> Markdown version of [/jobs/ext/2026629-systems-engineer-devsecops](https://www.wearedevelopers.com/jobs/ext/2026629-systems-engineer-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Engineer (DevSecOps) - **Company:** DevSecOps, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Artificial Intelligence, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Apple Mac Systems, Systems Engineering, Ubuntu (Operating System), Cloud Engineering, Databases, Continuous Integration, Debian Linux, Linux, Disaster Recovery, Domain Name System (DNS), Federated Identity Management, Github, Graph Database, Identity and Access Management, Python (Programming Language), Key Management, Linux Servers, Online Transaction Processing, Red Hat Enterprise Linux, Zero Trust Network Access, SQL Databases, Transport Layer Security, Caching, Microsoft InTune, Github Enterprise, Data Analytics, Cloudflare, Terraform, Devsecops - **Published:** August 11, 2026 - **Apply:** https://www.elitetechnicaljobs.com/apply/?jobid=12649 ## About the Role Five years of professional experience in building and running production systems. Ideally a tertiary qualification, but we value demonstrated skill more. - Linux-first (RHEL/Debian/Ubuntu), macOS and iOS end-user devices, AWS, cloud-native - workloads run predominantly as containers and IaC, not hand-tended servers; this includes isolated, segmented environments. - Cloudflare: DNS, CDN, and Zero Trust (Access, Tunnels, WARP) end to end. AWS, multi-account: ECS/EC2, IAM, S3, networking, and governance - IaC via Terraform, Terraform-first. - Identity & endpoints: Entra ID, Intune - run well, evolved with judgment; note this is not a Windows-centric role. - Databases: Aurora (OLTP), Iceberg/S3 tables, with numerous other analytical and graph databases and caches. - CI/CD: GitHub Enterprise, Actions with security embedded in the pipeline. - AI-native engineering: you use AI tools fluently and are comfortable operating alongside AI agents in the delivery loop, You are a systems engineer first, an operator always. You have deep, evidenced experience running Linux and macOS environments in production - shown in the things you've actually built and shipped, and that you can walk us through in depth (a public GitHub or similar is welcome). You build the platform, you don't just tend it. You think in infrastructure-as-code and automation by default - Terraform, containers, CI/CD pipelines - and you treat click-ops as debt. You've designed and shipped systems that deploy, scale, and recover without someone standing over them. Every manual task is a candidate for elimination. You automate what you administer. You script fluently in shell (bash/zsh) and Python. You believe the best systems run themselves, and you build toward that. Security is woven through the work, not a layer someone else owns. DevSecOps is how you build, not a separate discipline: Zero Trust access (Cloudflare Access/Tunnels/WARP), least privilege IAM, federated identity (Entra/SSO/SCIM), secrets management and rotation, guardrails as code, and pipeline security in GitHub Actions - ephemeral credentials, secret-scanning, artefact integrity. You've done serious work across several of these surfaces and want to own the rest. You own resilience, and you prove it. Backup, disaster recovery, observability, and incident response are yours - kept honest by drill, not assumption. You instrument what you run, you know before your users do, and you've been the person in the incident, not just downstream of it. You understand the full stack beneath the application. Networking, DNS, TLS, databases - transactional and analytical. You might not be a DBA, but you speak SQL well enough to diagnose, optimise, and not break things. You work with AI, not around it. You use AI tooling - e.g. Claude Code - to go faster and build better, and you can contribute to the infrastructure that supports AI workloads. ## Description This is a foundational hire with room to grow. You will be responsible for the operational layer of a fast moving, high-impact research and technology environment. You'll start as the senior engineer who runs and hardens the platform, reporting to the CTO for our client, a growing advisor firm, with the runway to develop further. You will work closely with our Software Engineers to maintain, harden, and evolve a modern stack: macOS/iOS user endpoints, Linux servers, AWS infrastructure, Cloudflare for edge services and ZTNA, and a sophisticated data analytics environment including a multi-DB lakehouse. You will operate and continuously improve all aspects of DevSecOps - including CI/CD, secrets management, IdAM, and security posture overall. This is not a ticket-queue role. You will architect as well as administer, automate as well as operate, and maintain an optimal estate as our team and systems scale - minimising click-ops. You will not be walking into a confused mess. We already operate a sophisticated and well-designed (but part-built) environment, with clarity on where we are going. E.g. at present deployments are health-gated with automatic rollback, CI runs on short-lived redentials rather than long-lived cloud keys, dependency and image updates arrive as automated, review-gated pull requests, and backups sit in deletion-locked vaults with cross-region copies. Your job will be to help us go further. Resilience - backup, DR, recovery, and the observability and incident response around them - is yours to own, and to keep proven by drill rather than assumed. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [HTTP headers that make your website go faster](https://www.wearedevelopers.com/videos/1676-http-headers-that-make-your-website-go-faster) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)