×
Register Here to Apply for Jobs or Post Jobs. X

Senior DevSecOps Engineer Hybrid; Los Altos, CA; Ho Chi Minh , Viet Nam

Job in Northern, Floyd County, Kentucky, USA
Listing for: S27a
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below
Position: Senior DevSecOps Engineer Hybrid (Los Altos, CA; Ho Chi Minh City, Viet Nam)
Location: Northern

Job Title
Senior Dev Sec Ops  Engineer

Location
In-office or Remote - (strong preference for overlap with Pacific Time).



Employment Type
Full-time employee.

About the Role

Tiny Fish is looking for a hands-on Senior Dev Sec Ops  Engineer to drive the execution of our security program across infrastructure and product engineering.

You will own the day-to-day vulnerability management process, implement and automate security controls, and work with engineering teams to drive findings through remediation and verified closure. You will help translate security policies, compliance requirements, penetration-test findings, and identified risks into concrete engineering work.

This is an individual-contributor role for someone who combines strong cloud and application-security fundamentals with a bias for execution. You will partner closely with Infrastructure, Engineering, Product, and company leadership. You will not be expected to single-handedly own every aspect of company security strategy, compliance, and risk acceptance.

Responsibilities
  • Own the vulnerability-management lifecycle across cloud infrastructure, application code, dependencies, containers, CI/CD systems, and production services.

  • Establish repeatable processes for vulnerability discovery, triage, severity assessment, ownership, remediation SLAs, exceptions, verification, and reporting.

  • Drive critical and high-severity findings through closure by partnering with service owners and escalating unresolved risks when necessary.

  • Implement and maintain security controls across AWS, including IAM, networking, encryption, key management, secrets, logging, and workload isolation.

  • Integrate security into the software-development lifecycle through practical guardrails such as SAST, DAST, dependency scanning, secret detection, container scanning, and infrastructure-as-code checks.

  • Review security-sensitive designs and changes, perform threat modeling, and provide concrete recommendations to engineering teams.

  • Improve security across public APIs, authentication and authorization, service-to-service communication, customer credentials, sensitive data, and software-supply-chain workflows.

  • Coordinate third-party penetration tests and ensure findings are assigned, prioritized, remediated, and validated.

  • Develop and maintain incident-response playbooks, participate in security incidents, facilitate tabletop exercises, and track corrective actions after incidents.

  • Partner with Infrastructure and Observability teams to improve security logging, alerting, investigation workflows, and threat detection.

  • Translate security policies and compliance controls into technical requirements, automated checks, and engineering work.

  • Support SOC 2, ISO 27001, and other applicable assurance or regulatory initiatives through control implementation, evidence collection, and remediation of audit findings.

  • Maintain clear reporting on security posture, vulnerability backlog, remediation performance, control coverage, and overdue risks.

  • Create practical security guidance and documentation that helps engineers ship secure systems without unnecessary friction.

Qualifications
  • 5+ years of hands-on experience in Dev Sec Ops , cloud security, application security, security engineering, or a related role.

  • Demonstrated experience building or operating a vulnerability-management program and driving findings through verified remediation.

  • Strong knowledge of AWS security, including IAM, VPC networking, KMS, secrets management, logging, monitoring, and multi-account environments.

  • Production experience with infrastructure as code, preferably Terraform.

  • Experience securing CI/CD pipelines, preferably Git Hub Actions, including identity, permissions, secrets, dependencies, and build artifacts.

  • Practical experience with security tooling such as SAST, DAST, software-composition analysis, secret detection, container scanning, cloud-security posture management, and infrastructure-as-code scanning.

  • Solid understanding of common application-security risks, secure coding practices, authentication and authorization patterns, and the OWASP Top 10.

  • Experience reviewing technical designs, conducting threat models, and turning…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary