Job Closed
This listing is no longer active.
Expert Software Engineering On Demand
Staff DecSecOps Engineer
Location
California + 4 moreAll locations: California | New Jersey | Maryland | Missouri | South Carolina
Posted
110 days ago
Salary
$166K - $200K / year
Seniority
Lead
Job Description
Staff DecSecOps Engineer
Alto
• Define and lead the DevSecOps vision and roadmap across infrastructure, application, and CI/CD ecosystems. • Architect secure-by-design cloud-native systems across AWS/GCP environments. • Establish security patterns, guardrails, and reference architectures for engineering teams. • Evaluate and implement modern security tooling across SAST, DAST, SCA, container scanning, IaC scanning, and runtime protection. • Embed security controls into CI/CD pipelines and developer workflows. • Drive infrastructure-as-code security best practices (Terraform, CloudFormation, etc.). • Automate security testing and compliance checks to reduce manual overhead. • Implement policy-as-code and automated governance controls. • Lead identity and access management (IAM) strategy and least-privilege enforcement. • Strengthen container and Kubernetes security posture. • Oversee secrets management, encryption standards, and key management processes. • Partner with infrastructure teams on network segmentation, zero-trust architectures, and environment isolation. • Support and mature Alto’s security program in alignment with HIPAA, SOC 2, HITRUST, and other healthcare regulatory frameworks. • Conduct threat modeling, security design reviews, and architecture risk assessments. • Partner with Security and Compliance teams on audits and remediation efforts. • Provide senior-level leadership during security incidents, including root cause analysis and long-term mitigation planning. • Mentor senior and mid-level engineers on secure coding and DevSecOps practices. • Influence engineering leadership and executive stakeholders on security strategy and risk prioritization. • Drive cross-functional alignment across Engineering, Product, IT, and Compliance. • Raise the overall security maturity of the organization through scalable frameworks and standards.
Job Requirements
- 14+ years of experience in software engineering, infrastructure engineering, or security engineering, with significant experience in DevSecOps environments
- Deep expertise in cloud security architecture (AWS and/or GCP)
- Strong experience securing containerized and Kubernetes-based environments
- Hands-on experience with CI/CD systems (GitHub Actions, GitLab CI, CircleCI, Jenkins, etc.)
- Expertise in infrastructure-as-code (Terraform, CloudFormation) and securing IaC pipelines
- Strong knowledge of application security principles, OWASP Top 10, and secure coding practices
- Experience implementing and scaling SAST, DAST, SCA, container scanning, and secrets detection tools
- Deep understanding of IAM, RBAC, zero-trust models, and encryption best practices
- Experience operating in regulated environments (HIPAA, SOC 2, HITRUST, PCI, etc.)
- Strong scripting or programming skills (Python, Go, Ruby, or similar)
- Demonstrated ability to influence architectural decisions at a Staff or Principal level
- Experience in healthcare, pharmacy, fintech, or other highly regulated industries (preferred)
- Experience building DevSecOps programs from early-stage to scale (preferred)
- Background in site reliability engineering (SRE) or platform engineering (preferred)
- Security certifications such as CISSP, CISM, CCSP, or cloud security certifications (AWS/GCP) (preferred)
- Experience implementing threat modeling frameworks (STRIDE, PASTA, etc.) (preferred)
- Experience with observability platforms and integrating security telemetry into monitoring systems (preferred)
Benefits
- dental, vision, and multiple group medical plans to choose from
- a 401(k) retirement savings plan
- group life insurance
- accidental death and dismemberment (AD&D) insurance
- flexible spending account (FSA) and health savings account (HSA)
- commuter benefits
- employer-paid short-term (STD) and long-term disability (LTD) insurance
- additional supplemental insurance plans (spouse life insurance, legal insurance, an employee assistance program, home health testing kits, and a fertility medication discount program)
- flexible vacation time
- accrued paid sick time
- 10 paid holidays
- 2 floating holidays for full time non-exempt employees
- eight weeks of paid parental leave for eligible employees
- additional paid weeks for the birthing parent
- 4 weeks paid caregiver leave
- a Lifestyle Spending Account allowance each month
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Senior ISSO/Security Operations Lead
Simple Technology Solutions8(a) HUBZone IT consultancy w/ advanced partnerships w/ Amazon Web Services, Microsoft Azure & Google Cloud Platform
• Serve as the technical authority for CMASS IV security operations and authorization support • Lead ongoing authorization (OA/cATO), continuous monitoring execution, RMF artifact quality, and compliance alignment with DHS and USCIS security requirements • Designated Key Personnel due to its critical role in operational security execution and audit readiness • Lead continuous monitoring and OA/cATO execution across USCIS systems • Oversee development and maintenance of SSPs, SAPs, SARs, POA&Ms, and supporting evidence • Ensure control validation and security posture consistency across supported directorates • Coordinate with system owners, Authorizing Officials (AOs), ISSOs, and engineering teams • Ensure alignment with DHS 4300A, ISPP, and USCIS security policies • Support audits, assessments, and leadership briefings related to security posture
