Istari Digital Logo

Istari Digital

DevSecOps Engineer

Reposted 27 Days Ago
Remote
Hiring Remotely in US
135K-220K Annually
Senior level
Remote
Hiring Remotely in US
135K-220K Annually
Senior level
Design, harden, and maintain secure, scalable AWS and Kubernetes infrastructure using Terraform. Harden hosts, manage Linux/Windows VMs and Active Directory, secure CI/CD, support vulnerability management, compliance/audits, incident response, runbooks, and operational troubleshooting for regulated and production environments.
The summary above was generated by AI

We are seeking a DevSecOps Engineer to join our Engineering team. This role is critical to securing, hardening, and scaling the infrastructure that powers our platform across cloud-hosted production environments.

This engineer will work closely with platform, infrastructure, and security stakeholders to improve the security and operational maturity of our AWS and Kubernetes environments, support compliance and audit readiness, and help ensure our systems are reliable, secure, and maintainable as we grow. This role will also support environments serving regulated and security-sensitive customer needs, including an environment we host for a Government organization.

The ideal candidate combines strong hands-on infrastructure expertise with sound security judgment and a practical, execution-focused mindset. They should be comfortable working across cloud infrastructure, Kubernetes, operating systems, compliance controls, and production operations.

Core Responsibilities

    Responsibilities include collaborating with the platform and engineering teams to secure and improve production infrastructure, harden cloud and host configurations, and build repeatable operational practices across environments. Key responsibilities include:

  • Design, implement, and maintain secure, scalable infrastructure in AWS

  • Manage, secure, and improve Kubernetes-based environments, including production workloads

  • Build and maintain infrastructure as code using Terraform

  • Harden production systems across cloud, compute, container, identity, and network layers

  • Develop and maintain secure baseline configurations for infrastructure and platform services

  • Support vulnerability management, patching, remediation, and configuration compliance efforts across environments

  • Configure, administer, and patch both Linux and Windows VMs

  • Support identity and access management practices, including least privilege, role design, and privileged access controls

  • Contribute to administration and integration of Active Directory domains where needed

  • Partner with engineering teams to improve security within CI/CD pipelines, deployment workflows, and operational processes

  • Support compliance initiatives, audits, evidence collection, and technical control validation

  • Develop and maintain documentation, operational runbooks, technical standards, and playbooks

  • Monitor, troubleshoot, and resolve complex infrastructure and security issues with clear and timely communication

  • Participate in incident response and post-incident analysis when infrastructure or platform issues arise

  • Stay current on cloud, infrastructure, and security best practices that can improve platform resilience and delivery

Required Qualifications

  • Minimum of 5 years of experience in DevOps, DevSecOps, Infrastructure Engineering, Platform Engineering, or Security Engineering

  • Strong hands-on experience with AWS in production environments

  • Proven experience with Kubernetes, preferably in production

  • Strong experience with Terraform and infrastructure-as-code practices

  • Experience hardening production environments and implementing secure configuration standards

  • Experience supporting compliance frameworks, audit preparation, evidence gathering, and control validation

  • Experience with vulnerability remediation, system patching, and operational security practices

  • Experience configuring and maintaining both Linux and Windows virtual machines

  • Strong understanding of IAM, secrets management, network security, logging, monitoring, and operational controls

  • Proven experience improving or securing CI/CD pipelines and deployment workflows

  • Excellent troubleshooting and problem-solving skills in complex production environments

  • Strong communication skills with the ability to explain technical concepts to both technical and non-technical stakeholders

  • Must live/work in the U.S.

Preferred Qualifications

  • Experience supporting environments with regulated, compliance-driven, or security-sensitive requirements

  • Familiarity with compliance or security frameworks such as SOC 2, NIST, ISO 27001, CMMC, or similar

  • Experience with EKS or other managed Kubernetes platforms

  • Experience configuring or supporting Active Directory Domain Services, Group Policy, or hybrid identity environments

  • Experience with automation and configuration management tools such as Ansible, PowerShell, or similar

  • Experience with PostgreSQL, cloud storage platforms, and production networking patterns

  • Scripting experience in Python, Bash, or PowerShell

  • Experience with security tooling related to container security, vulnerability management, or policy enforcement

  • Experience supporting customer-facing or mission-critical production infrastructure

  • Security+ Certification

  • Top Secret Security Clearance

About Istari Digital

Istari is a digital engineering software company building open, scalable infrastructure for engineering data. Our platform lets customers simply and securely integrate engineering models across disciplines, organizations, and security levels — whether they're designing prototypes, performing virtual testing, or training AI and autonomy for complex systems.

Focus is rewarded.  Finish is remembered.

Facts are friendly.  Even when they are not fun.

Fellowship is fundamental.  Make others successful.

Similar Jobs

Yesterday
In-Office or Remote
SC, USA
Senior level
Senior level
Aerospace • Information Technology • Cybersecurity • Defense
Designs and operates secure AWS cloud environments, DevSecOps pipelines, infrastructure-as-code, automated security controls, and incident response workflows. Responsibilities include integrating security testing into CI/CD, managing AWS firewalls and virtualized NGFWs, securing containers and Kubernetes workloads, enforcing IAM and compliance controls, monitoring threats, troubleshooting incidents, and automating remediation. The role supports NIWC Atlantic and requires an active Secret clearance, an ABET-accredited engineering degree, and substantial IT, AWS security, DevOps, and network-security experience.
Top Skills: ArtifactoryAWSAws CodepipelineAws Network FirewallAws SsoAws Step FunctionsAws WafBashCheck Point NgfwCloudFormationCloudtrailCloudwatchDnsEc2EcrEcsEfsEksF5 Big-IpFortinet NgfwGitGitlab CiGoGuarddutyIamJenkinsJIRAKubernetesLambdaPalo Alto NgfwPythonRdsRoute 53S3Security HubSftpSonarqubeTerraformVpcVpn
Yesterday
Remote
US
Senior level
Senior level
Aerospace • Information Technology • Cybersecurity • Defense
Designs, builds, and maintains DevSecOps platforms, CI/CD pipelines, cloud infrastructure, Kubernetes environments, infrastructure-as-code, and automated security validation. Supports AWS networking, image hardening, risk assessments, DoD and NIST compliance, system testing, troubleshooting, documentation, and Agile delivery for United States Navy systems. Requires collaboration across engineering teams, technical writers, and project work teams, along with periodic travel and active Secret clearance.
Top Skills: Amazon EksArgo CdAWSCloudFormationCnssi 1253Disa StigsDnsDockerDod 8570FargateGitlab Ci/CdHashicorp VaultIngress/EgressJenkinsKubernetesNist 800OpenshiftRancherRed Hat Enterprise LinuxTerraformTls
Yesterday
Remote
US
Senior level
Senior level
Aerospace • Information Technology • Cybersecurity • Defense
Designs, builds, and maintains DevSecOps platforms, CI/CD pipelines, infrastructure-as-code, Kubernetes environments, cloud networking, hardened images, and infrastructure automation. Performs security control validation, risk assessments, troubleshooting, testing, documentation, and compliance activities aligned with DoD and NIST guidance. Supports Agile planning, technical assessments, system integration, and cloud application development for United States Navy systems. Requires an active Top Secret clearance, Security+ certification, U.S. citizenship, and periodic travel.
Top Skills: AgileAmazon EksArgo CdAWSCloudFormationCnssi 1253Disa StigsDnsDockerDod 8570FargateGitlabGitlab Ci/CdHashicorp VaultIngress/EgressJenkinsKubernetesNist 800OpenshiftRancherRed Hat Enterprise LinuxTerraformTls

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account