DevSecOps Engineer
Some ghost-posting signals
- open for 59 days (30+ days starts to look stale)
- 148 open roles at this company in 30 days (mass-hiring blitz)
- no salary disclosed (correlates with ghost postings)
See your fit for this role and apply with a truthfully tailored résumé.
About the role
Responsibilities
Infrastructure as Code (IaC): Architect, deploy, and maintain complex AWS environments using Terraform. Consolidate and manage Terraform state files, module composition, and cross-stack resource references.
Security Engineering & IAM: Enforce least-privilege IAM policies, manage strict Security Group routing, and implement defense-in-depth security features (e.g., CloudFront WAF Web ACLs, Content Security Policy (CSP) violation reporting endpoints).
CI/CD & Automation: Design and optimize GitHub Actions workflows for continuous integration and continuous deployment. Manage complex build pipelines for serverless architectures (Python/Lambda) and frontend single-page applications.
Observability & Incident Response: Build CloudWatch dashboards, configure metric filters, and set up automated alerting for operational and security events. Author comprehensive deployment guides, operational runbooks, and disaster recovery processes.
Developer Enablement: Establish and maintain SDLC standards. Optimize local developer environments and AI-assisted tooling configs (e.g., Cursor rules, dev containers) to reduce token overhead and enforce secure coding practices.
Qualifications
Experience: 5+ years in DevOps, Cloud Engineering, or DevSecOps roles.
Cloud Platform: Deep expertise in AWS, specifically with serverless computing (Lambda, API Gateway), networking/routing (CloudFront, WAF, VPCs), and event-driven architecture (EventBridge).
Infrastructure as Code: Advanced proficiency with Terraform . You should be comfortable managing complex state migrations, module extractions, and zero-drift deployments.
Security-First Mindset: Strong understanding of AWS IAM (custom policies, service roles, boundary policies), network security, and application-layer protections like WAF and CSP headers.
CI/CD Tooling: Extensive experience building declarative pipelines using GitHub Actions , including custom composite actions and build artifact management.
Scripting/Languages: Strong scripting skills in Bash and Python. Experience managing Python dependencies (e.g., uv , pip ) for serverless packaging.
Stop applying to ghosts.
OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.
Do more with OyaPilot