> Markdown version of [/jobs/ext/1405618-senior-devops-security-lead](https://www.wearedevelopers.com/jobs/ext/1405618-senior-devops-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior DevOps Security Lead - **Company:** THE KINGS - **Location:** Coppell, TX, United States - **Experience:** Expert - **Salary:** $170,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Amazon Elastic Compute Cloud, Bash Shell, Command-Line Interface, Cloud Computing Security, Continuous Integration, Software Debugging, Linux, DevOps, Disaster Recovery, Identity and Access Management, Information Security Management, Log Analysis, Raspberry Pi, Smart Devices, Software Deployment, Delivery Pipeline, Mttr, Backend, Cloudformation, Performance Monitor, Terraform, Devsecops - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=20222bd8ace94f0b ## About the Role * Bachelor's degree or equivalent experience; AWS or Security credentials a plus. * 8+ years across DevOps/SRE/platform engineering AND information security, with senior-level AWS depth. * Direct ownership of a SOC 2 (or ISO 27001) program, including auditor relationship and evidence. * Strong infrastructure-as-code (Terraform / CloudFormation), CI/CD, and containerization experience. * Strong IAM and cloud-security depth - identity federation, access governance, and hardening. * Hands-on observability and production incident response. * Deep, hands-on Linux expertise - operating, debugging, and hardening Linux hosts from the command line (systemd, networking, bash scripting, log analysis); the edge devices (Raspberry Pi) and the AWS EC2 services run on Linux. * Working Rust proficiency - able to build, package, deploy, and troubleshoot the Rust backend / VTS (including ARM / edge cross-compilation) and to own its CI/CD and release pipelines. * Pragmatic for a small, fast-moving company - risk-based, automation-first, low ego; communicates bottom-line-first. ## Description You are a proactive leader, always looking for opportunities for improvement. You love to build solid foundations and ensure uptime and reliability, as well as protection from vulnerability, are well managed. You are comfortable to lead projects and take ownership of systems and processes. You're ready to take on AWS cloud infrastructure, CI/CD, release engineering, and observability, and own the information security program and the SOC 2 compliance effort. In this seat, you'll concentrate on elevated infrastructure access with security oversight, you'll operate under explicit compensating controls that preserve segregation of duties and have the opportunity to lead in maturing our DevOps and security posture., * Own CI/CD pipelines and release engineering across all environments (Dev/QA/Staging/Production/Demo/Multi-Region). * Own cloud infrastructure-as-code (reliability, scaling, and cost optimization on AWS). * Own the observability/monitoring stack, on-call alerting, and incident response. * Implement and operate change management for production deployments. * Own the information security program, policies, and the SOC 2 control set and evidence. * Govern identity and access management (IAM) - provisioning standards, least privilege, and MFA enforcement. * Run quarterly access reviews/recertification across all in-scope systems. * Own vendor/third-party security risk assessment and review. * Manage the SOC 2 auditor relationship and readiness milestones. * Manage AWS Cognito identity integration, backups, and disaster-recovery procedures. * Monitor platform uptime percentage (target 99.9%). * Own deployment frequency and change-failure rate; mean time to recovery (MTTR). * Manage infrastructure cost as a percentage of ARR. * SOC 2 Type 1 readiness milestones delivered on schedule. * Quarterly access reviews completed on time, exceptions remediated. * Mean time to revoke access on offboarding (target = 1 business day). * Security incident count and time-to-contain. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)