TrueML is a fintech company building software to create positive experiences for consumers seeking financial health.
DevSecOps Engineer
Location
Kansas
Posted
4 days ago
Salary
$122.1K - $160K / month
Seniority
Lead
Job Description
DevSecOps Engineer
TrueML
• Security Automation & CI/CD Integration (Core Focus): Embed security controls and scanners (SAST, SCA, DAST, IaC, Container Security) into CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI, Azure DevOps). • Design and maintain automated security workflows across build, test, and deploy stages. • Implement security gates, policy enforcement, and compliance checks within pipelines. • Cloud Security (AWS Focus): Secure cloud-native architectures across AWS (IAM, VPC, ECS/EKS, Lambda, S3, API Gateway). • Integrate and operationalize CNAPP/CSPM tools (e.g., Wiz, Prisma Cloud). • Enforce least privilege access, secrets management, and runtime protections. • Own Cloud Security: Define and maintain security policies for our AWS environment, specifically focusing on containerized workloads (EKS/ECS) and serverless architectures (Lambda). • Automate Compliance: Move beyond manual checks by building real-time monitoring and automated remediation for AWS resources, ensuring we stay 'audit-ready' for frameworks like PCI and ISO 27001. • Lead Threat Modeling: Perform deep-dive threat modeling exercises on applications and designs, turning theoretical risks into actionable engineering plans. • Innovate with AI: Develop security standards for Generative AI leveraging AI-powered tools to explore our attack surface. • Guard the Infrastructure: Secure our Infrastructure as Code (IaC) templates (Terraform/CloudFormation) and manage cloud primitives like IAM, KMS, and WAF to ensure a 'least privilege' environment.
Job Requirements
- An Experienced Defender: You bring 7-10 years in software engineering, DevOps, or cloud engineering. 3+ years in a DevSecOps focused role and a deep mastery of cloud security, vulnerability analysis, and incident response.
- A Cloud Specialist: You have demonstrable expertise in the AWS ecosystem and are highly proficient in securing Infrastructure as Code (Terraform) and containerized environments.
- Certified and Credentialed: You hold top-tier industry certifications (such as CISSP, SANS GIAC, or CASP) and have a firm grasp of compliance frameworks like PCI and ISO 27001.
- Technically Versatile: You are familiar with OWASP, proficient with modern security tooling, and have the ability to secure complex API integrations and data protection layers.
- AI-Aware: You understand the evolving landscape of AI regulations and have the technical curiosity to investigate how threat actors use AI to bypass traditional controls.
- A Strategic Partner: You are a natural collaborator who can translate complex InfoSec projects into simple, maintainable tasks for Engineering teams.
- An Elite Communicator: You can propose strategic methodologies to tackle legacy security debt and convince stakeholders of the business value of security-first design
- Core Skills & Capabilities: Deep expertise in CI/CD pipelines (GitHub Actions, Jenkins)
- Strong hands-on experience with AWS cloud security
- Proficiency in application security tooling and integration
- Experience with container security (Docker, Kubernetes)
- Strong scripting/programming skills (Python, JavaScript)
- Understanding of modern DevSecOps and shift-left security practices
- Excellent collaboration skills across engineering, security, and DevOps teams
Benefits
- Flexible vacation
- Medical/dental/vision insurance
- Traditional/Roth retirement savings options
- Company-paid disability and life insurance
- Flexible Spending Account & Limited FSA
- Family-friendly parental leave, volunteer and voting time off
- On-demand wellness platform access for you and 5 friends and family
- PerkSpot discount program for 900+ merchants nationwide
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
Site Reliability Engineer
VyncaCommitted to empowering individuals, their loved ones, and their care teams with solutions delivered in their homes.
• Design, provision, and manage AWS infrastructure using Terraform • Operate, maintain, and scale production workloads running on Kubernetes • Package, deploy, and manage applications using Helm and infrastructure automation tools • Build, operate, and improve distributed and event-driven systems • Define, monitor, and maintain Service Level Indicators (SLIs), Service Level Objectives (SLOs), and error budgets • Develop automation for deployment, scaling, monitoring, incident response, and operational workflows • Own platform observability by implementing and maintaining metrics, logging, tracing, monitoring, and alerting solutions • Lead incident response efforts, facilitate blameless postmortems, and drive long-term corrective actions • Partner with Product and Engineering teams on capacity planning, performance optimization, and resilient system design • Implement and maintain security best practices to support HIPAA, SOC 2, and other compliance requirements • Participate in an on-call rotation and provide operational support for production systems
Azure DevOps Engineer – Hub-Remote: DC or Philly Metro
Element 84Accelerating and scaling impactful projects with great software and design. Geospatial, cloud, and petabyte-scale data.
