Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
DevSecOps Engineer image - Rise Careers
Job details

DevSecOps Engineer

As a DevSecOps Engineer at Authorium, you'll play a vital role in building and maintaining our secure and scalable SaaS platform hosted on AWS by bridging the gap between development and security, implementing robust application security measures aligned with NIST 800-53, and engineering secure infrastructure. You'll work closely with developers, security experts, and other operations teams to ensure our platform's security, reliability, and performance.

  • Application Security:
    • Integrate security vulnerability scanning, SAST, and DAST tools into the CI/CD pipeline.
    • Manage vulnerability and code scanning tools to ensure adequate coverage and efficient vulnerability remediation.
    • Conduct security reviews of code, APIs, and infrastructure designs.
    • Partner with the engineering team to implement security measures and remediate any discovered vulnerabilities.
  • Security Infrastructure Engineering:
    • Design, build, and deploy secure infrastructure on AWS Commercial and AWS GovCloud using Infrastructure as Code (IaC) technologies like Terraform.
    • Oversee management of security controls within the AWS ecosystem, including IAM roles and policies, VPCs, security groups, and encryption.
    • Automate security tasks and configuration management.
    • Monitor and analyze security alerts to identify and respond to potential threats.
    • Collaborate with the DevOps team to integrate security considerations into CI/CD pipelines.
      • Defence in Depth
      • High-Availability/Disaster Recovery/Business Continuity
      • Drift Detection/Remediation
      • E2EE (end to end encryption)
      • Role-based access controls (RBAC)
      • Incident Response
      • Least Privilege
    • Familiarity with the following technologies: 
      • Linux
      • Kubernetes
      • Helm
      • CircleCI
      • Git
      • GitHub Actions
      • AWS tools and services: 
        • AWS Security Hub
        • Amazon GuardDuty
        • Amazon Inspector
        • Amazon CloudWatch
        • AWS CloudTrail
        • AWS WAF & Shield
        • AWS Key Management Service (KMS)
        • AWS Systems Manager Parameter Store
        • AWS Secrets Manager
        • AWS Lambda
        • AWS IAM
        • Amazon EC2
        • Amazon ECR
        • Amazon ECS
        • Amazon EKS
        • Amazon EFS
        • Amazon S3
        • Amazon RDS
  • General DevSecOps:
    • Collaborate with development and security teams to define and implement DevSecOps principles and best practices.
    • Manage and automate security testing procedures within the CI/CD pipeline.
    • Stay informed about new DevSecOps tools and technologies.
    • Communicate effectively with technical and non-technical stakeholders.
  • Bachelor's degree in Information Security, Computer Science, or a related field or equivalent work experience.
  • Minimum of 2 years of experience in information security or a related field.
  • Working knowledge of FedRAMP/StateRAMP requirements and compliance frameworks.
  • Experience with continuous monitoring tools and techniques.
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and as part of a team.

Nice to Have:

  • Certification (e.g. CISSP, CISM, CISA, Ethical Hacking, AWS, etc.).
  • Knowledge of scripting languages (e.g., Python, Bash) is a plus.

Employees located within 30 miles of our hub cities—San Francisco, Sacramento, and (coming soon) Washington, D.C. —are required to work onsite from Tuesday to Thursday. Remote work is available on other days.

  • Salary Range: $145,000-$155,000
  • Flexible PTO
  • 100% employer-funded medical, dental and vision insurance
  • 100% remote
  • $500 home office stipend
  • 401K with Profit Sharing Plan

Average salary estimate

$150000 / YEARLY (est.)
min
max
$145000K
$155000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About DevSecOps Engineer, Authorium

As a DevSecOps Engineer at Authorium, you’ll be an integral part of our dynamic team, pushing the boundaries of secure and scalable SaaS solutions hosted on AWS. Your role is pivotal as you bridge the gap between development and security, enabling us to implement top-notch application security measures that align with NIST 800-53 guidelines. Collaborating closely with developers, security experts, and various operations teams, you’ll ensure our platform maintains utmost security, reliability, and performance. In this role, you’ll be responsible for integrating security scanning tools into our CI/CD pipeline, managing vulnerabilities, and conducting thorough code reviews. Moreover, you’ll design and deploy secure infrastructure using Infrastructure as Code (IaC) technologies like Terraform, while overseeing security controls within the AWS environment. This involves managing IAM roles, security policies, and monitoring for potential threats to fortify our defenses. Familiarity with tools like AWS Security Hub, Amazon GuardDuty, and other AWS services will be crucial as you automate security tasks and enhance our incident response protocols. Ideally, you bring a background in Information Security or Computer Science with at least two years of relevant experience, coupled with excellent problem-solving skills. If you have a certification like CISSP or a knack for scripting languages, that’s a bonus! Join us at Authorium, where innovation meets security, and help us shape a safer digital landscape.

