TinyFish Logo

TinyFish

Senior DevSecOps Engineer

Reposted 9 Days Ago
Be an Early Applicant
Hybrid
Los Altos, CA
Senior level
Hybrid
Los Altos, CA
Senior level
Own and improve TinyFish’s vulnerability-management program across AWS infrastructure, applications, containers, CI/CD, and production services. Implement security controls, automate security testing and compliance checks, conduct threat modeling, coordinate penetration tests, and drive findings through verified remediation. Support incident response, security logging, detection engineering, SOC 2 and ISO 27001 initiatives, and security reporting while partnering with engineering and leadership.
The summary above was generated by AI

Job Title
Senior DevSecOps Engineer

Location
In-office or Remote - (strong preference for overlap with Pacific Time).

Employment Type
Full-time employee.

About the Role

TinyFish is looking for a hands-on Senior DevSecOps Engineer to drive the execution of our security program across infrastructure and product engineering.

You will own the day-to-day vulnerability management process, implement and automate security controls, and work with engineering teams to drive findings through remediation and verified closure. You will help translate security policies, compliance requirements, penetration-test findings, and identified risks into concrete engineering work.

This is an individual-contributor role for someone who combines strong cloud and application-security fundamentals with a bias for execution. You will partner closely with Infrastructure, Engineering, Product, and company leadership. You will not be expected to single-handedly own every aspect of company security strategy, compliance, and risk acceptance.

Responsibilities
  • Own the vulnerability-management lifecycle across cloud infrastructure, application code, dependencies, containers, CI/CD systems, and production services.

  • Establish repeatable processes for vulnerability discovery, triage, severity assessment, ownership, remediation SLAs, exceptions, verification, and reporting.

  • Drive critical and high-severity findings through closure by partnering with service owners and escalating unresolved risks when necessary.

  • Implement and maintain security controls across AWS, including IAM, networking, encryption, key management, secrets, logging, and workload isolation.

  • Integrate security into the software-development lifecycle through practical guardrails such as SAST, DAST, dependency scanning, secret detection, container scanning, and infrastructure-as-code checks.

  • Review security-sensitive designs and changes, perform threat modeling, and provide concrete recommendations to engineering teams.

  • Improve security across public APIs, authentication and authorization, service-to-service communication, customer credentials, sensitive data, and software-supply-chain workflows.

  • Coordinate third-party penetration tests and ensure findings are assigned, prioritized, remediated, and validated.

  • Develop and maintain incident-response playbooks, participate in security incidents, facilitate tabletop exercises, and track corrective actions after incidents.

  • Partner with Infrastructure and Observability teams to improve security logging, alerting, investigation workflows, and threat detection.

  • Translate security policies and compliance controls into technical requirements, automated checks, and engineering work.

  • Support SOC 2, ISO 27001, and other applicable assurance or regulatory initiatives through control implementation, evidence collection, and remediation of audit findings.

  • Maintain clear reporting on security posture, vulnerability backlog, remediation performance, control coverage, and overdue risks.

  • Create practical security guidance and documentation that helps engineers ship secure systems without unnecessary friction.

Qualifications
  • 5+ years of hands-on experience in DevSecOps, cloud security, application security, security engineering, or a related role.

  • Demonstrated experience building or operating a vulnerability-management program and driving findings through verified remediation.

  • Strong knowledge of AWS security, including IAM, VPC networking, KMS, secrets management, logging, monitoring, and multi-account environments.

  • Production experience with infrastructure as code, preferably Terraform.

  • Experience securing CI/CD pipelines, preferably GitHub Actions, including identity, permissions, secrets, dependencies, and build artifacts.

  • Practical experience with security tooling such as SAST, DAST, software-composition analysis, secret detection, container scanning, cloud-security posture management, and infrastructure-as-code scanning.

  • Solid understanding of common application-security risks, secure coding practices, authentication and authorization patterns, and the OWASP Top 10.

