Dalio Family Office Logo

Dalio Family Office

Senior DevSecOps Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
New York, NY, USA
170K-230K Annually
Senior level
In-Office
New York, NY, USA
170K-230K Annually
Senior level
Design, deploy, and secure scalable AWS and Azure cloud environments using IaC. Build secure CI/CD pipelines, enforce software supply-chain protections, harden AKS/EKS, manage key rotation and data protection, and centralize telemetry into Microsoft Defender for Cloud. Support secure AI/LLM platforms and operationalize cloud security posture and runtime protections.
The summary above was generated by AI

Senior DevSecOps Engineer

Dalio Family Office

Dalio Family Office Overview:

The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO’s culture is built around meaningful work and meaningful relationships and the family’s commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi. This is a hybrid position reporting primarily out of our New York City office location.

Position Summary:

Reporting to the Cybersecurity Lead, the Senior DevSecOps Engineer will design, deploy, and secure scalable AWS + Azure environments with a strong focus on Infrastructure as Code (IaC). The purpose of this role is to build secure cloud-native infrastructure from the ground up, operationalize AWS/Azure services, and automate the reliability and security of mission-critical systems. You will embed security-by-design across the SDLC by implementing secure CI/CD pipelines with automated testing, policy controls, and supply-chain protections (SBOMs, signed artifacts, provenance), while centralizing security telemetry into Microsoft Defender for Cloud for unified posture management, threat detection, and compliance. The role also secures cloud infrastructure, data, and key management using AWS KMS and Azure Key Vault, hardens AKS/EKS with policy-as-code (OPA/Gatekeeper) and runtime protections, and extends these controls to AI/LLM development and inference platforms including AWS Bedrock, AI Foundry, and vLLM.

Day-to-day responsibilities would include a combination of the following:

  • Embed security-by-design across the SDLC with automated controls and measurable security outcomes.
  • Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key management.
  • Harden container and Kubernetes platforms with consistent policy enforcement and runtime protection.
  • Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection, and policy gates, including threat modelling and secure design practices.
  • Enforce software supply-chain security (SBOMs, signed images, provenance verification) and route pipeline/code telemetry into Microsoft Defender for Cloud.
  • Secure AWS/Azure workloads across identity, network, compute, and storage; implement encryption, classification, retention, DLP, and safe logging.
  • Operate AWS KMS / Azure Key Vault (rotation, auditing, envelope encryption) and use Defender for Cloud for CSPM/CWPP, threat detection, and compliance.
  • Harden AKS/EKS using pod security, OPA/Gatekeeper, network policies, secrets management, and runtime protections; govern artifacts via JFrog Artifactory (trust, allow/deny, immutability) and integrate Kubernetes signals into Defender for Cloud.
  • Additional duties as assigned.

The ideal candidate will possess the following knowledge, skills, attributes, and values:

  • Security minded with the utmost regard for confidentiality and discretion.
  • Collaborative and helpful by nature.
  • Strong sense of ownership in one’s work.
  • Excellent communication and synthesis skills.
  • Demonstrated track record supporting mission-critical workloads end-to-end: secure deployments, hardening, centralized logging/telemetry, compliance, and continuous optimization.
  • Familiarity with cloud governance and security tooling including Microsoft Defender for Cloud, AWS SCPs/RCPs, Azure Policy, and OPA/Gatekeeper.

Illustrative Benefits:    

  • 100% company paid medical premiums
  • 17 company paid holidays
  • Friday summer hours
  • Monthly community happy hours
  • Hybrid work environment
  • Free catered food services for in-office days
  • Generous PTO offering 
  • Casual dress code
  • 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit)
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!

