
Senior DevSecOps Engineer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Arizona, +17 more states.
• Define and guide the DevSecOps vision across infrastructure, application, and CI/CD ecosystems.
• Architect secure-by-design cloud-native systems within AWS/GCP environments.
• Establish security patterns, guardrails, and reference architectures for engineering teams.
• Design, maintain, and secure CI/CD pipelines and developer workflows.
• Promote infrastructure-as-code security best practices utilizing Terraform, CloudFormation, and similar tools.
• Automate security testing and compliance verifications.
• Implement policy-as-code and automated governance controls.
• Develop automated workflows to enhance developer experience through tooling.
• Design and maintain Kubernetes resources and environments for both internal and external use.
• Lead the IAM strategy and enforce least-privilege access.
• Enhance the security posture for containers and Kubernetes.
• Oversee secrets management, encryption standards, and key management processes.
• Implement network segmentation, zero-trust architectures, and environment isolation controls.
• Support and advance the security program in accordance with HIPAA, SOC 2, HITRUST, and other healthcare regulatory frameworks.
• Collaborate with Security and Compliance teams during audits and remediation efforts.
• Provide senior-level leadership during incidents, including root cause analysis and long-term mitigation strategies.
• Mentor senior and mid-level engineers on secure coding practices and DevSecOps methodologies.
• Influence engineering leadership and executive stakeholders regarding DevSecOps practices, security strategy, and risk prioritization.
• Foster cross-functional alignment among Engineering, Product, IT, and Compliance teams.
• Build and manage highly reliable, secure, and compliant systems for a national pharmacy operation.
• 6+ years of experience in software engineering, infrastructure engineering, or security engineering, with substantial experience in DevSecOps settings.
• Profound knowledge of cloud architecture (AWS and/or GCP).
• Strong experience in designing, building, and securing containerized and Kubernetes-based environments.
• Practical experience with CI/CD systems such as GitHub Actions, GitLab CI, CircleCI, or Jenkins.
• Expertise in infrastructure-as-code, including Terraform and CloudFormation, along with securing IaC pipelines.
• Solid understanding of application security principles, OWASP Top 10, and secure coding methodologies.
• Extensive knowledge of IAM, RBAC, zero-trust models, and encryption best practices.
• Experience in regulated environments such as HIPAA, SOC 2, HITRUST, or PCI.
• Strong scripting or programming skills in Python, Go, Ruby, or similar languages.
• Preferred: experience in healthcare, pharmacy, fintech, or other heavily regulated sectors.
• Preferred: experience in building DevSecOps-owned resources from inception to scale.
• Preferred: background in site reliability engineering (SRE) or platform engineering.
• Preferred: security certifications like CISSP, CISM, CCSP, or AWS/GCP cloud security credentials.
• Preferred: experience with observability platforms and integrating security telemetry into monitoring systems.
• Must be authorized to work for any employer in the U.S.
• Capability to work at a computer terminal with monitor, keyboard, and mouse for extended durations.
• Ability to stoop, bend, reach for equipment and supplies, perform frequent repetitive computer-operating motions, and lift, carry, push, pull, and move light objects up to 20 pounds.
• Ability to communicate verbally, discern auditory information, and visually perceive details.
• Dental, vision, and multiple group medical plans.
• 401(k) retirement savings plan.
• Group life insurance.
• Accidental death and dismemberment (AD&D) insurance.
• Flexible spending account (FSA) and health savings account (HSA).
• Commuter benefits.
• Employer-paid short-term (STD) and long-term disability (LTD) insurance.
• Supplemental spouse life insurance.
• Legal insurance.
• Employee assistance program.
• Home health testing kits.
• Fertility medication discount program.
• Flexible vacation time.
• Accrued paid sick time.
• 10 paid holidays.
• 2 floating holidays for full-time non-exempt employees.
• Eight weeks of paid parental leave for eligible employees, with additional paid weeks for the birthing parent.
• 4 weeks paid caregiver leave.
• Monthly Lifestyle Spending Account allowance.
Rimutee
CACI International Inc
CACI International Inc
Rimutee
Get handpicked remote jobs straight to your inbox weekly.