  • Experience reviewing technical designs, conducting threat models, and turning identified risks into actionable engineering recommendations.

  • Experience supporting security incident response, root-cause analysis, and corrective-action tracking.

  • Familiarity with SOC 2, ISO 27001, CIS Benchmarks, or similar security and compliance frameworks.

  • Ability to automate security workflows using Python, Bash, or another scripting language.

  • Strong written and verbal communication skills, including the ability to explain risk, priorities, and remediation requirements to both engineers and leadership.

  • A pragmatic, risk-based approach and a strong bias toward measurable execution.

Nice to Have
  • Experience securing containerized or isolated workloads running on ECS, EKS, Kubernetes, or similar platforms.

  • Experience with AWS Organizations, Control Tower, Security Hub, GuardDuty, AWS Config, CloudTrail, and IAM Identity Center.

  • Experience securing distributed systems, public APIs, browser automation infrastructure, or systems that handle customer credentials and session data.

  • Experience with SIEM, centralized security logging, and detection engineering.

  • Experience automating compliance evidence collection or working with platforms such as Vanta.

  • Experience coordinating penetration tests, red-team exercises, or customer security reviews.

  • Security certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or OSCP.

What We Offer
  • A high-impact role securing infrastructure and products at the core of an AI-powered web automation platform.

  • Direct collaboration with Infrastructure, Product, and Engineering teams.

  • Significant ownership and the ability to shape how security is implemented as TinyFish grows.

  • A culture that values security, engineering quality, pragmatism, and accountability.

  • A remote, distributed, and async-friendly work environment.

  • Competitive compensation.

Similar Jobs

6 Days Ago
In-Office
114K-213K Annually
Senior level
114K-213K Annually
Senior level
Aerospace • Logistics • Security • Software • Cybersecurity
Develops and maintains enterprise engineering toolsets, operational data platforms, mission-critical systems, and CI/CD pipelines. Collaborates across cloud, application, communications, payload, testing, and DevSecOps teams. Responsibilities include predictive analytics, database and container platform development, automation, system deployment, technical risk mitigation, stakeholder communication, and supporting cloud migration and microservices adoption. This is a full-time, on-site role requiring an active Top Secret clearance and eligibility for SCI and SAP clearances.
Top Skills: Amazon EksAnsibleAtlassian SuiteBambooBashBitbucketC++Ci/CdConfluenceDockerDocker SwarmElastic StackGitlabGrafanaInfrastructure As CodeJavaJIRAKubernetesMatlabMavenMicroservicesNomadPowershellPuppetPythonRed Hat Openshift
12 Days Ago
In-Office
112K-179K Annually
Senior level
112K-179K Annually
Senior level
Aerospace • Information Technology • Security • Cybersecurity • Defense
Build and maintain CI/CD pipelines, automate infrastructure, and support secure containerized platforms for U.S. Navy mission software. The role partners with software and cybersecurity engineers to resolve delivery issues, adapt technical stacks, and enable rapid microservice deployment to orchestration platforms. Responsibilities include infrastructure automation, container platform support, and pipeline engineering in regulated environments.
Top Skills: AnsibleAWSAws CodebuildAzureBashBitbucketBuildahCentosCloudFormationComptia Security+ConfluenceDockerGitlabHelmJavaJenkinsJIRAKubernetesLinuxOpenshiftPodmanPowershellPythonReactRhelSQLTerraformTypescriptUbuntu
One Month Ago
Remote or Hybrid
USA
Senior level
Senior level
Software
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Top Skills: Api SecurityAquaAzureAzure DevopsAzure Key VaultAzure Security CenterBlack DuckBurp SuiteCheckmarxCi/CdDastGithub Advanced SecurityHashicorp VaultMendMicroservicesOwasp ZapPrisma CloudSastScaSecrets ManagementSemgrepSnykSonarqubeTerraformVeracodeWiz

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account