Overview
The DevSecOps Engineer executes security engineering activities across cloud infrastructure, CI/CD pipelines, and production applications. The role implements and validates security controls, delivers infrastructure and application improvements, supports continuous audit readiness, and automates security and audit evidence workflows.
What you'll do
- Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications.
- Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments.
- Deliver production code addressing authentication, single sign-on, authorization, session security, and vulnerability remediation.
- Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation.
- Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools.
- Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply.
- Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence.
- Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification.
- Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows.
- Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams.
- Perform security impact analysis for production changes and maintain pre-production security deployment checklists.
- Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews.
What you'll need
- Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience.
- At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering.
- Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language.
- Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting.
- Experience using Terraform or a similar infrastructure as code platform in production environments.
- Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration.
- Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation.
- Experience with scripting and automation using Python, shell, SQL, or similar tools.
- Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks.
- Ability to translate security and compliance requirements into practical engineering changes and implement them directly.
- Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs.
- Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks.
- Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams.
- Self-directed with strong follow-through in a fast-paced, deadline-driven environment.
- Ability to work individually as well as collaboratively across technical and business teams.
- Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification.
Nice to have
- Experience working in regulated or compliance-driven environments.
- Familiarity with FIPS 140-2 or FIPS 140-3 requirements.
- Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling.
- Experience operating in a private equity-backed or high-growth environment.
- CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification.
Details
- Location: Panama.
- Remote role.
- Employment type: Full-time.
- Reports to the Principal Security Engineer.
Read the full description and apply on the company’s own careers page.