Qualifications:

  • Bachelor’s Degree or Diploma in Cybersecurity, Computer Science, Information Technology, or related discipline.
  • 7+ years of experience in DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments, including cloud security architecture and operations.
  • At least 3 years hands-on experience operating enterprise-scale platforms (systems engineering/administration), including reliability engineering, monitoring/telemetry, and incident response.
  • Advanced IaC expertise with Terraform (plus CloudFormation/Bicep preferred), building standardized, governed cloud foundations (landing zones, guardrails, automation).
  • Proven experience building and securing CI/CD automation using GitLab and/or Azure DevOps, including automated security testing and supply-chain controls (SBOMs, artifact signing, provenance).
  • Strong Kubernetes security experience with AKS/EKS, including policy enforcement and runtime protections.
  • Expertise in cryptographic key management and data protection, including AWS KMS / Azure Key Vault, encryption, and data security controls.
  • Experience securing AI/LLM systems and inference platforms (AI Foundry, AWS Bedrock, vLLM), including knowledge of OWASP LLM Top 10 and LLM guardrails.
  • Strong proficiency across Linux and Microsoft ecosystems (identity, hardening, patching, operational best practices) and scripting with Python/Bash/PowerShell (application languages such as Java/.NET/JavaScript (React.js) are a plus).

 

Compensation:

Compensation for the role includes a competitive salary in the range from $170,000 -$230,000 (inclusive of a merit-based bonus, dependent on years of experience, level of education obtained, as well as applicable skillset) and an excellent benefits package, including a comprehensive employer paid medical plan and generous employer match for 401k. 

Please note we are unable to provide immigration sponsorship for this position.

Use of AI in the Application Process:

We recognize that candidates may use AI-enabled tools to assist with resume drafting, application preparation, and interview preparation. Such use is permitted provided all submitted materials accurately reflect the candidate's own qualifications, experience, skills, and work history.

Candidates may not submit hidden instructions, embedded prompts, misleading metadata, deceptive content, code, or other materials intended to interfere with or improperly influence the Company's recruiting process or the administration of candidate applications

Any attempt to misrepresent qualifications or improperly interfere with the recruiting process may result in disqualification from consideration.


At the DFO, we believe our biggest asset is our people. We are proud to be an equal opportunity employer, hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting, hiring, and promoting processes and general treatment during employment, including on the basis of actual or perceived race, creed, color, religion, sex, age, sexual orientation, gender identity and/or expression, alienage or national origin, ancestry, citizenship status, marital status, veteran status, or disability.



 

 



Similar Jobs

2 Days Ago
Remote or Hybrid
USA
Senior level
Senior level
Software
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Top Skills: Api SecurityAquaAzureAzure DevopsAzure Key VaultAzure Security CenterBlack DuckBurp SuiteCheckmarxCi/CdDastGithub Advanced SecurityHashicorp VaultMendMicroservicesOwasp ZapPrisma CloudSastScaSecrets ManagementSemgrepSnykSonarqubeTerraformVeracodeWiz
17 Days Ago
In-Office or Remote
USA
Senior level
Senior level
Software
Design and harden Azure cloud architectures, embed security into CI/CD and infrastructure via DevSecOps, implement SAST/DAST and supply-chain controls, improve observability and SIEM integrations, remediate security debt, secure containers/Kubernetes, and build automation and developer-friendly guardrails to increase remediation velocity and operational resilience.
Top Skills: AutomationAzureAzure PolicyAzure RbacCi/CdClaude CodeContainer SecurityDastDependency ScanningDockerGitGithub ActionsGithub Advanced SecurityGithub CopilotInfrastructure As CodeKubernetesObservability ToolingPimSastScriptingSecrets ManagementSIEMSoftware Supply-Chain Security
5 Days Ago
Hybrid
New York, NY, USA
165K-225K Annually
Senior level
165K-225K Annually
Senior level
Software • Financial Services
Hands-on Senior DevSecOps Engineer responsible for designing and securing AWS infrastructure using IaC, improving CI/CD and developer experience, embedding security controls for SOC 2 readiness, building observability and on-call practices, and driving BC/DR and resilience across production systems.
Top Skills: AWSAws Ecs FargateAws Systems Manager (Ssm)BashBedrockChatgptCi/CdClaudeCloudwatchContainersDnsDockerElk StackIamJenkinsKubernetesPulumi (Python)PythonRedisRedshiftTerraformTlsUbuntu/LinuxVpc

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account