A

DevSecOps Engineer

A-LIGN External
Posted this week

LOCATION

Panama · Remote

EXPERIENCE

4+ Years

TYPE

FullTime

SKILLS REQUIRED

Identity and Access ManagementVulnerability ManagementContinuous Integration and Delivery (CI/CD)

Job description

Overview

The DevSecOps Engineer executes security engineering activities across cloud infrastructure, CI/CD pipelines, and production applications. The role implements and validates security controls, delivers infrastructure and application improvements, supports continuous audit readiness, and automates security and audit evidence workflows.

What you'll do

  • Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications.
  • Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments.
  • Deliver production code addressing authentication, single sign-on, authorization, session security, and vulnerability remediation.
  • Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation.
  • Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools.
  • Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply.
  • Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence.
  • Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification.
  • Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows.
  • Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams.
  • Perform security impact analysis for production changes and maintain pre-production security deployment checklists.
  • Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews.

What you'll need

  • Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience.
  • At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering.
  • Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language.
  • Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting.
  • Experience using Terraform or a similar infrastructure as code platform in production environments.
  • Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration.
  • Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation.
  • Experience with scripting and automation using Python, shell, SQL, or similar tools.
  • Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks.
  • Ability to translate security and compliance requirements into practical engineering changes and implement them directly.
  • Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs.
  • Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks.
  • Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams.
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment.
  • Ability to work individually as well as collaboratively across technical and business teams.
  • Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification.

Nice to have

  • Experience working in regulated or compliance-driven environments.
  • Familiarity with FIPS 140-2 or FIPS 140-3 requirements.
  • Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling.
  • Experience operating in a private equity-backed or high-growth environment.
  • CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification.

Details

  • Location: Panama.
  • Remote role.
  • Employment type: Full-time.
  • Reports to the Principal Security Engineer.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

DevSecOps Engineer