Frequently Asked Questions (FAQs) for DevSecOps Engineer Role at Authorium
What are the main responsibilities of a DevSecOps Engineer at Authorium?

As a DevSecOps Engineer at Authorium, you'll oversee the integration of security measures within our development processes. Your responsibilities include executing security vulnerability scanning, managing tools like SAST and DAST, and collaborating with developers to ensure the safety of the code and infrastructure. You'll also design secure AWS architectures using Infrastructure as Code technologies and automate security tasks to enhance our CI/CD pipeline.

Join Rise to see the full answer
What qualifications are required for the DevSecOps Engineer position at Authorium?

To qualify for the DevSecOps Engineer position at Authorium, candidates should hold a Bachelor's degree in Information Security, Computer Science, or a related field, or possess equivalent work experience. A minimum of two years of experience in information security is expected. Familiarity with compliance frameworks like FedRAMP/StateRAMP and tools associated with AWS security is preferred to ensure successful performance in this role.

Join Rise to see the full answer
What tools and technologies should I be familiar with as a DevSecOps Engineer at Authorium?

As a DevSecOps Engineer at Authorium, you should be well-versed in a variety of technologies, including AWS services like AWS Security Hub, Amazon GuardDuty, and IAM management. Familiarity with CI/CD tools such as CircleCI and GitHub Actions, as well as scripting languages like Python or Bash, will also set you up for success in strengthening our security posture in the cloud environment.

Join Rise to see the full answer
Does the DevSecOps Engineer position at Authorium allow for remote work?

Yes, Authorium offers flexibility for the DevSecOps Engineer position. While employees within 30 miles of our hub cities are required to work onsite from Tuesday to Thursday, remote work is encouraged on other days. This setup enables you to maintain a work-life balance while playing a crucial role in our security efforts.

Join Rise to see the full answer
How does Authorium support professional development for a DevSecOps Engineer?

At Authorium, we believe in continuous learning and professional growth. As a DevSecOps Engineer, you'll have access to training programs and resources to stay updated with the latest DevSecOps tools and practices. We encourage certifications like CISSP or AWS to further enhance your skills, reflecting our commitment to your career development.

Join Rise to see the full answer
Common Interview Questions for DevSecOps Engineer
Can you explain your experience with cloud security, specifically in AWS, as a DevSecOps Engineer?

When answering this question, you should detail specific AWS services you've worked with, like AWS Security Hub and IAM. Discuss your practical experiences in implementing security measures, managing vulnerabilities, and using Infrastructure as Code to create secure environments, showcasing your hands-on expertise.

Join Rise to see the full answer
What are the key principles of DevSecOps that you implement in your daily work?

Describe the principles of integrating security into every stage of the development lifecycle, highlighting automation, continuous monitoring, and collaboration among development, security, and operations teams. Explain how these principles lead to enhanced security and efficiency within the organization.

Join Rise to see the full answer
How do you handle security vulnerabilities found during code reviews?

Discuss your approach to identifying, prioritizing, and remediating vulnerabilities. Mention tools you use for scanning and how you collaborate with developers to ensure timely fixes, ensuring security remains a shared responsibility across teams.

Join Rise to see the full answer
What tools do you prefer for security vulnerability scanning in a CI/CD pipeline?

Speak about your experience with popular tools such as SAST and DAST, explaining why you prefer them based on their effectiveness and how they integrate into CI/CD workflows. Highlight how these tools contribute to proactive security measures and quality assurance.

Join Rise to see the full answer
How do you ensure compliance with frameworks like NIST 800-53 in your work?

Talk about your familiarity with compliance requirements and how you incorporate them into your security practices, from infrastructure design to regular audits. Provide examples of specific controls you've implemented to maintain compliance.

