DevSecOps Engineer

Posted 9 Days Ago
Be an Early Applicant
Hiring Remotely in Panamá
Remote
Junior
Security • Cybersecurity
The Role
Designs and validates security controls across cloud infrastructure, CI/CD pipelines, and production applications. Builds infrastructure as code, develops security-focused software, administers identity and access management, remediates vulnerabilities, and addresses penetration testing findings. Translates FedRAMP and NIST requirements into technical controls and audit evidence, automates security operations, maintains cryptographic compliance and architecture documentation, and supports threat modeling, monitoring, supply-chain security, and access reviews.
Summary Generated by Built In
About the Role

The DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. As the DevSecOps Engineer, you will provide exceptional technical and security strategies to help support the continued growth of our fast-paced company. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.

Reports to

Principal Security Engineer

Pay Classification

Full-Time

Responsibilities
  • Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications
  • Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments
  • Deliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation
  • Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation
  • Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools
  • Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply
  • Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence
  • Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification
  • Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows
  • Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams
  • Perform security impact analysis for production changes and maintain pre-production security deployment checklists
  • Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews
Minimum Qualifications

EDUCATION

  • Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience

EXPERIENCE

  • At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering
  • Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language
  • Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting
  • Experience using Terraform or a similar infrastructure as code platform in production environments
  • Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration
  • Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation
  • Experience with scripting and automation using Python, shell, SQL, or similar tools
  • Experience working in regulated or compliance-driven environments preferred
  • Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks
  • Familiarity with FIPS 140-2 or FIPS 140-3 requirements preferred
  • Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling preferred
  • Experience operating in a private equity-backed or high-growth environment preferred

CERTIFICATIONS

  • Preferred: CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification

SKILLS

  • Ability to translate security and compliance requirements into practical engineering changes and implement them directly
  • Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs
  • Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks
  • Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment
  • Ability to work individually as well as collaboratively across technical and business teams
  • Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification
Benefits
  • Employer Paid Life & Health Insurance 
  • Competitive Bonus Structure 
  • Home Office Reimbursement 
  • Technology Allowance 
  • Certification Reimbursement 
  • BeneficiaT Discount Loyalty Program 
  • Personalized Career Coaching 
  • Generous Paid Time Off 
  • Paid Office Closure December 25-January 1 
  • Summer Hours  
About A-LIGN

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com. 

Come Work for A-LIGN! 

Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn.  

A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply! 

Skills Required

  • Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or equivalent education and experience
  • At least 2 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering
  • Production software development experience in Go, Python, TypeScript, or a comparable modern programming language
  • Hands-on experience with GCP, AWS, or Azure, including IAM, containers or serverless services, build pipelines, secrets management, and log troubleshooting
  • Production experience using Terraform or a similar infrastructure-as-code platform
  • Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration
  • Experience managing vulnerabilities and remediating penetration testing findings at the code level
  • Experience with scripting and automation using Python, shell, SQL, or similar tools
  • Experience in regulated or compliance-driven environments
  • Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks
  • Familiarity with FIPS 140-2 or FIPS 140-3 requirements
  • Experience with fine-grained authorization models, GRC platforms, or compliance-as-code tooling
  • CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security Specialty, or similar cloud security certification
  • Experience using agentic AI development tools for coding, integrations, workflow automation, and output verification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Tampa, FL
573 Employees
Year Founded: 2009

What We Do

A-LIGN is a technology-enabled security and compliance partner that helps global organizations take a strategic approach to confidently mitigate cybersecurity risks. Our breadth and depth of expertise and A-SCEND, our proprietary compliance management platform, enable you to assess against the leading cybersecurity compliance frameworks important to your business – with one partner. With A-LIGN as your guide, we bring you the people, process and platform you need to secure your summit, protect against future risks and build customer confidence so you can focus on elevating your business.

Similar Jobs

Bluelight Consulting Logo Bluelight Consulting

Site Reliability Engineer

Professional Services • Software
In-Office or Remote
David, Chiriquí, PAN
22 Employees

Bluelight Consulting Logo Bluelight Consulting

Site Reliability Engineer

Professional Services • Software
Remote
Colón, PAN
22 Employees

Bluelight Consulting Logo Bluelight Consulting

Site Reliability Engineer

Professional Services • Software
In-Office or Remote
Panama City, Panamá, PAN
22 Employees

Similar Companies Hiring

SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account