Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff DevSecOps Engineer based in United States.
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff DevSecOps Engineer based in United States. This role offers the opportunity to shape and own the security foundations that enable modern product engineering at scale. You’ll lead the engineering side of cloud security and compliance while building secure-by-default practices directly into development workflows. Rather than focusing on reactive ticket resolution, you’ll create reusable platforms, automation, and guardrails that allow engineers to move quickly without compromising security. You’ll have broad technical ownership across infrastructure, CI/CD, vulnerability management, compliance, and runtime security. The role also provides an opportunity to apply AI and agentic tooling to reduce manual security work and accelerate remediation. You’ll work closely with security and GRC partners while helping mature an internal security capability.
Own the engineering side of the SOC 2 Type 2 compliance program, including control implementation, evidence collection, and audit readiness. Operate and improve compliance automation platforms, integrations, evidence pipelines, and control mappings. Productize compliance through policy-as-code, automated evidence generation, and security guardrails embedded into engineering workflows. Own cloud security posture management and runtime security capabilities, including posture monitoring, container scanning, infrastructure-as-code scanning, and runtime coverage. Triage, prioritize, and remediate security findings against defined SLAs while developing automation and alerting to manage security at scale. Build automated remediation workflows, including AI-assisted pipelines that can detect, create, and safely resolve security findings with minimal manual intervention. Design and maintain CI/CD security gates covering SAST, SCA, secret scanning, SBOM generation, dependency management, and container and IaC scanning. Encode security and compliance requirements into infrastructure-as-code and policy-as-code so secure practices become the default path for engineering teams. Help transition prototypes into production-ready systems by introducing secure-by-default architectures and automated controls. Develop reusable infrastructure modules, pipeline components, internal tooling, and AI/agentic capabilities that turn security operations into scalable self-service functionality. Partner with corporate security and GRC teams while strengthening the organization’s internal security engineering capabilities and decision-making processes. Requirements: 5+ years of experience in security engineering, DevSecOps, or platform/infrastructure engineering with a strong security focus; Staff-level candidates should have 8+ years and a track record of building security functions or programs. Deep hands-on experience securing cloud environments, including compute, networking, IAM, key management, and logging on a major cloud platform. Strong infrastructure-as-code expertise, particularly with Terraform and policy-as-code. Proven experience implementing CI/CD security controls such as SAST, SCA, secret scanning, dependency scanning, and container security within developer workflows. Hands-on experience managing vulnerabilities at scale, including triage, prioritization, SLA-driven remediation, and automation. Working knowledge of SOC 2 or comparable compliance frameworks, including implementing and evidencing controls within real engineering environments. Familiarity with modern security tooling across CSPM, application security, SAST, secret scanning, compliance automation, and SIEM. Strong coding and scripting skills with the ability to build scalable automation, pipelines, infrastructure modules, and security tooling rather than simply configure existing products. Experience establishing or maturing an in-house security engineering function. Multi-cloud experience and a background securing internal developer platforms. Experience designing security monitoring, detection, alerting, and response capabilities. Experience applying AI and LLM technologies to security operations, including automated remediation, evidence generation, and agentic workflows. Ability to collaborate effectively across engineering, security, compliance, and GRC teams while operating with a high degree of technical ownership. Benefits: Total cash compensation range of $150,000–$225,000 per year, depending on location, experience, and qualifications. Remote or hybrid work options, with a preference for candidates on the East Coast. Hybrid opportunities centered around New York, NY and Charlotte-area offices. Health insurance coverage, including medical, dental, and vision. Life insurance. Short- and long-term disability insurance. Flexible spending accounts. Holiday pay. 401(k) plan with company match. Employee Assistance Program. Paid parental bonding benefit program. Flexible paid time off, with full-time employees accruing 20 days annually and increasing to 25 days after five years of service. The role requires availability during Eastern Standard Time working hours. The position does not offer visa sponsorship or transfer of visa sponsorship and is not available for corp-to-corp arrangements.
Tips for this job
Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
jobgether (lever) ↗Browse current Job and Scholarship listings from jobgether (lever) →