×
Register Here to Apply for Jobs or Post Jobs. X

Devsecops Engineer

Job in Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listing for: Sutherland
Full Time position
Listed on 2026-08-16
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 140000 - 180000 USD Yearly USD 140000.00 180000.00 YEAR
Job Description & How to Apply Below

Dev Sec Ops  Engineer

Cloud Security
• Kubernetes Security
• Pipeline Security

Location: Remote

Type: Full-time
• Senior
• 7+ years

ABOUT

THE ROLE

We are looking for a Dev Sec Ops  Engineer who will embed security into every layer of our cloud infrastructure and software delivery pipeline. Your primary responsibility is to ensure our GCP and AWS environments, Kubernetes clusters, CI/CD pipelines, and internal endpoints are secure, compliant, and hardened without slowing down engineering velocity. You will own the shift-left security culture, partnering closely with platform, Cloud Ops, and application teams.

RESPONSIBILITIES Cloud Security — Primary
  • Own cloud security posture management (CSPM) across GCP and AWS — continuous assessment, misconfiguration detection, and remediation tracking.
  • Design and enforce IAM policies, service account hygiene, least-privilege access controls, and workload identity across multi-cloud environments.
  • Implement VPC security controls — private service access, firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
  • Internalise and secure service endpoints — move external-facing services to internal load balancers, private endpoints, and VPN/interconnect. Continuously audit and reduce the public attack surface.
  • Manage secrets hygiene — enforce Secret Manager (GCP) and AWS Secrets Manager, eliminate hardcoded credentials, and rotate secrets programmatically.
  • Lead cloud security incident response — triage, contain, investigate, and remediate across cloud and Kubernetes environments.
  • Own compliance reporting for SOC 2, HIPAA, and ISO 27001 — evidence collection, gap analysis, and control implementation.
  • Conduct regular threat modelling, security reviews, and architecture risk assessments.
Kubernetes Security — Primary
  • Harden GKE clusters — CIS benchmarks, pod security standards (restricted/baseline), and admission control policies.
  • Implement and manage network policies to enforce east-west traffic segmentation between name spaces and services.
  • Deploy and operate runtime security tooling (e.g. Falco) for threat detection inside cluster workloads.
  • Manage Kubernetes RBAC with least-privilege principles. Audit and remediate over permissioned service accounts.
  • Secure the container supply chain — image scanning in CI (Trivy/Snyk), enforce signed images, and maintain a trusted registry policy.
  • Implement Istio security controls — mTLS enforcement, authorisation policies, and east-west traffic observability.
  • Continuously audit running workloads for security drift — privileged containers, host path mounts, and secrets in environment variables.
CI/CD & Git Lab Security — Primary
  • Secure the Git Lab CI/CD pipeline end-to‑end — protect runner environments, restrict pipeline permissions, enforce branch protection and MR approvals.
  • Integrate SAST, DAST, dependency scanning, container scanning, and secret detection natively into Git Lab CI. Own the triage and remediation workflow.
  • Implement IaC security scanning (tfsec, Checkov) as a mandatory pipeline gate for all Terraform changes.
  • Manage Git Lab token hygiene — enforce expiry policies, rotate project tokens, and audit personal access token usage.
  • Define and enforce pipeline security policies organisation-wide using Git Lab security policy‑as‑code.
Endpoint & Network Security — Primary
  • Audit and reduce the external attack surface — inventory all public endpoints and drive internalisation of services that do not need to be public.
  • Implement and maintain WAF and Cloud Armor rules to protect externally exposed services.
  • Enforce TLS certificate management — automate issuance, rotation, and enforce TLS 1.2+ across all endpoints.
  • Manage bastion host security — enforce short‑lived certificates (OS Login / IAP), eliminate persistent SSH keys, and log all administrative sessions.
  • Own DNS security controls — DNSSEC, private DNS zones for internal services, split‑horizon DNS where required.
Security Engineering & Automation
  • Build security automation pipelines — policy enforcement, compliance checks, and vulnerability remediation as code.
  • Instrument security observability in Datadog — threat detection dashboards and alert tuning for cloud and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary