DevSecOps Engineer
Company: Authorium
Location: San Francisco
Posted on: March 29, 2025
Job Description:
As a DevSecOps Engineer at Authorium, you'll play a vital role
in building and maintaining our secure and scalable SaaS platform
hosted on AWS by bridging the gap between development and security,
implementing robust application security measures aligned with NIST
800-53, and engineering secure infrastructure. You'll work closely
with developers, security experts, and other operations teams to
ensure our platform's security, reliability, and
performance.Responsibilities
- Application Security:
- Integrate security vulnerability scanning, SAST, and DAST tools
into the CI/CD pipeline.
- Manage vulnerability and code scanning tools to ensure adequate
coverage and efficient vulnerability remediation.
- Conduct security reviews of code, APIs, and infrastructure
designs.
- Partner with the engineering team to implement security
measures and remediate any discovered vulnerabilities.
- Security Infrastructure Engineering:
- Design, build, and deploy secure infrastructure on AWS
Commercial and AWS GovCloud using Infrastructure as Code (IaC)
technologies like Terraform.
- Oversee management of security controls within the AWS
ecosystem, including IAM roles and policies, VPCs, security groups,
and encryption.
- Automate security tasks and configuration management.
- Monitor and analyze security alerts to identify and respond to
potential threats.
- Collaborate with the DevOps team to integrate security
considerations into CI/CD pipelines.
- General DevSecOps:
- Collaborate with development and security teams to define and
implement DevSecOps principles and best practices.
- Manage and automate security testing procedures within the
CI/CD pipeline.
- Stay informed about new DevSecOps tools and technologies.
- Communicate effectively with technical and non-technical
stakeholders.Minimum Requirements
- Bachelor's degree in Information Security, Computer Science, or
a related field or equivalent work experience.
- Minimum of 2 years of experience in information security or a
related field.
- Working knowledge of FedRAMP/StateRAMP requirements and
compliance frameworks.
- Experience with continuous monitoring tools and
techniques.
- Strong analytical and problem-solving skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team.Nice to
Have:
- Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS,
etc.).
- Knowledge of scripting languages (e.g., Python, Bash) is a
plus.Employees located within 30 miles of our hub cities-San
Francisco, Sacramento, and Washington, D.C.-are required to work
onsite from Tuesday to Thursday. Remote work is available on other
days.Benefits
- Salary Range: $145,000-$155,000
- Flexible PTO
- 100% employer-funded medical, dental and vision insurance
- 100% remote
- $500 home office stipend
- 401K with Profit Sharing Plan
#J-18808-Ljbffr
Keywords: Authorium, San Francisco , DevSecOps Engineer, Engineering , San Francisco, California
Didn't find what you're looking for? Search again!
Loading more jobs...