Implement GitOps-based delivery using Argo CD or Flux with Helm/Kustomize, incorporating progressive delivery patterns like blue-green and canary releases, along with automated rollback capabilities.
• Establish and maintain observability functions across metrics, logging, tracing, and alerting, with defined SLOs and actionable, low-noise alerts.
• Oversee artifact repositories and software supply-chain controls, including image registries, SBOM generation, artifact signing, and provenance using Sigstore/Cosign and SLSA.
• Drive capacity planning, autoscaling, and cloud cost optimization across compute, storage, and network layers.
• Advocate for compliance-related engineering controls, including PCI DSS and SOC 2, while automating evidence collection.
• Mentor engineers on secure coding practices and operational security.
• Report directly to the Director of DevOps.
• 6–12 years of experience in DevOps, platform engineering, security engineering, or a related field.
• At least 3 years of experience focused on DevSecOps or application/cloud security in production environments.
• Extensive hands-on experience with GitHub Actions, GitLab CI, Jenkins, or Azure DevOps, including the integration of security tools into delivery pipelines.
• Strong background in cloud engineering with AWS and/or Azure, covering IAM, networking, encryption, logging, and monitoring services.
• Production-level experience with Kubernetes and containers, particularly in securing clusters and workloads at scale.
• Proficient in Terraform or CloudFormation and at least one programming language such as Python, Go, or Bash.
• Solid understanding of networking fundamentals, including TCP/IP, DNS, HTTP/HTTPS, TLS, routing, firewalls, security groups/NACLs, segmentation, tcpdump, dig, and Wireshark.
• Practical experience with cloud networking, including VPC/VNet design, load balancing, ingress controllers, private connectivity, service mesh technologies, and zero-trust network patterns.
• Experience operating Prometheus, Grafana, ELK/OpenSearch, or Datadog and utilizing telemetry to enhance reliability and security outcomes.
• Familiarity with application security principles, including OWASP Top 10, dependency and software supply-chain risk, secrets hygiene, and secure SDLC practices.
• Experience with security platforms such as Snyk, Trivy, SonarQube, Wiz, Prisma Cloud, Falco, or similar.
• Effective and pragmatic communication skills, capable of explaining risks and trade-offs to engineers and leaders and influencing without direct authority.
• Security certifications such as CISSP, CKS, OSCP, AWS Certified Security - Specialty, Azure security certifications, or GIAC.
• Networking certifications such as CCNA or AWS Certified Advanced Networking - Specialty.
• Experience with multi-region, highly available architectures, disaster recovery, and chaos engineering practices.
• Background in payments, fintech, retail, or other PCI DSS-regulated environments.
• Exposure to zero-trust architectures, SIEM/SOAR platforms, or internal security platforms and paved-road tooling.
• Contributions to open-source security tools or active participation in the security community.
• Potential eligibility for additional compensation, including bonuses, commissions, and/or equity, as applicable.
• Equal employment opportunities.
• Reasonable accommodations for individuals with disabilities.
knowmad mood
RealTime eClinical Solutions
Koniag Government Services
Koniag Government Services
Get handpicked remote jobs straight to your inbox weekly.