• Collaborating with development teams for the design and implementation of robust, scalable, and secure cloud-native solutions on Azure and AWS. • Developing and maintaining infrastructure-as-code to manage and provision infrastructure across numerous Azure and AWS accounts, ensuring consistency and efficiency. • Maintaining and optimizing CI/CD automation pipelines to facilitate rapid and reliable software deployments. • Collaborating with security experts to translate organizational security requirements into secure and compliant cloud implementations. • Participate in all aspects of the software development lifecycle from user story generation, through design, development, automated testing and operational support • Improve quality by actively participating in code-reviews and adhering to team quality standards. • Own execution of small-medium sized features with higher-level technical support • You describe the details of your work fluidly and accurately to technical peers
• Scaling and maintaining our infrastructure and services using AI (Claude Code) as a first-class collaborator in your daily development workflow. • Being opinionated on technical direction and strategy (and documenting those opinions for others to be able to follow). • Leading and mentoring other engineers on the team • Owning and resolving the most complex infrastructure failures — Kubernetes scheduling edge cases, networking degradation, cross-service cascading failures, and AWS platform issues that other engineers escalate • Participating in a shared on-call rotation (roughly one week every six to eight weeks on call) • Estimating schedules, breaking tasks down to reasonable 1-3 day tasks. • Driving cloud cost efficiency by identifying over-provisioned resources, rightsizing EC2 and container workloads, and building tooling to surface cost anomalies before they compound
Site Reliability Engineer I
MedalliaAt Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at ApplicantAccessibility@medallia.com . For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.
Role Description The Site Reliability Engineering organization at Medallia brings together the infrastructure and applications that power a highly reliable global SaaS platform. As an SRE I, you will work alongside experienced engineers to help maintain reliable, scalable, and efficient production systems. This role is designed for engineers early in their careers who are passionate about cloud infrastructure, automation, Kubernetes, and modern operational practices. - Gain hands-on experience supporting cloud-native applications. - Troubleshoot production environments. - Build automation to improve operational efficiency. - Participate in a rotating on-call schedule after onboarding and training. Responsibilities - Support production applications and infrastructure running in cloud and Kubernetes environments. - Monitor systems, troubleshoot alerts, and assist with operational incidents. - Collaborate with engineering teams to improve reliability and operational processes. - Write scripts and automation to reduce repetitive operational tasks. - Leverage modern automation and AI-assisted tools to improve operational efficiency and reduce repetitive work. - Demonstrate an engineering leverage mindset by identifying opportunities to automate repetitive work and improve team productivity. - Assist with CI/CD and deployment workflows. - Help maintain monitoring, alerting, and observability systems. - Participate in root cause analysis and continuous improvement efforts. - Learn and apply SRE principles and operational best practices. Qualifications - Bachelor’s degree in Computer Science, Engineering, or a related technical field, or equivalent practical experience. - 1 year of experience in software engineering, systems engineering, cloud operations, DevOps, or related technical roles. - Demonstrated experience configuring, navigating, or managing Linux systems and managing basic networking protocols (such as TCP/IP, DNS, or HTTP). - Ability to write, debug or modify scripts using Python or Bash. - Experience using Git and basic software development workflows. - Experience troubleshooting, diagnosing and resolving technical errors or system failures in a development or production environment. - Professional working proficiency in written and spoken English. Preferred Qualifications - Exposure to Kubernetes, Docker, or containerized environments. - Familiarity with cloud platforms such as AWS, OCI, or GCP. - Exposure to CI/CD concepts and automation tooling. - Familiarity with monitoring and observability concepts. - Internship or academic project experience related to cloud infrastructure or automation. - Understanding of infrastructure-as-code concepts such as Terraform or Ansible. - Exposure to AI-assisted engineering tools, automation platforms, or modern developer productivity solutions. - Strong willingness to learn modern cloud and infrastructure technologies. - Demonstrated curiosity and enthusiasm for automation, modern engineering practices, and emerging technologies. - Troubleshooting and analytical thinking mindset. - Strong communication and collaboration skills.



