> Markdown version of [/jobs/ext/2499959-cloud-security-devsecops-engineer](https://www.wearedevelopers.com/jobs/ext/2499959-cloud-security-devsecops-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security / DevSecOps Engineer - **Company:** Epsilon, Inc. - **Location:** United States (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Cloud Computing, Cloud Computing Security, Continuous Integration, Github, Security Software, Software Engineering, Software Vulnerability Management, Cloud Platform System, Software Security, Kubernetes, Terraform, Devsecops, Security Orchestration, Automation & Response, Golang - **Published:** August 25, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aeca71cada24fbcd ## About the Role * Strong professional experience with Terraform and infrastructure as code. * Hands-on experience with Go (Golang). * Experience building or maintaining CI/CD pipelines using GitHub Actions. * Experience with AWS cloud infrastructure. * Strong understanding of cloud security and infrastructure security principles. * Experience identifying and remediating vulnerabilities in containers and cloud environments. * Familiarity with NIST security guidelines and frameworks. * Experience working in a security-conscious or regulated environment., * Experience maintaining FedRAMP-compliant environments. * Experience with AWS security services and controls. * Kubernetes and container security experience. * Experience with vulnerability management and remediation. * Familiarity with automated security testing and DevSecOps practices. * Experience working with government or highly regulated customers. * Experience with additional infrastructure/security tooling such as Rust is a plus., We're looking for someone who is comfortable operating at the intersection of engineering, cloud infrastructure, security, and compliance. The ideal candidate isn't simply checking compliance boxes-they can understand the underlying infrastructure, troubleshoot technical vulnerabilities, and work directly with engineering teams to implement practical solutions. Strong Golang experience is particularly valuable for this role, as it will be used to address vulnerabilities and maintain components within the existing containerized environment. ## Description We are seeking a Cloud Security / DevSecOps Engineer to help maintain and strengthen the security, compliance, and reliability of a FedRAMP-compliant environment running on AWS. This is a highly hands-on role focused on cloud infrastructure, security automation, vulnerability remediation, and compliance. You'll work across infrastructure and application security to identify and resolve vulnerabilities, address cloud misconfigurations, and ensure the environment continues to meet stringent security and compliance requirements. This is also an opportunity for a high-performing engineer to take on increasing technical and organizational responsibility, with the potential to grow into a Head of Engineering role. What You'll Do * Maintain and improve FedRAMP compliance within an AWS environment. * Manage and improve infrastructure using Terraform and infrastructure-as-code best practices. * Identify and remediate Golang/container vulnerabilities and other security issues. * Investigate and resolve cloud infrastructure misconfigurations. * Review systems and infrastructure against NIST security guidelines and controls. * Develop and maintain CI/CD automation using GitHub Actions. * Partner with engineering teams to integrate security into the software development lifecycle. * Monitor infrastructure and applications for security vulnerabilities and compliance gaps. * Help establish repeatable processes for security, compliance, and infrastructure management. * Contribute to architectural and engineering decisions as the organization scales. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023)