> Markdown version of [/jobs/ext/2248643-iac-security-engineer](https://www.wearedevelopers.com/jobs/ext/2248643-iac-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IAC Security Engineer - **Company:** American CyberSystems - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $176,800.0 - $187,200.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, JIRA, Microsoft Azure, Bash Shell, Cloud Computing Security, Continuous Integration, Software Debugging, Github, Python (Programming Language), Windows PowerShell, Regression Testing, Systems Integration, Visual Studio Online, Policy as Code, Scripting, Google Cloud, Software Security, Cloudformation, Gitlab-ci, Kubernetes, Bicep, Hashicorp, Terraform, Devsecops, Jenkins, Servicenow - **Published:** August 26, 2026 - **Apply:** https://public-rest34.bullhornstaffing.com/rest-services/2WXP1S/query/JobBoardPost?where=id=1023085&fields=id,title,publishedCategory(id,name),address(city,state),employmentType,dateLastPublished,publicDescription,isOpen,isPublic,isDeleted ## About the Role * 8+ years in Cloud Security, DevSecOps, or AppSec with deep hands-on expertise. * IaC & Containers: Strong, production-grade security experience with Terraform and Kubernetes/Helm (CloudFormation and ARM/Bicep are a plus). * Wiz Expertise: Proven experience operating Wiz for IaC scanning, CI/CD gating, and posture management. * Policy Engine: Demonstrated ability to write, debug, and test OPA/Rego rules. * CI/CD Fluency: Hands-on pipeline authoring across GitHub Actions, GitLab CI, Azure DevOps, or Jenkins. Preferred Skills * Integration experience with ServiceNow (AVR/CVR/ITSM) for finding synchronization and SLA tracking. * Scripting proficiency in Python, Bash, or PowerShell for workflow automation and reporting. * Certifications: CKA/CKAD, HashiCorp Terraform Associate, or Cloud Security (AWS, Azure, GCP). ## Description Lead and scale Infrastructure as Code (IaC) security across multi-cloud CI/CD pipelines. You will design, build, and enforce custom OPA/Rego policies with Wiz, integrate shift-left scanning across Terraform and Kubernetes, and partner directly with engineering teams to minimize noise and prevent cloud misconfigurations before deployment., * Policy as Code (OPA/Rego): Author, test, version, and tune custom IaC security rules in Rego/OPA to extend Wiz checks and codify internal guardrails. * Staged Enforcement: Manage regression testing and staged rollouts (Report ? Warn ? Block) to maintain low false-positive rates and high pipeline throughput. * CI/CD & IDE Integration: Embed Wiz CLI, VCS integrations, and plugins into GitHub Actions, GitLab CI, Azure DevOps, and VS Code for real-time PR/local feedback. * Triage & Operations: Monitor pipeline health, triage scanner failures, maintain exception ledgers, and automate findings routing via ServiceNow (AVR/CVR) and Jira. * Developer Enablement: Host office hours, build "how-to-fix" documentation, and create secure sample IaC templates to accelerate remediation. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)