DevSecOps Engineer

Posted Yesterday
Be an Early Applicant
27 Locations
Remote
Senior level
Artificial Intelligence • Information Technology • Cybersecurity
The Role
Lead DevSecOps engineer owning security and compliance implementation across infrastructure, CI/CD, Kubernetes, and cloud. Implement SOC 2/ISO controls in Drata, automate onboarding/offboarding and access reviews, drive SDLC security (SAST/SCA/secrets), run vulnerability management and incident response, and spend ~60% on infrastructure operations, monitoring, and on-call.
Summary Generated by Built In
Description

The company is systematically building out its security and compliance function. We have already launched the SOC 2 and ISO 27001 processes on Drata, with the goal of completing them by the end of Q2. In the mid-term roadmap, we also plan to cover GDPR, HIPAA, and HITRUST.

We are looking for our first dedicated DevSecOps Engineer who will take ownership of this area.

Above all, we are seeking a strong, hands-on engineer, someone who can not only describe security and compliance processes but also independently implement them across infrastructure, CI/CD, Kubernetes, cloud environments, and production services.

This role is not about “paper compliance”. However, working with policies, procedures, and evidence will also be an important part of the responsibility. We need someone who can connect compliance requirements to real technical controls and ensure they are properly implemented, validated, documented, and audit-ready.

Requirements
  • 5+ years of hands-on experience in security / DevSecOps for production infrastructure.
  • Direct experience with SOC 2 implementation: controls, evidence collection, audit preparation, and communication with auditors. Experience with Drata, Vanta, or a similar compliance automation platform.
  • Ability to write security policies and procedures yourself — and implement them in a way that actually works in day-to-day operations, not just sits in Notion as a checkbox.
  • Strong hands-on experience with Docker, Kubernetes, and cloud environments — GCP and/or AWS. This includes IAM, network policies, secrets management, hardening, and production operations, not just theory.
  • Strong understanding of IAM/SSO: centralized access management, provisioning/deprovisioning, and periodic access reviews.
  • Experience building onboarding and offboarding processes from a security and compliance perspective.
  • Ability to automate routine work using Python and/or Bash.
  • Ownership mindset: you take responsibility for a task, drive it to completion, and think one step ahead.
  • Friendly, non-toxic, and pleasant to work with.
  • Strong communication with developers: you can clearly and constructively explain your position, defend it when needed, and find common ground.
  • Willingness and ability to mentor, teach, and share knowledge with others.
  • Analytical mindset: you dig down to the root cause instead of just treating symptoms.
  • Proactivity: you would rather prevent an outage than heroically fight it later.
  • Strong attention to detail and reliability.

Nice to have

  • Experience with GDPR, HIPAA, and HITRUST — these are the next steps on our roadmap.
  • Experience in regulated industries such as banking, fintech, or healthcare, including customer/vendor security audits.
  • Experience with both on-prem and SaaS environments.
  • Kubernetes security tooling: Falco, OPA/Gatekeeper, Pod Security Standards, Trivy.
  • Experience using AI agents to automate routine tasks — this is already part of our engineering culture.
  • Terraform/Ansible and GitOps experience.
  • Experience with bug bounty or responsible disclosure programs.
Responsibilities
  • Own Drata, controls, evidence collection, and communication with auditors. Support SOC 2 and ISO 27001, with GDPR, HIPAA, and HITRUST planned next.
  • Develop and maintain security policies and procedures, including Vulnerability Management, Access Control, Incident Response, Data Protection, and others. These should be practical, living documents that reflect how we actually work, not generic templates.
  • Build onboarding, offboarding, and access review as a real process. Today, this is mostly handled through manual tickets; you will own the process and automate it through SSO, centralized IAM, and automated provisioning/deprovisioning across GCP, AWS, GitHub, and SaaS tools.
  • Drive SDLC security: Dependabot, CodeQL/SAST, SCA, dependency update policies, secrets management, and related controls. The goal is to find the right balance between compliance requirements, common sense, and a smooth developer experience.
  • Own vulnerability management: scanning, CVE triage, patching, annual penetration testing, vendor selection, coordination, and follow-up on findings.
  • Participate in response to critical vulnerabilities and security incidents.
  • Improve security observability: audit logging, change tracking, and reporting across all production platforms.
  • Spend around 60% of your time on the general infrastructure track: Kubernetes, deployments, monitoring, automation, and on-call. Infrastructure should not be a black box for you.
What we offer
  • The team has built award-winning AI products for tech corporations — devices, voice assistants, products that are actually in the world 
  • Cutting-edge tech stack: Speech Technologies, NLP, Generative AI (LLMs, diffusion models), voice-first agentic architecture with privacy-first and on-premises deployment
  • High engineering bar and real ownership — the team cares about what actually works in production, not what looks good in a demo, and you'll see the impact of your work directly 
  • Fast career progression — a senior-heavy team and a high volume of real problems means you grow faster than you would anywhere else 
  • Startup pace with enterprise stability — real clients, real revenue, no bureaucracy 
  • Fully remote across Europe
  • 21 vacation days + public holidays + 5 sick days 
  • Private English lessons via Preply

