Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
DevSecOps Engineer image - Rise Careers
Job details

DevSecOps Engineer

As a DevSecOps Engineer at Authorium, you'll play a vital role in building and maintaining our secure and scalable SaaS platform hosted on AWS by bridging the gap between development and security, implementing robust application security measures aligned with NIST 800-53, and engineering secure infrastructure. You'll work closely with developers, security experts, and other operations teams to ensure our platform's security, reliability, and performance.

  • Application Security:
    • Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
    • Manage vulnerability and code scanning tools to ensure adequate coverage and efficient vulnerability remediation.
    • Conduct security reviews of code, APIs, and infrastructure designs.
    • Partner with the engineering team to implement security measures and remediate any discovered vulnerabilities.
  • Security Infrastructure Engineering:
    • Design, build, and deploy secure infrastructure on AWS Commercial and AWS GovCloud using Infrastructure as Code (IaC) technologies like Terraform.
    • Oversee management of security controls within the AWS ecosystem, including IAM roles and policies, VPCs, security groups, and encryption.
    • Automate security tasks and configuration management.
    • Monitor and analyze security alerts to identify and respond to potential threats.
    • Collaborate with the DevOps team to integrate security considerations into CI/CD pipelines.
      • Defence in Depth
      • High-Availability/Disaster Recovery/Business Continuity
      • Drift Detection/Remediation
      • E2EE (end to end encryption)
      • Role-based access controls (RBAC)
      • Incident Response
      • Least Privilege
    • Familiarity with the following technologies: 
      • Linux
      • Kubernetes
      • Helm
      • CircleCI
      • Git
      • GitHub Actions
      • AWS tools and services: 
        • AWS Security Hub
        • Amazon GuardDuty
        • Amazon Inspector
        • Amazon CloudWatch
        • AWS CloudTrail
        • AWS WAF & Shield
        • AWS Key Management Service (KMS)
        • AWS Systems Manager Parameter Store
        • AWS Secrets Manager
        • AWS Lambda
        • AWS IAM
        • Amazon EC2
        • Amazon ECR
        • Amazon ECS
        • Amazon EKS
        • Amazon EFS
        • Amazon S3
        • Amazon RDS
  • General DevSecOps:
    • Collaborate with development and security teams to define and implement DevSecOps principles and best practices.
    • Manage and automate security testing procedures within the CI/CD pipeline.
    • Stay informed about new DevSecOps tools and technologies.
    • Communicate effectively with technical and non-technical stakeholders.
  • Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
  • Minimum of 2 years of experience in information security or a related field.
  • Working knowledge of FedRAMP/StateRAMP requirements and compliance frameworks.
  • Experience with continuous monitoring tools and techniques.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.

Nice to Have:

  • Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS, etc.).
  • Knowledge of scripting languages (e.g., Python, Bash) is a plus.
  • Salary Range: $145,000-$155,000
  • Flexible PTO
  • 100% employer-funded medical, dental and vision insurance
  • 100% remote
  • $500 home office stipend
  • 401K with Profit Sharing Plan

Average salary estimate

$150000 / YEARLY (est.)
min
max
$145000K
$155000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About DevSecOps Engineer, Authorium

As a DevSecOps Engineer at Authorium, you're stepping into an exciting role that seamlessly blends development and security with a focus on our secure and scalable SaaS platform hosted on AWS. Your expertise will be crucial in implementing robust security measures that align with NIST 800-53 while ensuring our infrastructure remains secure and efficient. You'll team up with talented developers, security professionals, and operations teams, where your mission will be to integrate security throughout our CI/CD pipeline. This involves managing vulnerability scanning tools, conducting code reviews, and designing secure infrastructure using Infrastructure as Code (IaC) technologies like Terraform. You’ll also monitor security alerts and automate security tasks to swiftly address potential threats. In addition to managing IAM roles and policies in AWS, you will play a key role in fostering a culture of security awareness across the team. With responsibilities that also include incident response and collaboration on security best practices, you'll be pivotal in making sure Authorium's platform is not just functional but also exceptionally secure. Enjoy the benefits of remote work with flexible PTO, competitive pay between $145,000-$155,000, and perks like a $500 home office stipend and a 401K with Profit Sharing Plan. If you're ready to elevate your career in an engaging and supportive environment, Authorium is the perfect place for you!

Frequently Asked Questions (FAQs) for DevSecOps Engineer Role at Authorium
What are the responsibilities of a DevSecOps Engineer at Authorium?

At Authorium, a DevSecOps Engineer is responsible for integrating security measures within the CI/CD pipeline, managing vulnerability scanning tools, conducting security reviews of code, and engineering secure infrastructure on AWS using technologies like Terraform. The role emphasizes close collaboration with development and security teams to ensure application security while responding to potential threats proactively.

Join Rise to see the full answer
What qualifications do you need to apply for the DevSecOps Engineer position at Authorium?

To apply for the DevSecOps Engineer position at Authorium, you should have a Bachelor’s degree in Information Security, Computer Science, or a related field, or equivalent work experience. Additionally, a minimum of two years in information security and familiarity with compliance frameworks like FedRAMP/StateRAMP is essential. Strong communication and analytical skills are also crucial for this role.

Join Rise to see the full answer
Can you describe the tools a DevSecOps Engineer at Authorium will use?

A DevSecOps Engineer at Authorium will work extensively with a range of tools including AWS Security Hub, Amazon GuardDuty, Terraform for infrastructure as code, and CI/CD tools like CircleCI and GitHub Actions. Familiarity with scripting languages such as Python or Bash and knowledge of security controls within the AWS ecosystem are also highly beneficial.

Join Rise to see the full answer
What is the work environment like for a DevSecOps Engineer at Authorium?

The work environment for a DevSecOps Engineer at Authorium is fully remote, providing flexibility and work-life balance. The team is collaborative and supportive, focusing on integrating security best practices and continuous improvement in a dynamic and evolving tech landscape.

Join Rise to see the full answer
What benefits does Authorium offer to its DevSecOps Engineers?

Authorium offers an appealing benefits package for its DevSecOps Engineers, including a competitive salary range of $145,000-$155,000, 100% employer-funded medical, dental, and vision insurance, flexible PTO, a $500 home office stipend for remote work, and a 401K with a Profit Sharing Plan to help secure your financial future.

Join Rise to see the full answer
Common Interview Questions for DevSecOps Engineer
How do you integrate security into the CI/CD pipeline?

When integrating security into the CI/CD pipeline, I focus on automating security testing using tools like SAST and DAST. I ensure that vulnerabilities are identified early by incorporating scanning tools within the process. Additionally, I promote communication between development and security teams to instill a security-first mindset throughout the software lifecycle.

Join Rise to see the full answer
Can you explain the concept of Infrastructure as Code (IaC)?

Infrastructure as Code (IaC) is an approach where infrastructure is provisioned and managed using code rather than manual processes. This allows for automation, version control, and consistency across deployments. In my experience with IaC, I've successfully utilized Terraform on AWS, allowing rapid infrastructure delivery while maintaining security best practices.

Join Rise to see the full answer
What strategies do you use for vulnerability management?

For effective vulnerability management, I adopt a proactive approach that includes continuous scanning and assessment of systems, prioritizing vulnerabilities based on risk, and collaborating with development teams to remediate issues swiftly. Regularly reviewing findings and implementing automated fixes is key to maintaining a secure environment.

Join Rise to see the full answer
Explain the principle of least privilege in security.

The principle of least privilege entails granting users only the permissions they need to perform their job functions. This minimizes the potential attack surface and limits access to sensitive information. In practice, I assess roles and responsibilities regularly to ensure compliance with this principle within cloud environments, especially when configuring IAM roles.

Join Rise to see the full answer
How do you respond to security incidents?

Responding to security incidents involves having a well-defined incident response plan in place. Initially, I assess the situation to determine the scope and impact, then engage the necessary stakeholders for assessment and resolution. Post-incident, I analyze the situation to improve security measures, ensuring that similar incidents can be prevented in the future.

Join Rise to see the full answer
What experience do you have with AWS security tools?

My experience with AWS security tools includes using AWS Security Hub to centralize security management, Amazon GuardDuty for threat detection, and AWS WAF to protect against common web exploits. I utilize these tools to monitor security metrics and maintain compliance with industry standards.

Join Rise to see the full answer
How do you stay current with DevSecOps trends and tools?

To stay current in the DevSecOps field, I engage with online training, attend conferences, and participate in community forums. I regularly review industry blogs and publications that focus on emerging trends and tools to ensure that our practices remain cutting-edge and effective.

Join Rise to see the full answer
Describe your experience collaborating with development and security teams.

Collaboration between development and security teams has been a fundamental part of my experience. I foster open communication channels to align security practices early in the development process. Conducting training sessions and security workshops has proven effective in embedding a security-first culture across teams.

Join Rise to see the full answer
What do you understand by Defense in Depth?

Defense in Depth is a layered security strategy that involves implementing multiple security controls throughout the IT environment. This approach ensures that if one security control fails, additional layers provide backup defenses. I apply this principle by leveraging various security technologies and procedures, enhancing the overall security posture.

Join Rise to see the full answer
What scripting languages are you familiar with, and how do you use them in your work?

I am well-versed in using scripting languages such as Python and Bash to automate various tasks within the DevSecOps workflow. These scripts help me streamline processes like vulnerability scans, configuration management, and reporting, allowing for quicker responses to security issues.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Authorium Hybrid San Francisco, CA
Posted 14 days ago
HSO Remote No location specified
Posted 12 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 2 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Family Medical Leave
Maternity Leave
Paternity Leave
Lactation Facilities
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Time-Off
Paid Volunteer Time
Posted 3 days ago
Photo of the Rise User
Posted 4 days ago

authorium is the industry leader in document process automation, providing a transformative enterprise solution for city, state, and federal government agencies with complex document-centric processes. whether in admin, policy, hr, budgeting, cont...

9 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!