Join Rise to see the full answer
Can you describe a time when you had to respond to a security incident?

Use the STAR method to outline a specific incident and your response strategy, focusing on how you analyzed the situation, the immediate actions taken, and post-incident evaluations that improved your organization’s security posture.

Join Rise to see the full answer
What’s your experience with Infrastructure as Code (IaC) for security purposes?

Explain your understanding of IaC concepts and tools like Terraform, detailing past projects where you used IaC to establish secure infrastructure. Discuss how this approach enhances consistency and security while provisioning resources.

Join Rise to see the full answer
How do you keep yourself updated with the latest security threats and tools?

Share your strategies for staying informed, such as following industry blogs, participating in forums, attending webinars and conferences, and engaging with community discussions. This showcases your proactive approach to continuous learning.

Join Rise to see the full answer
What role does automation play in your DevSecOps practices?

Emphasize the importance of automation in improving efficiency and reducing human error in security processes. Talk about specific areas you’ve automated, like vulnerability scanning, compliance checks, or security configurations, and the benefits realized.

Join Rise to see the full answer
Why do you want to work as a DevSecOps Engineer at Authorium?

Craft a response that connects your career goals and values with Authorium’s mission, focusing on your passion for security, innovation, and collaboration. Mention specific aspects of the company or role that excite you, showing that you’ve done your research.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Authorium Remote Washington, District of Columbia, United States
Posted 8 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 6 days ago
Cigna Healthcare Remote St. Louis, Missouri, United States
Posted 12 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User

Join Daimler Truck as a Software Architect to shape the future of driver experience in their software-defined vehicle platform.

Photo of the Rise User
Posted 6 days ago
Posted 5 days ago

Join Mindrift as a freelance AI Tutor to work on cutting-edge AI projects while enjoying a flexible schedule.

Join Trissential as a Full Stack Developer and help innovate healthcare technology from the comfort of your home.

authorium is the industry leader in document process automation, providing a transformative enterprise solution for city, state, and federal government agencies with complex document-centric processes. whether in admin, policy, hr, budgeting, cont...

21 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
12 people applied to Software Engineer Intern at UiPath
Photo of the Rise User
Someone from OH, Columbus just viewed Amazon customer service at Amazon
Photo of the Rise User
Someone from OH, Hilliard just viewed UX Researcher (Contract Position) at RR Donnelley
Photo of the Rise User
Someone from OH, Hilliard just viewed Minor Team Member (14-15) at Chick-fil-A
Photo of the Rise User
Someone from OH, Hilliard just viewed Lead UX Product Designer -Stores(Remote Or Hybrid) at Target
F
Someone from OH, Cincinnati just viewed Payroll Tax Consultant at Fourth Enterprises, LLC
Photo of the Rise User
Someone from OH, Columbus just viewed Aquatics Director at British Swim School
Photo of the Rise User
Someone from OH, North Canton just viewed 2025 MiLB Gameday Support (Seasonal) at MLB (Job Board Only)
E
Someone from OH, Columbus just viewed Intern, Cell Line Development at Evotec
Photo of the Rise User
Someone from OH, Westlake just viewed Payments Support Specialist (1 year contract) at Convera
Photo of the Rise User
Someone from OH, Portsmouth just viewed Property Manager II (Buckeye Towers) at WinnCompanies
Photo of the Rise User
Someone from OH, Columbus just viewed Financial Services Representative at Nationwide
Photo of the Rise User
Someone from OH, Dublin just viewed Global Growth Marketing Associate at Spotify
Photo of the Rise User
Someone from OH, Portsmouth just viewed Merchandising Part Time Days at Lowes
Photo of the Rise User
Someone from OH, Euclid just viewed Notary - Digital Reporter at Parrot
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager - Remote at Experian
Photo of the Rise User
Someone from OH, Cleveland just viewed Data Entry Specialist - Remote at ABC Legal Services
Photo of the Rise User
Someone from OH, Cleveland just viewed Digital Sales Operations Analyst at Visa
Photo of the Rise User
Someone from OH, Lancaster just viewed Client Partner, Inside Sales at Sportradar
Photo of the Rise User
Someone from OH, Perrysburg just viewed Patient Success Specialist Temp to Hire at Natera
Photo of the Rise User
Someone from OH, Cincinnati just viewed Producer at ElevenLabs