More jobs:
DevSecOps Engineer
Job in
South Naperville Area, Will County, Illinois, 60564, USA
Listed on 2026-09-17
Listing for:
ampliFI Loyalty Solutions
Full Time
position Listed on 2026-09-17
Job specializations:
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, AWS, Information Security & Data Protection
Job Description & How to Apply Below
Overview
The Dev Sec Ops Engineer is responsible for embedding automated security guardrails, vulnerability scanning, and compliance controls directly into our cloud platform and CI/CD pipelines. By managing security tooling platforms (SAST/DAST/SCA), automating vulnerability triage, and building secure multi-cloud integration patterns (including AWS to Google Gemini Enterprise Plus), this role ensures our core cloud infrastructure remains scalable, secure, and friction-free. This position operates as a mid-to-senior technical resource, accelerating software delivery while reducing administrative security overhead across teams.
Responsibilities- Implement, configure, and maintain automated security scanning platforms (SAST, DAST, SCA, container scanning) across our development pipelines.
- Triage security scan findings and automate remediation workflows to streamline vulnerability management across teams.
- Partner with Architecture and Engineering to establish secure multi-cloud guardrails, including AWS-to-GCP identity federation, KMS key management, and API gateway access controls for AI platform integrations.
- Enforce Infrastructure as Code (IaC) security automation (such as Terraform, Checkov, and Trivy) to embed policy-as-code across environments.
- Serve as a Subject Matter Expert (SME) for cloud security tooling, CI/CD automation, and multi-cloud access patterns, providing technical guidance across the organization.
- Proactively tune security tools to reduce false positives and eliminate operational noise for software delivery teams.
- Serve as a secondary point of escalation for security and platform incidents, rather than participating in the primary on-call rotation.
- Coordinate technical resolution during security events and contribute to post-mortem analysis to prevent recurrence.
- 3 to 5+ years of experience in Dev Sec Ops , cloud security, or platform security engineering.
- Multi-cloud experience across public cloud platforms, with deep expertise in AWS and working experience in GCP (Google Cloud Platform).
- Deep experience with AWS core security infrastructure (IAM, KMS, Secrets Manager, VPC, EKS/ECS).
- Strong proficiency in Terraform or AWS CDK to enforce infrastructure guardrails as code across cloud environments.
- Hands-on experience integrating security testing tools (SAST/DAST/SCA/Container scanning) into CI/CD pipelines (Git Hub Actions, AWS Code Build, or Jenkins).
- Experience establishing identity flows, OAuth configurations, and Workload/Workforce Identity Federation across multi-cloud environments (AWS and GCP).
- Hands-on experience with container security, image scanning repositories (ECR, Trivy), and containerized application runtime security.
- Proficiency in Cloud Watch, SIEM log monitoring, and security findings triage.
- Professional or Associate cloud or security certifications (such as AWS Certified Security Specialty, GCP Professional Cloud Security Engineer, CISSP, AWS Sys Ops Administrator, or Dev Ops Engineer).
- Hands-on experience implementing cross-cloud integration patterns between AWS workloads and GCP enterprise services (such as Google Gemini Enterprise Plus).
- High proficiency in scripting languages (Python, Go, Bash, or Power Shell) to automate security workflows and vulnerability triage.
- Direct experience with container orchestration platforms (AWS ECS/Fargate or EKS) and microservice security.
- Familiarity with database security controls and encrypted connectivity in cloud environments (Postgres, MySQL, DynamoDB).
- Proactive Problem Solver:
Does not wait for tickets; actively identifies platform bottlenecks, security risks, and scanner noise, proposing and implementing automated solutions independently. - Developer-Centric Mindset:
Views the developer as a customer, focusing on creating frictionless security controls and actionable feedback loops for engineering teams. - Cross-Functional Collaborator:
Able to navigate and work effectively across multiple departments (Security, Dev, Ops, Architecture), bridging technical gaps to ensure successful integrations. - Automation-Driven:
Constantly seeks opportunities to replace manual security administration with automated scripts, policy-as-code, and self-service tools. - Adaptable:
Comfortable with the rapid pace of cloud-native and AI developments, quickly mastering new cloud provider features to enhance platform security.
- Based at ampliFI's Naperville, IL Corporate office,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×