
Senior DevSecOps Engineer
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Argentina, +2 more states.
• Incorporate security measures into cloud infrastructure, Kubernetes environments, CI/CD pipelines, and developer self-service processes.
• Develop and implement secure-by-default practices for IAM, workload identity, secrets management, network security, infrastructure as code, application deployment, and workload protection.
• Evaluate the existing security landscape, pinpoint gaps and risks, and establish scalable security protocols within DevOps and platform teams.
• Create automated, risk-based security guardrails across source control, container builds, infrastructure modifications, and application deployments utilizing policy-as-code.
• Enhance security for Kubernetes, containers, and software supply chains, focusing on cluster configuration, workload isolation, ingress, admission controls, runtime protection, dependency management, SBOMs, artifact signing, and build provenance.
• Collaborate with engineering teams to identify, prioritize, and address vulnerabilities and security misconfigurations across cloud, Kubernetes, and CI/CD environments.
• Assist in security incident response across infrastructure and delivery systems, covering investigation, containment, recovery, and post-incident enhancements.
• Convert security, regulatory, and audit requirements into practical and maintainable engineering controls.
• Develop automation, documentation, runbooks, and security standards.
• Guide engineers on DevSecOps best practices.
• Over 5 years of practical experience in DevSecOps, DevOps, Cloud Security, Platform Engineering, or a similar role, with a significant focus on security engineering and automation.
• Extensive hands-on experience securing AWS or Google Cloud, covering IAM, workload identity, networking, encryption, logging, and cloud-native security measures.
• Profound experience in operating and securing Kubernetes and containerized workloads, including managed platforms like Amazon EKS or Google Kubernetes Engine.
• Strong hands-on experience with Terraform, encompassing reusable modules, dependency management, policy enforcement, and safe change management.
• Comprehensive understanding of CI/CD and release engineering, including artifact security, deployment controls, approval gates, trusted builds, and rollback strategies.
• Experience in implementing automated security controls such as vulnerability and dependency scanning, container image scanning, secrets detection, policy-as-code, infrastructure scanning, cloud configuration assessment, and software supply-chain security.
• Proficient scripting or programming skills for automation, integrations, tooling, and operational problem-solving.
• Experience in regulated or audited environments, translating frameworks such as HIPAA, SOC 2, PCI DSS, HITRUST, or SOX into engineering controls.
• Excellent communication and technical leadership abilities, capable of balancing security, reliability, developer experience, maintainability, and delivery speed.
• English proficiency: B2+ or higher.
• Full-time employment.
• 12-month+ project duration.
CWILL
a37
GT
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.