PactFi Logo

PactFi

Senior DevSecOps Engineer

Posted Yesterday
In-Office or Remote
Hiring Remotely in New York, NY, USA
165K-225K Annually
Senior level
In-Office or Remote
Hiring Remotely in New York, NY, USA
165K-225K Annually
Senior level
The Senior DevSecOps Engineer will enhance security and reliability of PactFi's platform, focusing on AWS infrastructure, CI/CD workflows, and SOC 2 compliance while participating in 24/7 on-call operations.
The summary above was generated by AI

About PactFi

Private asset markets (PE, Private Credit, VC, Real Estate) have 10x to 9.8T in AUM over the past decade and are projected to grow to $17T in the next five years. However, digital infrastructure has not kept pace, with most of the market operating predominantly in error-prone, internal-only software solutions.

PactFi provides secure, end-to-end, operational infrastructure for managing complex private credit transactions. Our web-based application brings together all parties involved in such a transaction to more efficiently allocate capital, complete KYC, share documents, manage funds flow, and more. The platform is secured to a bank-grade standard, and we have received our SOC 2 Type 2 attestation.

PactFi was developed in close partnership with two of the industry's largest players, both of whom represent the top 3 players in the private credit space by both size (AUM) and deal activity.

Overview

We're looking for a Senior DevSecOps Engineer to work closely with our Lead DevSecOps Engineer to improve the security, reliability, infrastructure, deployment, and operational maturity of our platform. This is a hands-on individual contributor role for someone who enjoys building, automating, securing, and improving production systems — not managing a team.

You'll strengthen our CI/CD workflows, AWS infrastructure, observability, SOC 2 readiness, business continuity, disaster recovery, and 24/7 on-call operations. The ideal candidate is experienced, practical, and collaborative — comfortable owning technical workstreams and helping engineering teams ship safely and efficiently.

What You'll Do

Infrastructure & Cloud Engineering

  • Design, build, and improve secure, scalable AWS infrastructure using infrastructure-as-code (Terraform, Pulumi-Python).

  • Improve cloud networking, IAM, secrets management, environment isolation, and secure configuration.

  • Standardize provisioning, access control, auditability, and change management.

  • Troubleshoot infrastructure issues and drive long-term fixes that reduce operational toil.

CI/CD & Developer Experience

  • Build, maintain, and improve secure CI/CD pipelines for application, infrastructure, and platform deployments.

  • Support container-based build and deployment workflows, including rolling updates and rollback strategies.

  • Support Environment as a Service for the engineering and QA teams

  • Reduce deployment friction while maintaining strong security and compliance controls.

Security, Compliance & SOC 2 Type 2

  • Embed security controls into infrastructure, CI/CD pipelines, and cloud operations.

  • Support SOC 2 Type 2 readiness through control implementation, evidence collection, access reviews, and audit support.

  • Manage secrets, IAM, least-privilege access, and vulnerability management across containers, dependencies, and cloud services.

  • Ensure sensitive data is protected across logs, pipelines, monitoring systems, backups, and AI-assisted workflows.

  • Contribute to secure usage patterns for AI/ML tools and services, including data handling, vendor risk, access controls, and model boundary considerations.

Observability, Reliability & On-Call

  • Build and improve observability across logs, metrics, dashboards, and alerts; maintain centralized logging pipelines.

  • Define and maintain SLOs, SLIs, alerting standards, and escalation paths.

  • Participate in a 24/7 production on-call rotation; support incident response, root-cause analysis, and postmortems.

  • Create and maintain runbooks, playbooks, and operational documentation.

Business Continuity & Disaster Recovery

  • Design, document, and improve BC/DR plans; support RTO/RPO planning for critical systems.

  • Implement and test backup, restore, replication, failover, and recovery procedures.

  • Identify single points of failure and drive remediation across infrastructure, data stores, and operational processes.

What We're Looking For

Experience & Technical Skills

  • 6+ years in DevOps, DevSecOps, SRE, platform engineering, infrastructure, or security engineering.

  • Strong hands-on AWS experience, including IAM, networking, logging, monitoring, and secure access patterns.

  • Solid CI/CD pipeline development and release automation experience; container build and deployment workflows.

