DEFCON AI15.02.26
AI SCORE 8.5

Remote Senior DevSecOps Platform Security Engineer

$140K–$180K/year

About the Role

We're hiring a Remote Senior DevSecOps Platform Security Engineer to join our innovative team at DEFCON AI. In this role, you will build and operate production security controls across our AWS and Kubernetes platform. As a key player in our organization, you will design and implement security guardrails that make secure delivery the default, ensuring our systems are resilient and secure.

What You'll Do

  • Design, build, and maintain CI/CD security controls that scale across repositories.
  • Implement developer-facing security workflows including SAST/SCA, secrets scanning, IaC scanning, and container scanning.
  • Establish software supply chain controls such as SBOM, artifact/image signing and verification, and provenance workflows.
  • Enforce Kubernetes policies and admission controls using policy-as-code to encode platform security guardrails.
  • Collaborate with Platform/SRE to co-own AWS security guardrails, including IAM patterns, logging and detection, and network and encryption baselines.
  • Work closely with Security/GRC on control interpretation and evidence needs, implementing controls in engineering systems and pipelines.

Requirements

  • 5+ years of experience in DevSecOps or Platform Security Engineering.
  • Strong knowledge of AWS security best practices and Kubernetes security.
  • Experience with CI/CD security automation and software supply chain security.
  • Familiarity with policy-as-code frameworks and tools.
  • Proficiency in scripting languages such as Python or Bash.
  • Excellent problem-solving skills and the ability to work collaboratively in a team environment.

Nice to Have

  • Experience with security compliance frameworks (e.g., NIST, ISO).
  • Knowledge of container orchestration and management tools.
  • Familiarity with security tools like Aqua, Twistlock, or similar.

What We Offer

  • Competitive salary ranging from $140,000 to $180,000 per year.
  • Fully remote work environment with flexible hours.
  • Opportunities for professional development and growth.
  • Collaborative and innovative team culture.
  • Health, dental, and vision insurance benefits.
  • Generous paid time off and holidays.
Why This Job8.5 of 10

This Remote Senior DevSecOps Platform Security Engineer role offers a unique opportunity to lead security initiatives in a cutting-edge AI company, with a competitive salary and flexible work environment.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Proficient in AWS security best practices and services, with hands-on experience in implementing IAM roles and policies to enforce least privilege access across cloud resources.

Strong understanding of Kubernetes security measures, including network policies and pod security standards, with a proactive approach to identifying and mitigating vulnerabilities in containerized applications.

Expertise in CI/CD pipelines with a focus on integrating security automation tools such as Snyk or Aqua Security to ensure that security checks are embedded in the development process from the outset.

Learning Resources

AWS Security Best Practicesguide

Career Path

Remote Senior DevSecOps Platform Security Engineer(Now)Lead DevSecOps Engineer(1-2 years)Director of Security Operations(3-5 years)

Market Overview

AWS Market Size 2024
$100B
Annual Growth (AWS)
22.5%
Global DevSecOps Adoption
40%
Investment in Security Automation
+35%
Labour Demand for DevSecOps Roles
+30%
Avg Salary for Senior DevSecOps Engineer
$140K

Skills & Requirements

Required
AWSKubernetesCI/CD
Growing in Demand
TerraformContainer SecurityInfrastructure as Code (IaC)
Declining
Traditional Network SecurityManual Deployment Processes

Domain Trends

Increased Focus on Security Automation
Organizations are investing heavily in security automation tools, with 65% of companies planning to increase their budget for security automation in the next year.
Shift to Cloud-Native Security Practices
By 2025, 70% of organizations will adopt cloud-native security practices, driven by the rapid migration to cloud environments and the need for integrated security solutions.
Rise of Policy as Code
Adoption of Policy as Code is expected to grow by 50% in the next two years, as organizations seek to automate compliance and security checks in their CI/CD pipelines.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.