Cloud Security / DevSecOps Engineer

Epsilon, Inc.
United States
12 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Cloud Computing Cloud Computing Security Continuous Integration Github Security Software Software Engineering Software Vulnerability Management Cloud Platform System Software Security Kubernetes
+4 more
Terraform Devsecops Security Orchestration, Automation & Response Golang

Job description

We are seeking a Cloud Security / DevSecOps Engineer to help maintain and strengthen the security, compliance, and reliability of a FedRAMP-compliant environment running on AWS.

This is a highly hands-on role focused on cloud infrastructure, security automation, vulnerability remediation, and compliance. You’ll work across infrastructure and application security to identify and resolve vulnerabilities, address cloud misconfigurations, and ensure the environment continues to meet stringent security and compliance requirements.

This is also an opportunity for a high-performing engineer to take on increasing technical and organizational responsibility, with the potential to grow into a Head of Engineering role.

What You’ll Do

  • Maintain and improve FedRAMP compliance within an AWS environment.
  • Manage and improve infrastructure using Terraform and infrastructure-as-code best practices.
  • Identify and remediate Golang/container vulnerabilities and other security issues.
  • Investigate and resolve cloud infrastructure misconfigurations.
  • Review systems and infrastructure against NIST security guidelines and controls.
  • Develop and maintain CI/CD automation using GitHub Actions.
  • Partner with engineering teams to integrate security into the software development lifecycle.
  • Monitor infrastructure and applications for security vulnerabilities and compliance gaps.
  • Help establish repeatable processes for security, compliance, and infrastructure management.
  • Contribute to architectural and engineering decisions as the organization scales.

Requirements

  • Strong professional experience with Terraform and infrastructure as code.
  • Hands-on experience with Go (Golang).
  • Experience building or maintaining CI/CD pipelines using GitHub Actions.
  • Experience with AWS cloud infrastructure.
  • Strong understanding of cloud security and infrastructure security principles.
  • Experience identifying and remediating vulnerabilities in containers and cloud environments.
  • Familiarity with NIST security guidelines and frameworks.
  • Experience working in a security-conscious or regulated environment., * Experience maintaining FedRAMP-compliant environments.
  • Experience with AWS security services and controls.
  • Kubernetes and container security experience.
  • Experience with vulnerability management and remediation.
  • Familiarity with automated security testing and DevSecOps practices.
  • Experience working with government or highly regulated customers.
  • Experience with additional infrastructure/security tooling such as Rust is a plus., We’re looking for someone who is comfortable operating at the intersection of engineering, cloud infrastructure, security, and compliance.

The ideal candidate isn’t simply checking compliance boxes-they can understand the underlying infrastructure, troubleshoot technical vulnerabilities, and work directly with engineering teams to implement practical solutions.

Strong Golang experience is particularly valuable for this role, as it will be used to address vulnerabilities and maintain components within the existing containerized environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

6:32 min

Embracing DevSecOps and automating the software development lifecycle

Mathias Tausig · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:20 min

Integrating security into the DevOps lifecycle

Reto Kaeser · LIVE

Videos

See all

Related articles

See all