  • Infrastructure-as-code with Terraform and/or Pulumi (Python); strong scripting in Python, Bash, or similar.

  • Strong Ubuntu/Linux command-line experience.

  • Strong networking fundamentals, including VPCs, DNS, TLS, routing, firewalls/security groups, load balancing, and private connectivity.

  • Observability tooling: logs, metrics, dashboards, alerts, and operational visibility.

  • Experience with secrets management, IAM, audit logging, vulnerability scanning, and secure configuration.

  • Strong hands-on experience with AI tools (e.g. Claude, ChatGPT) and AI-assisted development workflows, including an understanding of related security and data-handling risks.

  • Experience participating in 24/7 on-call operations and supporting high-reliability production systems.

Security & Compliance

  • Hands-on experience supporting SOC 2 Type 2 and/or ISO 27001 frameworks.

  • Experience implementing controls for access management, change management, incident response, logging, and data protection.

  • Ability to translate compliance requirements into practical, repeatable technical controls.

  • Experience in regulated or security-sensitive environments (fintech, healthcare, enterprise SaaS) is a strong plus.

Reliability & Collaboration

  • Strong understanding of distributed systems, failure modes, and resilience; experience with SLOs/SLIs and incident management.

  • Experience with backup, restore, failover, and disaster recovery procedures; familiarity with RTO/RPO planning.

  • Strong communication skills; comfortable working closely with a technical lead while independently owning deliverables.

  • Able to provide senior-level technical judgment and practical recommendations across DevSecOps, infrastructure, and security decisions.

  • Ownership mindset, strong documentation habits, and comfort operating in high-accountability production environments.

Nice to Have

  • Jenkins, Docker, Kubernetes (including security, admission controls, and network policies).

  • AWS ECS Fargate, CloudWatch, ELK stack, Bedrock, Redis, redshift, and AWS Systems Manager (SSM).

  • Experience with SOC 2 Type 2 audit support and automated compliance evidence collection.

  • Disaster recovery testing, tabletop exercises, and production failover planning.

  • Fintech or other regulated industry background.

  • Bachelor's degree in Computer Science

What We Offer

  • Competitive salary + equity.

  • Healthcare coverage.

  • 401k

HQ

PactFi New York, New York, USA Office

New York, New York, United States, 10016

Similar Jobs

16 Days Ago
Remote
United States
126K-160K Annually
Senior level
126K-160K Annually
Senior level
Big Data • Cloud • Hardware • Software • App development
The Senior DevSecOps Engineer will embed automated security tooling into client environments, assess CI/CD pipelines, and translate security findings into actionable remediation for engineering teams.
Top Skills: Aws Secrets ManagerBicepCheckovCi/Cd PlatformsClairCloudFormationDastGrypeHashicorp VaultOwasp ZapPipeline-As-CodeSastSca ToolingSemgrepSnykSonarqubeTerraformTrivyVeracode
5 Days Ago
Remote
USA
Senior level
Senior level
News + Entertainment
Design and implement security guardrails across AWS and GCP, embed policy-as-code in Terraform, integrate security into CI/CD, build detection and SOAR playbooks, lead threat modeling, and partner with engineering to reduce MTTD/MTTR and scale compliance.
Top Skills: AWSAws Secrets ManagerAzure AdCi/CdCrowdstrikeDastDependency ScanningEdr/XdrElastic SiemGCPGcp Secret ManagerGithub ActionsGoogle WorkspaceIntuneJAMFMicrosoft DefenderMitre Att&CkOktaPythonSastScimSentineloneSIEMSoarSsoTerraformVault
10 Days Ago
Remote
USA
110K-124K Annually
Senior level
110K-124K Annually
Senior level
Information Technology • Consulting
Support secure, mission-critical federal platforms by designing and operating CI/CD pipelines, containerized workloads (Kubernetes), secure artifact management, cloud (AWS) deployments, observability, and access controls. Collaborate with developers, data scientists, and government stakeholders to enable secure experimentation, automation, and scale from IL2 to IL4+ environments.
Top Skills: Artifact RepositoriesAWSCi/CdContainerizationDatadogElastic CloudGitlab CiIamKubernetesService-To-Service AuthenticationSsoToken-Based AuthenticationVs Code

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account