SecOps Engineer – North Central region
GuidePoint SecurityFounded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security
• Ability to autonomously prioritize and successfully deliver across a portfolio of projects. • Learn and keep up with current cyber threats, attack methodology, active campaigns, and detection techniques using a wide variety of capabilities and sources (GOTS, COTS, and Open Source). • Understand and utilize cyber threat intelligence sources. • Familiarity with key security events on common IT platforms. • Experience authoring security runbooks, policy, and best practice documentation. • Preferred experience in the areas of SecOps, Security Analytics, SIEM/SOAR, etc. • Proficiency in developing log ingestion and aggregation strategies. • Expertise developing security-focused content for one or more SIEM platforms (Splunk, CrowdStrike NG-SIEM, Elastic Security or Palo Alto XSIAM), including creation of complex threat detection logic and operational dashboards. • Understand and articulate complex technical information to both technical and non-technical audiences. • Demonstrated experience in the identification and assessment of the relevance and effectiveness of signatures and indicators of compromise based on intelligence. • Experience developing and providing regular and ad hoc briefs, documents, diagrams and other products.
SecOps Observability Engineer
GuidePoint SecurityFounded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security
• Provide trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. • Evaluate security posture and ecosystems. • Optimize resources and integrate best-fit solutions that mitigate risk.
Cyber Security Operations Center (CSOC) Analyst – Tier 3
athenahealthWe provide network-enabled services, mobile apps, and data-driven insights to hospitals and medical organizations.
• Understand that as the Tier 3 (highest level) engineer, you’re expected to handle potential incidents and act as the as a subject matter expert for all security-related tickets that come into the team's various queues (including triage, containment, and remediation when necessary). • Receive incident escalations from Tier 1 and 2 analysts, assisting with real-time advanced analysis, response, and reporting. • Mentor and assist in training Tier 1 and 2 analysts to aid in their skills development and analytical capabilities. • Proactively hunt for threats and enacting identification, containment, and eradication measures while supporting recovery efforts. • Serve as a point person for coordination with appropriate parties during a security incident – client, management, legal, security, operations, etc. • Create thorough reports and documentation of all incidents and procedures, presenting findings to team and leadership on a routine basis. • Incident Response: remote remediation when possible and working with onsite teams when necessary. • Detailed documentation of events and remediation steps taken. • Root Cause Analysis: initiation and follow-through to ensure quality forensic materials are captured, writing reports with details and timelines of events with recommendations to avoid future occurrences. • Assist in the general maintenance and improvement of procedures, processes and playbooks. • Conduct research regarding the latest methods, tools, and trends in digital forensics analysis. • Conduct analysis using logs, previous alerts, etc. to identify trends to identify and prevent potential incidents. • Follow standard operating procedures (SOPs) to ensure tickets are triaged appropriately and in a timely manner, according to SLAs. • Excel at documentation and detailed notetaking, including SOP writing, incident reporting, e-mail and instant messaging etiquette, and most importantly, documenting incident actions in tickets. • This role is responsible for completing incident reports and forensic reports, when appropriate, so competent writing skills are necessary. • Ability to know when to appropriately escalate a potential issue to peers and/or leadership. • Desire to learn new concepts and technologies to grow and take on more responsibility over time. • Ability to communicate risk, prioritize incident response actions, and keep a cool head under pressure. • Advanced experience with security tools like Splunk, CrowdStrike EDR, Carbon Black EDR, Proofpoint tools, Microsoft Defender components, Cyberhaven DLP, Axiom Cyber and open-source forensic tools, Cylance Protect, Office 365 tools, PowerShell, and various network tools, etc. • Understanding the various stages of incident response, the importance and critical factors of an investigation, and how to contain as soon as possible. • Have experience with the incident response lifecycle, the Lockheed Martin Cyber Kill Chain, the MITRE framework, and the forensic workflows as outlined by NIST. • Work with development teams to ensure they're using best practices and company processes in their daily activities. • Drive self-organization; help determine how the team functions in collaboration with your peers. • Build strong relationships with cross-functional team members between the three tiers of the CSOC. • Participate in off-hours on-call incident handler rotation, which is a requirement for this role, as incidents may be escalated outside of normal business hours by our 24/7/365 Tier 2 team. Tier 3 teammates rotate on-call responsibilities which requires each teammate to be formally on-call roughly one week a month.



