Senior DevSecOps Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• Production operations for high-traffic web apps with a focus on security • Implementing security controls (WAF, IAM, scanning) in AWS environments • Infrastructure as Code (Terraform) and CI/CD security integration • Database administration (MariaDB/MySQL) and container security (Docker) • DDoS mitigation, incident response, and compliance framework experience • Security: Vulnerability assessment, threat detection, IAM design, secrets management • DevOps: CloudWatch alerting, Terraform module dev, Bash scripting, Log analysis • Soft Skills: Security-first mindset, calm under pressure, collaborative educator • What Success Looks Like • First 30-90 Days • First 30-90 Days • Audit security posture and identify high-priority gaps • Implement automated security scanning in CI/CD pipeline • Deploy DDoS and intrusion detection monitoring (GuardDuty/WAF) • Reduce critical vulnerabilities by 40% through remediation • Ongoing Success Indicators • Zero successful penetration attempts due to unmonitored vectors • 100% of infrastructure changes pass automated security review • Security vulnerabilities remediated within SLA (Critical: 24h) • Infrastructure deployed without incidents; high deployment confidence
Responsibilities
• Infrastructure & Systems Security • Implement and maintain security scanning in CI/CD (SAST, dependency, container) • Harden AWS infrastructure (WAF, Security Groups) and manage network segmentation • Monitor security advisories, coordinate patching, and track vulnerability remediation • Manage encryption (rest/transit), secure compute resources, and audit IAM policies • Provide security tooling/dashboards and assist developers with findings • Threat Detection & Observability • Maintain CloudWatch dashboards (Payment metrics, Database health, API performance) • Configure GuardDuty/Security Hub and build alerts for DDoS, intrusion, and anomalies • Monitor production health, investigate anomalies, and perform root cause analysis • Build investigation queries for security incidents and maintain response runbooks • Monitor for penetration attempts, API abuse, and suspicious access patterns • Infrastructure as Code & Operations • Manage AWS resources via Terraform (EC2, RDS, IAM, VPC) with security-first configurations • Maintain zero-downtime CI/CD pipelines with integrated security gates and rollback mechanisms • Administer MariaDB databases (performance tuning, backups, access controls) • Maintain Docker-based dev environments and secure container configurations • Support compliance requirements (PCI-DSS) and manage evidence collection • Technical Environment • Primary: AWS (GuardDuty, WAF, CloudWatch, EC2, RDS), Terraform, Docker, MariaDB, Git, Linux • Security Tools: Snyk/SonarQube (SAST), Trivy (Container), Checkov (IaC), AWS Secrets Manager • Secondary: Nginx, Memcached, PHP 7.4 envs, GitHub Actions, Let's Encrypt
Benefits
• Competitive salary + Equity + Security certification sponsorship (CISSP, AWS Security) • Impact: Secure a revenue-critical platform serving real businesses