> Markdown version of [/jobs/ext/126928-software-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/126928-software-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer, DevSecOps - **Company:** Sift - **Location:** Marina del Rey, CA, United States - **Experience:** Experienced - **Salary:** $170,000.0 - $220,000.0 - **Contract:** Temporary contract - **Skills:** Amazon Web Services, Bash Shell, Cloud Computing, Cyber Security, Continuous Integration, Identity and Access Management, Python (Programming Language), Key Management, Software Vulnerability Management, Policy as Code, Data Logging, Delivery Pipeline, Containerization, Kubernetes, Terraform, Devsecops, Security Orchestration, Automation & Response, Vulnerability Analysis, Golang - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c03c2e3f3ad74850 ## About the Role Do you have experience in Vulnerability scanning?, * 4-7+ years of hands-on experience in security engineering, platform/DevSecOps, or cloud infrastructure roles (founding or early-stage security builder experience strongly preferred). * Proven track record shipping production-grade security automation in cloud-native environments (AWS strongly preferred) - not just documenting or managing compliance programs. * Deep familiarity with implementing technical controls for SOC 2, FedRAMP, or similar frameworks in real production systems. * Strong proficiency in scripting and automation (Python, Go, Bash, or similar) and a bias toward building custom tooling over relying solely on off-the-shelf products. * Hands-on experience with Infrastructure as Code (Terraform or equivalent), containerized environments (Kubernetes), and CI/CD systems - and how to embed security directly into them. * Working knowledge across core security domains: + Access control, identity management, and least-privilege enforcement + Logging, monitoring, auditing, and security observability + Encryption, key management, and secrets handling + Vulnerability scanning, policy-as-code, and continuous compliance + Incident response and change management * Ability to quickly assess system state, identify meaningful gaps, and deliver pragmatic, high-impact solutions in a fast-moving environment. * Comfort operating as a founding security engineer: you thrive in ambiguity, own standards end-to-end, and focus on enabling velocity while raising the security bar. * Strong problem-solving skills with a builder mindset - you enjoy making complex security requirements disappear into clean, automated systems that engineering teams actually love to use. ## Description As a Software Engineer, Security Infrastructure, you will not just maintain a security checklist; you will define the posture, architecture, and practices that keep our products and infrastructure secure in the most demanding environments. You will be both hands-on and strategic, building controls, automating compliance, and owning SIFT's security posture end-to-end, with technical security engineering as the primary focus. You will set the standard for how we protect our systems and data, ensuring resilience against modern threats while partnering with external compliance specialists to meet the requirements of aerospace, defense, and enterprise sectors. In This Role, You'll: * Build and maintain tooling, scripts, services, and automation that assess, enforce, and monitor security and compliance controls across our AWS cloud environments, Kubernetes clusters, and CI/CD pipelines. * Develop lightweight internal solutions (e.g., policy-as-code, custom scanners, CI/CD integrations) that make security and compliance automatic, auditable, and invisible to the rest of engineering. * Embed security guardrails directly into infrastructure-as-code (Terraform), container orchestration, and deployment workflows so that secure-by-default becomes the path of least resistance. * Partner closely with the infrastructure and platform engineering teams to harden cloud-native systems, implement access controls, encryption, logging/monitoring, and vulnerability management at scale. * Improve visibility into our overall security posture through automated reporting, dashboards, and real-time observability that highlight risks and control coverage. * Translate compliance requirements (SOC 2, FedRAMP, and related frameworks) into pragmatic, enforceable technical implementations rather than manual checklists. * Reduce toil by automating security workflows, compliance validation, and remediation so engineering can ship fast without compromising security. * Support incident response and post-incident improvements by building better observability and tooling that accelerates detection and recovery. * Conduct security reviews of new features, services, and infrastructure changes, providing clear guidance that helps teams design and implement secure solutions. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)