> Markdown version of [/jobs/ext/2218180-infrastructure-as-code-iac-security-engineer](https://www.wearedevelopers.com/jobs/ext/2218180-infrastructure-as-code-iac-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure as Code (IaC) Security Engineer - **Company:** IAC Ltd - **Location:** Concord, NC, United States - **Experience:** Expert - **Salary:** $185,120.0 - $197,600.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Programming Tools, Github, Issue Tracking Systems, Python (Programming Language), Windows PowerShell, Regression Testing, Secure Coding, Security Software, Policy as Code, Google Cloud, System Availability, Software Security, Mttr, Gitlab, Cloudformation, Kubernetes, Information Technology, Bicep, Hashicorp, Terraform, Software Version Control, Devsecops, Jenkins, Servicenow, Vulnerability Analysis - **Published:** August 25, 2026 - **Apply:** https://www.dice.com/job-detail/25efb56e-376c-427a-819d-911e2352b428 ## About the Role * Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience. * 8+ years of experience in Application Security, Cloud Security, DevSecOps, or related security engineering roles. * Hands-on experience securing Terraform and Kubernetes environments. * Experience implementing and operating Wiz or comparable cloud security and IaC security platforms. * Strong understanding of Policy as Code, including practical experience with OPA/Rego or similar frameworks. * Experience integrating security controls within CI/CD pipelines and modern software delivery practices. * Strong analytical and troubleshooting skills with the ability to manage security findings at scale. * Excellent written and verbal communication skills with a demonstrated ability to influence and enable engineering teams. Preferred Qualifications * Experience integrating security workflows with ServiceNow AVR/CVR/ITSM or similar governance platforms. * Experience supporting developer tooling and IDE integrations, including VS Code. * Cloud certifications such as AWS, Azure, or Google Cloud Professional certifications. * HashiCorp Terraform Associate certification. * Kubernetes certifications such as CKA or CKAD. * Automation and scripting experience using Python, Bash, or PowerShell. * Experience building developer-focused security programs within large enterprise environments. Technologies * Cloud Security: Wiz * Infrastructure as Code: Terraform, ARM/Bicep, CloudFormation, Kubernetes, Helm * CI/CD & Source Control: Azure DevOps, GitHub, GitLab, Jenkins * Policy as Code: OPA, Rego * Workflow & Governance: ServiceNow * Automation: Python, Bash, PowerShell ## Description You will work closely with Application Security, Cloud Engineering, Platform Engineering, and Development teams to identify and prevent infrastructure misconfigurations before deployment. Success in this role requires balancing strong security controls with a frictionless developer experience while maintaining high platform reliability and low operational noise. What You'll Do Security Policy Engineering * Design, develop, and maintain custom security policies using OPA/Rego to extend IaC security coverage beyond out-of-the-box capabilities. * Translate internal security standards, compliance requirements, and cloud governance guardrails into scalable policy-as-code frameworks. * Implement version-controlled policy packages and establish governance processes for policy lifecycle management. CI/CD Security Integration * Integrate Wiz security scanning into CI/CD platforms including Azure DevOps, GitHub, GitLab, and Jenkins. * Implement automated security gates and enforcement strategies using phased rollout models (Report Warn Block). * Optimize scan performance, concurrency, and developer feedback loops to minimize pipeline impact. Platform Operations & Reliability * Monitor and maintain IaC security tooling, ensuring high availability and operational excellence. * Manage Wiz CLI upgrades, scanner integrations, policy bundle updates, and CI/CD plugin maintenance. * Develop regression testing frameworks to validate policy quality and prevent disruption during changes. Security Findings Management * Triage, validate, and prioritize IaC findings across large-scale environments. * Reduce false positives through continuous tuning and policy refinement. * Automate ownership routing, exception management, and remediation workflows. * Maintain compliance evidence, exception records, and audit-ready documentation. Developer Experience & Enablement * Enable developers through pull request scanning, local development workflows, and IDE integrations. * Provide actionable remediation guidance, reusable templates, and secure coding best practices. * Facilitate office hours, training sessions, and support channels to accelerate adoption of secure infrastructure practices. * Partner with platform teams to embed security into standardized pipelines and reusable infrastructure modules. Governance & Reporting * Integrate with ServiceNow workflows to support ticket synchronization, SLA tracking, and security lifecycle management. * Deliver operational metrics and executive reporting, including: + Security coverage + Policy adoption + Block rates + Mean Time to Resolution (MTTR) + False positive trends + Exception aging * Support audit requests with policy mappings, change records, and governance documentation. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)