Full Time

DevSecOps Engineer - New York Technology Partners - Chicago, IL

New York Technology Partners

Chicago, IL
150K–170K a year
Posted 9 days ago

Key Responsibilities

Drive a security-by-design approach across cloud infrastructure, CI/CD pipelines, and application architecturePartner with DevOps and platform engineering teams to embed security controls into existing and new systemsArchitect and implement cloud security posture management across AWS environments (GuardDuty, Security Hub, IAM, KMS, Secrets Manager, WAF)Define and enforce security standards for infrastructure as code (Terraform), container workloads (Docker, Kubernetes/EKS), and microservicesIntegrate automated security tooling into CI/CD pipelines including SAST, DAST, SCA, and secret scanningEstablish and maintain container and Kubernetes security practices including image scanning, runtime threat detection, and admission controlBuild and maintain observability and alerting for security events using SIEM tooling integrated with existing monitoring infrastructureDefine identity and access management standards including least-privilege IAM policies, secrets rotation, and zero-trust access patternsLead security architecture reviews for new systems, features, and third-party integrationsSupport incident response efforts as needed and drive post-incident improvementsDevelop internal security documentation, standards, and runbooks to enable the broader engineering teamEvaluate and drive compliance initiatives (SOC 2, CIS Benchmarks) as the business scales

Required Qualifications

7+ years of experience in DevOps, cloud infrastructure, or security engineering roles with meaningful overlap across both disciplinesDeep hands-on experience with AWS security services including GuardDuty, Security Hub, IAM, KMS, Secrets Manager, CloudTrail, and ConfigProficiency in infrastructure as code security using tools such as Checkov, tfsec, or Snyk IaC alongside TerraformExperience securing containerized environments with Kubernetes/EKS including Falco, Trivy, and admission controllers (Kyverno, OPA Gatekeeper)Hands-on experience with DevSecOps tooling: SAST (Se