Skills Required

  • 5+ years hands-on experience in security / DevSecOps for production infrastructure
  • Direct experience with SOC 2 implementation, evidence collection, audit preparation, and auditor communication; experience with Drata, Vanta, or similar
  • Ability to author and implement practical security policies and procedures
  • Strong hands-on experience with Docker, Kubernetes, and cloud environments (GCP and/or AWS), including IAM, network policies, secrets management, hardening, and production operations
  • Strong understanding of IAM/SSO, centralized access management, provisioning/deprovisioning, and periodic access reviews
  • Experience building onboarding and offboarding processes from a security and compliance perspective
  • Ability to automate routine work using Python and/or Bash
  • Ownership mindset, reliability, strong attention to detail
  • Friendly, non-toxic, strong communicator able to work with developers and defend positions constructively
  • Willingness and ability to mentor, teach, and share knowledge
  • Analytical mindset and proactivity (prevent outages, dig to root cause)
  • Experience with GDPR, HIPAA, and HITRUST
  • Experience in regulated industries (banking, fintech, healthcare) and customer/vendor security audits
  • Experience with on-prem and SaaS environments
  • Familiarity with Kubernetes security tooling: Falco, OPA/Gatekeeper, Pod Security Standards, Trivy
  • Experience using AI agents to automate routine tasks
  • Terraform/Ansible and GitOps experience
  • Experience with bug bounty or responsible disclosure programs

Acclaim AI Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Acclaim AI and has not been reviewed or approved by Acclaim AI.

  • Parental & Family Support Parental leave is explicitly listed on the company’s Wellfound profile. Feedback suggests family support is part of the baseline perks communicated publicly.
  • Leave & Time Off Breadth Generous vacation is highlighted on Wellfound. This points to broader time-off flexibility typical of startup-style packages.
  • Wellbeing & Lifestyle Benefits Professional development and company events are called out on Wellfound. These signals indicate investment in growth and team connection beyond core benefits.

Acclaim AI Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
69 Employees

What We Do

Acclaim is a voice-first AI customer experience (CX) platform purpose-built for regulated industries including banking, fintech, healthcare, and insurance. It provides enterprises with goal-oriented AI agents that go beyond conversation to deliver agentic solutions that solve end-to-end business problems—orchestrating and executing complete customer workflows from outreach through resolution. Acclaim's solutions transform human-driven CX processes into AI-powered ones that are continuously learning and improving. Our platform helps organizations delight with human-quality conversations, accelerate revenue-driving interactions, and safeguard their data by maintaining strict compliance across every customer channel—creating more seamless customer experiences while improving the productivity and satisfaction of human agents. Built on a privacy-first architecture with on-premises or private cloud deployment, Acclaim ensures every interaction is secure, compliant, and delivers results that speak for themselves.

Similar Jobs

CoinsPaid Logo CoinsPaid

Devsecops Engineer

Blockchain • Fintech • Payments • Cryptocurrency
Remote or Hybrid
Rigio, GRC
221 Employees

EUROPEAN DYNAMICS Logo EUROPEAN DYNAMICS

Devsecops Engineer

Information Technology • Consulting
In-Office or Remote
Athens, GRC
765 Employees

GitLab Logo GitLab

Marketing Manager

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
27 Locations
2500 Employees

GitLab Logo GitLab

Security Engineer

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
30 Locations
2500 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account