Cloud DevSecOps Engineer
ECS is seeking a Cloud DevSecOps Engineer to work remotely.
Job Description:
We are seeking a highly skilled Senior DevSecOps Engineer with extensive experience in cloud-native infrastructure engineering, Kubernetes container orchestration, and enterprise Identity and Access Management (IAM). Tools necessary for excelling in this role include Kubernetes, Docker, Helm, Keycloak Identity Broker, Okta SSO/OIDC, Terraform/IaC, CI/CD pipelines (GitLab CI, GitHub Actions, or Jenkins), and security scanning tooling (Trivy). This role will serve as the infrastructure and security authority within a lean, agile modernization team rebuilding an enterprise Microsoft Power Apps system into a cloud-native platform. You will play a critical role in provisioning and securing Kubernetes cluster environments, engineering automated build and deployment pipelines, deploying and managing high-availability Keycloak identity broker services federated to enterprise Okta, and safeguarding all infrastructure, database, and storage assets across non-production and production environments.
About the Job
- Architect, provision, configure, and maintain production-grade Kubernetes cluster environments hosting containerized front-end, backend, and identity services.
- Deploy, configure, and administer a highly available Keycloak Identity Broker instance running in Kubernetes, federating authentication to enterprise Okta via SAML 2.0 and OIDC.
- Configure identity brokering rules, realm roles, client scopes, and token exchange policies within Keycloak to power secure authentication for React and Spring Boot services.
- Design, build, and maintain end-to-end CI/CD pipelines for automated image builds, vulnerability scanning, automated testing gates, and zero-downtime rolling deployments via Helm.
- Implement robust platform security controls, including Kubernetes Ingress controllers (NGINX/Traefik), TLS certificate automation (cert-manager), network policies, and container image scanning (Trivy).
- Automate secrets management and configuration injection across environments using tools such as HashiCorp Vault, AWS Secrets Manager, or Kubernetes External Secrets Operator.
- Provision, monitor, and maintain supporting backing infrastructure including managed PostgreSQL instances and secure Amazon S3 storage buckets.
- Establish centralized logging, monitoring, and alerting frameworks (Prometheus, Grafana, Loki or EFK stack) to ensure high system observability and reliability.
Salary Range: $130,000-$175,000
General Description of Benefits
Skills
- Agile
- Authentication
- Automation
- AWS
- CI/CD
- Cloud
- Cloud Native
- DevSecOps
- Docker
- ECS
- GitHub
- GitHub Actions
- GitLab
- Grafana
- Helm
- IAM
- Infrastructure as Code
- Jenkins
- Keycloak
- Kubernetes
- Loki
- Nginx
- Observability
- Okta
- OpenID
- PostgreSQL
- Power Apps
- Prometheus
- React
- S3
- SAML
- Secrets Management
- Spring
- SSO
- Terraform
- Test Automation
- TLS
- Vault
- Vulnerability Scanning