As a DevSecOps Engineer at Authorium, you'll enhance the security and scalability of our SaaS platform on AWS by integrating security into the CI/CD pipeline, designing secure infrastructure, and performing security reviews. You will collaborate with developers and security teams to implement best practices in application security while managing various AWS services and tools.
As a DevSecOps Engineer at Authorium, you'll play a vital role in building and maintaining our secure and scalable SaaS platform hosted on AWS by bridging the gap between development and security, implementing robust application security measures aligned with NIST 800-53, and engineering secure infrastructure. You'll work closely with developers, security experts, and other operations teams to ensure our platform's security, reliability, and performance.
- Application Security:
- Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
- Manage vulnerability and code scanning tools to ensure adequate coverage and efficient vulnerability remediation.
- Conduct security reviews of code, APIs, and infrastructure designs.
- Partner with the engineering team to implement security measures and remediate any discovered vulnerabilities.
- Security Infrastructure Engineering:
- Design, build, and deploy secure infrastructure on AWS Commercial and AWS GovCloud using Infrastructure as Code (IaC) technologies like Terraform.
- Oversee management of security controls within the AWS ecosystem, including IAM roles and policies, VPCs, security groups, and encryption.
- Automate security tasks and configuration management.
- Monitor and analyze security alerts to identify and respond to potential threats.
- Collaborate with the DevOps team to integrate security considerations into CI/CD pipelines.
- Defence in Depth
- High-Availability/Disaster Recovery/Business Continuity
- Drift Detection/Remediation
- E2EE (end to end encryption)
- Role-based access controls (RBAC)
- Incident Response
- Least Privilege
- Familiarity with the following technologies:
- Linux
- Kubernetes
- Helm
- CircleCI
- Git
- GitHub Actions
- AWS tools and services:
- AWS Security Hub
- Amazon GuardDuty
- Amazon Inspector
- Amazon CloudWatch
- AWS CloudTrail
- AWS WAF & Shield
- AWS Key Management Service (KMS)
- AWS Systems Manager Parameter Store
- AWS Secrets Manager
- AWS Lambda
- AWS IAM
- Amazon EC2
- Amazon ECR
- Amazon ECS
- Amazon EKS
- Amazon EFS
- Amazon S3
- Amazon RDS
- General DevSecOps:
- Collaborate with development and security teams to define and implement DevSecOps principles and best practices.
- Manage and automate security testing procedures within the CI/CD pipeline.
- Stay informed about new DevSecOps tools and technologies.
- Communicate effectively with technical and non-technical stakeholders.
- Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
- Minimum of 2 years of experience in information security or a related field.
- Working knowledge of FedRAMP/StateRAMP requirements and compliance frameworks.
- Experience with continuous monitoring tools and techniques.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team.
Nice to Have:
- Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS, etc.).
- Knowledge of scripting languages (e.g., Python, Bash) is a plus.
Employees located within 30 miles of our hub cities—San Francisco, Sacramento, and Washington, D.C. —are required to work onsite from Tuesday to Thursday. Remote work is available on other days.
- Salary Range: $145,000-$155,000
- Flexible PTO
- 100% employer-funded medical, dental and vision insurance
- 100% remote
- $500 home office stipend
- 401K with Profit Sharing Plan
Similar Jobs
Software
As a Senior DevSecOps Engineer, you will enhance software security by integrating security practices into the software development lifecycle, leading application security efforts, managing cloud security in Azure, conducting security testing, and mentoring juniors.
Top Skills:
AzureAzure DevopsAzure Key VaultAzure Security CenterBashDastGoHashicorp VaultPowershellPythonSastTerraform
Computer Vision • Software
The DevSecOps Engineer will collaborate with DevOps engineers to implement best practices in creating and documenting CI/CD processes, utilizing Terraform for infrastructure creation, writing Ansible playbooks, and building deployment tools. This role supports ETL/ELT data processes and AI/ML project hosting, requiring familiarity with cloud environments and federal contracting.
Top Skills:
AnsibleAWSAzureCodacyCodeqlDatadogOpenshiftSonarqubeTerraform
Big Data • Cloud • Digital Media • Machine Learning • Mobile • Software • Industrial
The Senior DevSecOps Engineer will enhance and automate security processes using the SOAR platform. Responsibilities include designing and implementing solutions, collaborating with teams for incident response improvement, and conducting testing and validations. The role also involves providing training, managing data feeds, and participating in security audits.
Top Skills:
BashC++PerlPythonSIEMSoar
What you need to know about the Seattle Tech Scene
Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.
Key Facts About Seattle Tech
- Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Amazon, Microsoft, Meta, Google
- Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Madrona, Fuse, Tola, Maveron
- Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute