Demo

DevSecOps Engineer

Authorium
San Francisco, CA Full Time
POSTED ON 12/31/2024
AVAILABLE BEFORE 2/28/2025

As a DevSecOps Engineer at Authorium, you'll play a vital role in building and maintaining our secure and scalable SaaS platform hosted on AWS by bridging the gap between development and security, implementing robust application security measures aligned with NIST 800-53, and engineering secure infrastructure. You'll work closely with developers, security experts, and other operations teams to ensure our platform's security, reliability, and performance.

  • Application Security:
    • Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
    • Manage vulnerability and code scanning tools to ensure adequate coverage and efficient vulnerability remediation.
    • Conduct security reviews of code, APIs, and infrastructure designs.
    • Partner with the engineering team to implement security measures and remediate any discovered vulnerabilities.
  • Security Infrastructure Engineering:
    • Design, build, and deploy secure infrastructure on AWS Commercial and AWS GovCloud using Infrastructure as Code (IaC) technologies like Terraform.
    • Oversee management of security controls within the AWS ecosystem, including IAM roles and policies, VPCs, security groups, and encryption.
    • Automate security tasks and configuration management.
    • Monitor and analyze security alerts to identify and respond to potential threats.
    • Collaborate with the DevOps team to integrate security considerations into CI/CD pipelines.
      • Defence in Depth
      • High-Availability/Disaster Recovery/Business Continuity
      • Drift Detection/Remediation
      • E2EE (end to end encryption)
      • Role-based access controls (RBAC)
      • Incident Response
      • Least Privilege
    • Familiarity with the following technologies: 
      • Linux
      • Kubernetes
      • Helm
      • CircleCI
      • Git
      • GitHub Actions
      • AWS tools and services: 
        • AWS Security Hub
        • Amazon GuardDuty
        • Amazon Inspector
        • Amazon CloudWatch
        • AWS CloudTrail
        • AWS WAF & Shield
        • AWS Key Management Service (KMS)
        • AWS Systems Manager Parameter Store
        • AWS Secrets Manager
        • AWS Lambda
        • AWS IAM
        • Amazon EC2
        • Amazon ECR
        • Amazon ECS
        • Amazon EKS
        • Amazon EFS
        • Amazon S3
        • Amazon RDS
  • General DevSecOps:
    • Collaborate with development and security teams to define and implement DevSecOps principles and best practices.
    • Manage and automate security testing procedures within the CI/CD pipeline.
    • Stay informed about new DevSecOps tools and technologies.
    • Communicate effectively with technical and non-technical stakeholders.
  • Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
  • Minimum of 2 years of experience in information security or a related field.
  • Working knowledge of FedRAMP/StateRAMP requirements and compliance frameworks.
  • Experience with continuous monitoring tools and techniques.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.

Nice to Have:

  • Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS, etc.).
  • Knowledge of scripting languages (e.g., Python, Bash) is a plus.
  • Salary Range: $145,000-$155,000
  • Flexible PTO
  • 100% employer-funded medical, dental and vision insurance
  • 100% remote
  • $500 home office stipend
  • 401K with Profit Sharing Plan

Salary : $145,000 - $155,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a DevSecOps Engineer?

Sign up to receive alerts about other jobs on the DevSecOps Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$92,369 - $122,605
Income Estimation: 
$117,024 - $149,811
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Authorium

Authorium
Hired Organization Address Washington, DC Full Time
Authorium is on a mission to revolutionize government operations with cutting-edge technology. For nearly a decade, we'v...
Authorium
Hired Organization Address San Francisco, CA Full Time
Authorium is on a mission to redefine how agencies manage complex document-centric workflows by pioneering a unified pla...
Authorium
Hired Organization Address San Francisco, CA Full Time
About the Position Authorium’s customers are seasoned government executives, on the cutting edge and deeply committed to...

Not the job you're looking for? Here are some other DevSecOps Engineer jobs in the San Francisco, CA area that may be a better fit.

Risk Consulting - Digital Risk - DevSecOps - Senior - Multiple Locations

Ernst & Young Advisory Services Sdn Bhd, San Francisco, CA

AI Assistant is available now!

Feel free to start your new journey!