Senior DevSecOps Engineer
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Ideal start timeline:
August 2026
Role status:
Exempt
Compensation: Our target hiring range is $165,000-$196,000 plus participation in our Annual Bonus Program with eligibility for $12,000 bonus. Actual compensation will be commensurate with experience and skills.
Campminder’s Flexible Working
Location:
Our employees have the option to work 100% remotely within the United States or their choice of days at home and at our office in Boulder, Colorado. We host a variety of all-company hybrid meetings and social events. We require anybody working remotely to have a very reliable, high-speed internet connection.
We know the best people can choose to work anywhere.
This role’s mission & overview:Camps trust Campminder to keep their data safe, and that trust is what lets them focus on running a great summer. You'll own how we protect that data end to end: architecting and hardening our security infrastructure, carrying our PCI and SOC2 programs through every audit, and setting the roadmap that keeps us ahead of real threats. You'll be the person the engineering org comes to on security and the one who defines what good looks like at Campminder.
Asa Senior Dev Sec Ops Engineer on our Engineering team, you will:
- Partner with the Dev Ops team to Integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and drive remediation before code reaches production
- Configure, tune, and harden WAF rules across our web applications
- Partner with platform and IT to implement and maintain EDR, DLP, vulnerability scanning and remediation, and SIEM/XDR tooling across servers and endpoints
- Manage secrets and credentials in build pipelines, including vault-based storage, rotation, and least-privilege service accounts
- Execute PCI, SOC2, and ISO technical controls: SAQ completion, quarterly ASV scans, and disaster recovery implementation
- Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration
- Coordinate pen testing engagements and drive remediation against SLA timelines
- Run security awareness training programs (KnowBe4, Security Journey) and maintain AI usage oversight, including approved tooling, code-gen governance, and supply‑chain monitoring
- Experienced in security engineering or Dev Sec Ops , with hands‑on ownership of both pipeline‑level and infrastructure‑level security
- Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud‑native identity controls like Azure conditional access
- Comfort embedding security directly into CI/CD workflows through security and dependency scanning tooling, secrets management, and policy‑as‑code
- A track record of hardening containerized and cloud‑native environments, including Kubernetes and image scanning
- Experience executing PCI, SOC2 or similar compliance technical controls (scans, SAQs, evidence prep); program ownership isn't required, but you know how to translate auditor requirements into engineering work
- Familiarity administering centralized cybersecurity solutions, endpoint security, and data loss protection
- Strong judgement on how to balance security risk with employee experience and velocity, how to build trust through balanced approaches to security risk mitigation, and knowledge of when to elevate versus fix directly
- Experience running or supporting security awareness and training programs
Exposure to AI tooling governance, such as MCP inventories, code‑gen release gating, or supply‑chain monitoring for AI‑assisted development - Strong communication skills, with the ability to communicate technical concepts to technical and non‑technical people
- A track record of working collaboratively with engineers and supporting them in learning and implementing security best practices
- A track record of empowering delivery teams to move quickly and unblock themselves
- A growth‑oriented mindset
- 60 min
- Technical interview - 30 min
- Peer interview - 30 min
- Interview with our CTO
- Robust medical, dental, and vision coverage options with generous employer…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).