Istari Digital Logo

Istari Digital

DevSecOps Engineer

Reposted 15 Hours Ago
Remote
Hiring Remotely in US
135K-220K Annually
Senior level
Remote
Hiring Remotely in US
135K-220K Annually
Senior level
Design, harden, and maintain secure, scalable AWS and Kubernetes infrastructure using Terraform. Harden hosts, manage Linux/Windows VMs and Active Directory, secure CI/CD, support vulnerability management, compliance/audits, incident response, runbooks, and operational troubleshooting for regulated and production environments.
The summary above was generated by AI

We are seeking a DevSecOps Engineer to join our Engineering team. This role is critical to securing, hardening, and scaling the infrastructure that powers our platform across cloud-hosted production environments.

This engineer will work closely with platform, infrastructure, and security stakeholders to improve the security and operational maturity of our AWS and Kubernetes environments, support compliance and audit readiness, and help ensure our systems are reliable, secure, and maintainable as we grow. This role will also support environments serving regulated and security-sensitive customer needs, including an environment we host for a Government organization.

The ideal candidate combines strong hands-on infrastructure expertise with sound security judgment and a practical, execution-focused mindset. They should be comfortable working across cloud infrastructure, Kubernetes, operating systems, compliance controls, and production operations.

Core Responsibilities

    Responsibilities include collaborating with the platform and engineering teams to secure and improve production infrastructure, harden cloud and host configurations, and build repeatable operational practices across environments. Key responsibilities include:

  • Design, implement, and maintain secure, scalable infrastructure in AWS

  • Manage, secure, and improve Kubernetes-based environments, including production workloads

  • Build and maintain infrastructure as code using Terraform

  • Harden production systems across cloud, compute, container, identity, and network layers

  • Develop and maintain secure baseline configurations for infrastructure and platform services

  • Support vulnerability management, patching, remediation, and configuration compliance efforts across environments

  • Configure, administer, and patch both Linux and Windows VMs

  • Support identity and access management practices, including least privilege, role design, and privileged access controls

  • Contribute to administration and integration of Active Directory domains where needed

  • Partner with engineering teams to improve security within CI/CD pipelines, deployment workflows, and operational processes

  • Support compliance initiatives, audits, evidence collection, and technical control validation

  • Develop and maintain documentation, operational runbooks, technical standards, and playbooks

  • Monitor, troubleshoot, and resolve complex infrastructure and security issues with clear and timely communication

  • Participate in incident response and post-incident analysis when infrastructure or platform issues arise

  • Stay current on cloud, infrastructure, and security best practices that can improve platform resilience and delivery

Required Qualifications

  • Minimum of 5 years of experience in DevOps, DevSecOps, Infrastructure Engineering, Platform Engineering, or Security Engineering

  • Strong hands-on experience with AWS in production environments

  • Proven experience with Kubernetes, preferably in production

  • Strong experience with Terraform and infrastructure-as-code practices

  • Experience hardening production environments and implementing secure configuration standards

  • Experience supporting compliance frameworks, audit preparation, evidence gathering, and control validation

  • Experience with vulnerability remediation, system patching, and operational security practices

  • Experience configuring and maintaining both Linux and Windows virtual machines

  • Strong understanding of IAM, secrets management, network security, logging, monitoring, and operational controls

  • Proven experience improving or securing CI/CD pipelines and deployment workflows

  • Excellent troubleshooting and problem-solving skills in complex production environments

  • Strong communication skills with the ability to explain technical concepts to both technical and non-technical stakeholders

  • Must live/work in the U.S.

Preferred Qualifications

  • Experience supporting environments with regulated, compliance-driven, or security-sensitive requirements

  • Familiarity with compliance or security frameworks such as SOC 2, NIST, ISO 27001, CMMC, or similar

  • Experience with EKS or other managed Kubernetes platforms

  • Experience configuring or supporting Active Directory Domain Services, Group Policy, or hybrid identity environments

  • Experience with automation and configuration management tools such as Ansible, PowerShell, or similar

  • Experience with PostgreSQL, cloud storage platforms, and production networking patterns

  • Scripting experience in Python, Bash, or PowerShell

  • Experience with security tooling related to container security, vulnerability management, or policy enforcement

  • Experience supporting customer-facing or mission-critical production infrastructure

  • Security+ Certification

  • Top Secret Security Clearance

About Istari Digital

Istari is a digital engineering software company building open, scalable infrastructure for engineering data. Our platform lets customers simply and securely integrate engineering models across disciplines, organizations, and security levels — whether they're designing prototypes, performing virtual testing, or training AI and autonomy for complex systems.

Focus is rewarded.  Finish is remembered.

Facts are friendly.  Even when they are not fun.

Fellowship is fundamental.  Make others successful.

Similar Jobs

5 Days Ago
Remote or Hybrid
USA
Senior level
Senior level
Software
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Top Skills: Api SecurityAquaAzureAzure DevopsAzure Key VaultAzure Security CenterBlack DuckBurp SuiteCheckmarxCi/CdDastGithub Advanced SecurityHashicorp VaultMendMicroservicesOwasp ZapPrisma CloudSastScaSecrets ManagementSemgrepSnykSonarqubeTerraformVeracodeWiz
14 Days Ago
Remote or Hybrid
United States
121K-204K Annually
Senior level
121K-204K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead DevSecOps engineer on the Infrastructure and Platform Services team responsible for implementing and operating global SaaS infrastructure security. Duties include file integrity monitoring, automating audit evidence collection, hardening base images, securing containerized applications, release automation, incident response via on-call rotation, and collaborating with engineering and cybersecurity to meet compliance (FedRAMP, ISO, SOC) and remediation SLAs.
Top Skills: AWSAzureChefContainerizationFile Integrity MonitoringIdsIpsJenkinsPuppetPythonRubySIEMSirpTerraformWaf
2 Days Ago
Remote
USA
Mid level
Mid level
Information Technology • Professional Services
Support integration of a hybrid mainframe-to-cloud prototype by implementing secure network connectivity, Kubernetes container platforms, CI/CD and IaC automation, system integrations (APIs, messaging), DevSecOps security controls, and environment operations. Assist troubleshooting, testing, documentation, and knowledge transfer while aligning deployments with DoD security requirements.
Top Skills: AksAWSAzureAzure Resource ManagerBashCi/CdCloudFormationDockerEksIbm MqImage ScanningInfrastructure As CodeKubernetesLinuxOpenshiftPowershellPrivate CloudPythonSecrets ManagementStigTerraformVnetVpcVpn

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account