Nature, beauty, history. For everyone, for ever.
DevSecOps Engineer III
Location
Washington
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
DevSecOps Engineer III
National Trust
• Lead the hardening and modernization of our GitHub ecosystem — consolidating organizations, implementing guardrails and RBAC best practices, and establishing policy-as-code governance at scale. • Assess and evolve the current CI/CD posture — modernizing pipelines, evaluating tooling, and driving toward fully automated secure delivery workflows. • Implement Secure Software Development Framework (SSDF) practices to embed “secure-by-design” principles throughout the SDLC — ensuring supply chain integrity from commit to production. • Act as an SRE for new application infrastructure — building out observability, proactive reliability patterns, performance scaling strategy, and operational readiness. • Design, manage, and automate cloud infrastructure (including container and container orchestration where applicable) through infrastructure-as-code — aligned to NIST CSF 2.0, least-privilege, and zero-trust security models. • Develop and integrate ITSM operational workflows — introducing automation and process maturity where needed to align engineering velocity with auditable controls and resilience. • Promote a culture of security across the organization. • Be able to wear many hats, performing critically required duties as necessary, especially as the team is being developed. • Occasional travel to other offices, customers, and vendor offices
Job Requirements
- 5–8+ years of experience in DevSecOps, SRE, or Cloud Security Engineering roles operating in production-critical environments
- Deep hands-on expertise with leading cloud providers (IAM, networking, security services, automation, zero-trust / least privilege, cost awareness)
- Practical experience operating and securing Kubernetes — including IaC-driven provisioning, policy enforcement, and observability
- Strong command of SCM administration — including RBAC, repo automation, organization policy enforcement, and secure SDLC controls
- Proficiency with Infrastructure as Code (Terraform, CDK, or equivalent) and configuration automation (e.g., Helm, ArgoCD, Crossplane, etc. a plus)
- Familiarity with ITSM-aligned engineering operations — enabling traceability, incident management, and operational readiness at scale
- Excellent communicator and proactive collaborator — able to influence cross-functional teams and advocate for secure-by-design principles.
Benefits
- Medical, Dental, and Vision insurance
- 401(k)
- Disability insurance
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
• Investigate and respond to critical incidents • Develop internal solutions using Go and Python • Participate in metric standardization projects • Collaborate with engineering teams • Prepare applications for high-impact events • Contribute to the team's technical refinement • Define and govern standards through RFCs/IRCs • Lead Post-Incident Reviews (PIRs) and GameDays.
Freelance DevSecOps Engineer
WeMatch.Rezono is a performance marketing agency, partnering directly with Meta, Snapchat, Google, Newsbreak. The company provides its clients (publishers, webmasters, arbitrage teams) with ad accounts on all of the platforms mentioned. Moreover, Rezono helps customers optimize campaigns and leverage all the features of platforms to maximize revenue. The company deals with verticals such as home improvement, leadgen, loans, insurance, e-commerce, and mainstream dating.
Role Description Für ein langfristiges Projekt bei einem führenden Unternehmen aus dem Defense-Umfeld suchen wir zwei erfahrene DevSecOps Engineers (2 FTE) zur Einführung und Automatisierung einer modernen Software Factory. Im Fokus steht der Aufbau einer hochautomatisierten DevSecOps-Plattform inklusive einer sicheren CI/CD-Toolchain auf Basis von GitLab, Kubernetes und VMware-Technologien. Project Goal Im Rahmen des Projekts wird eine moderne Software Factory (SWF) auf Basis von R-CASTLE, VMware Cloud Foundation (VCF) und VMware Kubernetes Services (VKS) aufgebaut und weiterentwickelt. Ziel ist die Konzeption, Implementierung und vollständige Automatisierung des Onboardings neuer Softwareprojekte. Hierfür werden zentrale DevSecOps-Komponenten wie: - GitLab - JFrog Artifactory - Xray - HashiCorp Vault/OpenBao - Enterprise-Identity-Lösungen integriert und automatisiert. Darüber hinaus erfolgt die Vorbereitung zukünftiger Kubernetes-Workload-Tenants innerhalb der Plattform. Tasks - Design, Implementierung und Automatisierung neuer Projekt-Onboardings innerhalb der Software Factory - Aufbau und Weiterentwicklung einer standardisierten DevSecOps-Plattform - Administration und Optimierung von GitLab inklusive CI/CD - Integration und Automatisierung von GitLab, Artifactory, Xray und Vault - Implementierung von Infrastructure as Code mittels Terraform - Automatisierung von Plattform- und Onboarding-Prozessen - Integration von Enterprise-Identity-Lösungen (AD/LDAP) - Integration und Migration bestehender Jenkins-Pipelines nach GitLab - Aufbau und Integration zukünftiger Kubernetes-Workload-Tenants - Erstellung technischer Dokumentationen - Durchführung technischer Workshops mit den Fachbereichen Qualifications - MUST HAVE - GitLab - Tiefgehende Erfahrung mit GitLab - Helm Charts - GitLab Groups, Projects und Repositories - GitLab Runner - GitLab CI/CD - Compliance Pipelines - LDAP Integration - Backup & High Availability - GitLab Migrationen - Kubernetes - Sehr gute Kenntnisse in: - Kubernetes - VMware Cloud Foundation (VCF) - VMware Kubernetes Services (VKS) - VMware Tanzu oder vergleichbaren Kubernetes-Plattformen - Ingress - Network Policies - RBAC - Storage - Observability - GitOps - HashiCorp Vault / OpenBao - LDAP Integration - GitLab JWT - Kubernetes Authentication - Policies - Secret Management - Secret Automation - Secure Token Handling - JFrog Artifactory / Xray - Repository Design - Permission Targets - Storage Management - Security Scanning - Retention Policies - Automatisierung - Infrastructure as Code - Sehr gute Terraform-Kenntnisse - Erfahrung mit Terraform-Automatisierungen - Gute Ansible-Kenntnisse - Identity & Security - Active Directory - LDAP - RBAC - PKI - TLS - Enterprise Identity Integration - CI/CD - Jenkins Integration - Migration bestehender CI/CD-Pipelines nach GitLab - Erfahrung mit großflächigen Projektmigrationen - NICE TO HAVE - Argo CD - Flux - Workload Tenant Onboarding - R-CASTLE - VMware VKS Cluster Bootstrap - GitOps Deployment Patterns Soft Skills - Analytische und strukturierte Arbeitsweise - Fähigkeit, Architekturkonzepte in automatisierte Lösungen umzusetzen - Sehr gute Kommunikationsfähigkeiten im Austausch mit Plattform-, Security-, Netzwerk- und Operations-Teams - Erfahrung in der Durchführung technischer Workshops - Ausgeprägte Dokumentationsfähigkeiten - Qualitätsbewusstsein und lösungsorientierte Arbeitsweise - Erfahrung in regulierten oder sicherheitskritischen Projektumgebungen von Vorteil Language Skills - MUST HAVE - Deutsch – verhandlungssicher - Englisch – fließend in Wort und Schrift (mindestens C1) Requirements - Bereitschaft zur einmaligen Hardware-Abholung beim Endkunden - Teilnahme an ca. 1–2 Workshops vor Ort - Bereitschaft zur Unterzeichnung einer Vertraulichkeitsvereinbarung (NDA) - Staatsangehörigkeit eines vom Endkunden freigegebenen Landes (Staatenliste Ausschluss) Application Process Bitte senden Sie uns bei Interesse: - Aktuellen Lebenslauf (Word) - Frühestmöglichen Starttermin - Verfügbarkeit - Stundensatz - Staatsangehörigkeit - Projektreferenzen im Bereich GitLab, Kubernetes und DevSecOps - Kurzbeschreibung vergleichbarer Projekte Wir freuen uns auf Ihre Bewerbung! i.radchenko@wematch.de
Senior DevOps Engineer
Duetto ResearchDuetto is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other characteristic protected by applicable law. Sound like you? If this role has you excited, we'd love to hear from you — even if you don't tick every box. At Duetto, we hire for potential, perspective, and the drive to make things happen. Apply and let's start a conversation.
Role Description Duetto's platform runs 24/7 for hotels, resorts, and casinos around the world, and that reliability doesn't happen by accident. We're looking for a Senior DevOps Engineer to architect, build, and own the AWS infrastructure that keeps our Revenue & Profit Operating System fast, secure, and always on, while helping shape how our engineering org automates its way out of manual toil. What You'll Be Doing - Architect and implement infrastructure for seamless migrations of critical systems, keeping uptime and reliability front and center. - Design, build, and maintain the tooling and processes that let our SaaS products scale and run themselves on AWS. - Partner closely with developers to strengthen the reliability, performance, security, and scalability of our application architecture. - Build and maintain the critical infrastructure components that keep everything highly available and secure. - Drive alignment across technical and non-technical teams, making sure infrastructure decisions serve the whole business. - Take your turn as last line of defense in our weekly on-call rotation, leading root cause analysis and driving fixes that stick for good. Qualifications - 5+ years in an Ops, DevOps, or SRE role, with real system design and architecture chops. - Comfortable administering cloud infrastructure hands-on (AWS preferred, Azure or GCP also welcome). - Fluent in the AWS ecosystem (IAM, VPC, EC2, ELB, RDS, S3, Lambda, API Gateway, Secrets Manager, KMS, CloudWatch, CloudTrail). - Experience running Terraform/Terragrunt in production and working with Chef or Puppet. - Familiar with GitHub, GitHub Actions, Jenkins, JFrog Artifactory, and GitOps workflows. - Experience using DataDog, Prometheus, or Grafana to monitor system health. - Ability to read Java, Ruby, Bash/Zsh, HCL, Python, and JavaScript well enough to move fast across a codebase. Requirements - Experience with ECS or EKS, exposure to SOC2 or secure-by-default practices. - Familiarity with L7 load balancing. Benefits - Own meaningful infrastructure decisions, not just execute someone else's blueprint. - Work in an AI-forward company across every function, equipped to use AI for incident triage, IaC code generation, and runbook authoring. - Engage at the intersection of serious infrastructure and an industry we genuinely love. - Real collaboration with developers and cross-functional teams to solve problems together. - Celebrate diverse perspectives and have the room to debate ideas openly. The Details - Location: Remote, US (open to candidates anywhere in the US). - Work model: Fully remote. - Weekly on-call rotation as last line of support for 24/7 services.
DevSecOps Engineer
HolaflyOur mission is to enable all travellers to enjoy Internet connectivity wherever they are.
• Design and operate the GCP cloud platform foundations, owning the full lifecycle of infrastructure and security. • Automate everything via Terraform and Ansible, eliminating "snowflake" servers and manual console configurations. • Maintain and scale GKE clusters, managing workloads, network policies, and cluster lifecycles. • Strengthen our security posture by implementing least-privilege IAM, image scanning, and SOPS-based secret management. • Optimise CI/CD pipelines using Cloud Build and GitHub to ensure high-quality, secure code deployments. • Enhance observability and incident response through OpenTelemetry and OpenSearch to ensure 24/7 platform reliability.


