Jobiglo

No results.

DevOps Security Engineer

Easy2Employ, LLC

Senior 🇬🇧 English
AWS Terraform CDK GitHub Actions IAM KMS Secrets Manager VPC GuardDuty Config OIDC SAML RBAC S3 Object Lock CloudWatch Grafana Cost Explorer

Job description

About the role

You will own the infrastructure, CI/CD pipelines, identity management, and security posture for a production AWS platform where auditability and tenant isolation are contractual commitments. The position starts as a fractional role (2–3 days per week) and will transition to full‑time as the platform matures.

Key responsibilities

  • Design, implement, and maintain infrastructure‑as‑code using Terraform or CDK across multiple environments.
  • Build and operate secure CI/CD pipelines (GitHub Actions or equivalent) with automated quality, static‑analysis, and security gates.
  • Define and enforce AWS security controls: IAM policies, KMS, Secrets Manager, VPC, security groups, SCPs, GuardDuty, and Config.
  • Implement robust identity and access management, including RBAC, OIDC/SAML integration, token lifecycles, and provable off‑boarding.
  • Ensure auditability through immutable logs, S3 Object Lock/WORM storage, tamper‑evident hashing, and clock discipline.
  • Provide observability, cost monitoring, and SLO tracking using CloudWatch, Grafana, and Cost Explorer dashboards.
  • Maintain resilience with tested backup/restore procedures, RTO/RPO targets, and single‑region growth paths.
  • Prepare compliance evidence for SOC 2, ISO 27001, and enterprise security questionnaires.

Required profile

  • 4+ years of DevOps, platform, or SRE experience, primarily on AWS.
  • Proven end‑to‑end ownership of production infrastructure‑as‑code.
  • Experience designing CI/CD pipelines that enforce security gates and can block merges or deployments.
  • Security‑first mindset with a track record of implementing least‑privilege access and secret management.
  • Availability part‑time from autumn 2026, moving to full‑time in the new year.

Required skills

  • AWS (IAM, KMS, Secrets Manager, VPC, GuardDuty, Config, SCPs)
  • Infrastructure as Code: Terraform or CDK
  • CI/CD pipeline tools: GitHub Actions or equivalent
  • Identity protocols: OIDC, SAML, RBAC
  • Logging and audit: immutable logs, S3 Object Lock, WORM storage
  • Observability: CloudWatch, Grafana
  • Cost management: Cost Explorer, CUR dashboards

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Easy2Employ, LLC.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 2 weeks from now

32 views · 1 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Easy2Employ, LLC