Staff Security Engineer, DevSecOps
Summary
A hands-on Staff Security Engineer builds and automates security controls, hardens cloud-native systems, and partners with engineering teams to reduce risk while enabling fast, safe software delivery on AWS.
What You’ll Do:
Responsibilities:
- Drive secure-by-default patterns across the organization through reusable libraries, templates, guardrails, and paved-road workflows, improving security posture across cloud infrastructure, the application stack, and developer workflows.
- Lead practical threat modeling for new product capabilities, platform changes, and high-risk workflows, translating findings into clear engineering actions.
- Help define the security tooling strategy across application security, cloud security, detection, and developer workflows, evaluating and integrating tools that meaningfully reduce risk without slowing delivery.
- Improve software supply chain security across build systems, dependencies, container images, secrets, and deployment processes.
- Design, build, and operate security automation and production-quality tooling for identity and access management, secrets management, vulnerability management, and policy enforcement.
- Harden AWS environments, containerized workloads, and CI/CD pipelines, using AI-assisted tooling to accelerate work where it genuinely helps.
- Build and maintain detection and alerting for meaningful security events across endpoints, cloud infrastructure, application logs, audit trails, and identity systems.
- Partner with engineering teams to review architecture, application design, infrastructure changes, and operational patterns with a focus on reducing exploitable risk.
- Support compliance and audit needs through engineering-driven controls, evidence automation, logging, and repeatable operational practices.
- Own hands-on incident response, including triage, containment, root cause analysis, remediation, and post-incident follow-through.
- Participate in on-call rotations for high-severity security and platform incidents and build and test response procedures for scenarios such as credential compromise, privilege escalation, and exposed secrets.
What You’ll Bring:
- Bachelor's degree in Computer Science, Engineering, or equivalent practical experience.
- 8+ years of experience across software engineering, infrastructure engineering, platform engineering, SRE, DevOps, security engineering, or related roles in production SaaS environments.
- 3+ years of hands-on experience in security engineering, platform security, cloud security, or related security-focused roles.
- Strong hands-on experience securing cloud-native environments on AWS.
- Proven ability to write code for automation, integrations, internal tooling, and operational workflows using languages such as Python, Go, JavaScript, or Bash.
- Experience operating in a DevSecOps or platform-adjacent model where security is embedded into delivery pipelines and engineering workflows.
- Strong experience with identity and access management, secrets handling, key management, logging, auditability, and least-privilege design.
- Experience building or operating security controls for CI/CD, infrastructure as code, containerized systems, and developer platforms.
- Practical experience with security monitoring, detection engineering, alert tuning, and incident response.
- Ability to assess real-world risk and prioritize pragmatic fixes over theoretical perfection.
- Experience partnering with engineering teams to improve security architecture, code patterns, infrastructure posture, and operational readiness.
- Demonstrated ability to use AI-assisted development tools to accelerate investigations, automate repetitive work, and improve engineering effectiveness while maintaining strong judgment.
- Comfortable working in a fast-paced startup environment with a small, high-impact team.
- Excellent communication and collaboration skills, able to explain trade-offs clearly and drive consensus without becoming a bottleneck.