Principal DevSecOps Engineer
(5+ years exp)![Avatar for Upgrade](/cdn-cgi/image/width=112,height=112,fit=scale-down,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/3827773-9c488103652f45b529b70e568040df33-medium_jpg.jpg)
Upgrade
Job Location
Job Type
Full TimeVisa Sponsorship
AvailableHires remotely in
Relocation
AllowedHiring contact
Jennifer MonteroThe Role
Upgrade is a fintech unicorn backed by a top 10 global bank and other leading fintech investors. Founded in 2017, Upgrade has already delivered $4 billion in consumer credit and achieved $125 million in annual revenue run rate and cash profitability.
Upgrade is building a neobank offering exceptional value to mainstream consumers, including affordable and responsible credit through cards and loans. In 4 short years 10 million people have already applied for an Upgrade Card or loan.
Upgrade has been named a “Best Place to Work in the Bay Area” by the San Francisco Business Times and Silicon Valley Business Journal 3 years in a row, and received “Best Company for Women” and “Best Company for Diversity” awards from Comparably.
We are looking for new team members who get excited about designing and implementing new and better products to join a team of over 400 talented and passionate professionals. Come join us if you like to tackle big problems and make a meaningful difference in people's lives.
Responsibilities:
- Lead the security strategy governing the applications and cloud-based platform infrastructure.
- Collaborate with other infrastructure, DevOps, InfoSec and application engineers to understand the product, technology and business needs.
- Define and own guidance, alerts and security as code deployments to provide protection from malicious traffic, vulnerabilities and other attack vectors.
- Oversee building and maintaining an AWS cloud infrastructure architecture aligning security, compliance, performance and resilience.
- Own the management and remediation of identified security flaws within our development platforms.
- Build and maintain monitoring, auditing, and reporting frameworks that produce artifacts that support security and compliance needs.
- Architect procedures to automate security tasks which seamlessly integrate into code builds and deployments.
- Build security utilities and tools for internal use that enable the DevSecOps team to operate at high speed and wide scale.
- Develop security and compliance capabilities in support of DevOps processes.
- Create and maintain documentation for security systems.
- Participate in an on-call rotation for 24x7 support of security operations.
- Research security industry trends and best practices to share with the organization through presentations and training sessions.
You are:
- Highly motivated and self driven.
- Enjoy collaborating and working in small teams and cross teams.
- Technically strong and hands-on.
- Good at multitasking and thrive in fast-paced environments.
- Methodical, thorough, and solution oriented.
- Enjoy learning new technologies and applying that to solving problems.
- Excellent written and verbal communication skills.
Requirements:
- At least 5+ years of relevant experience in modern DevSecOps space.
- Expert level understanding of security best practices for client-server product architectures for cloud-based deployments.
- In-depth knowledge of AWS services and hands-on experience.
- Experience in performing security vulnerability assessments, good familiarity with PCI and SOX.
- Knowledge of SSO methodologies (SAML, LDAPS, AD).
- Experience in DevOps environments and maintaining security in CI/CD processes.
- Experience in HashiCorp Vault.
- Experience with Kubernetes and containerized applications.
- Experience developing infrastructure as code (Terraform, Ansible).
- Experience designing processes around DevSecOps tools.
- Experience with cloud-based security management/IDS/IPS/SIEM tools (WAF, Inspector, GuardDuty, Twistlock, Splunk, Dome9, AlienVault, AlertLogic, Fortinet, Threat Stack, Sumologic, Imperva etc).
- Knowledge of network based, system level, and application layer attacks and mitigation methods.
- Experience extracting security data from SIEM solutions, audit logs.
- Strong programming/scripting knowledge - Go, Python, Bash, etc.
Strong Plus:
- Experience in OOP, TDD, design patterns, data structures and software security.
- Experience with other IaaT platforms.
- One or more recognized security and cloud specific certifications (e.g. CCSP, SSCP, CISSP, CCSK, GWAP, AWS Solutions Architect).
Benefits/Perks
Competitive salary and stock option plan.
100% paid coverage of medical, dental and vision insurance.
Unlimited vacation.
Learning stipend for personal growth and development.
Paid parental leave.
More about Upgrade
Similar Jobs
![Give Lively company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/884834-fdc26a8044cb1d61fcd6cf6c82a34f0f-medium_jpg.jpg)
![Stonks company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/7641023-67bf91ba0e7f458607f981d1813d0ef8-medium_jpg.jpg)
![Recess company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/7899943-34d90c67ee2da636b9fd6f7f55b8c066-medium_jpg.jpg)
![Fusemachines company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/340295-bfee1f393ca0fae5db4700aad3c9a8a0-medium_jpg.jpg)
![Current company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/1000646-c793cd216addcdb8ccec0791b70aa7ba-medium_jpg.jpg)
![Dodgeball company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/8110982-e961bcbbe4b461be0a2f801a5eb14a44-medium_jpg.jpg)
![kimkim company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/1024253-c29f8e5df6608ba486cd5fe4ff9ae080-medium_jpg.jpg)
![Kero Sports company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/8415464-46a6163dd8d2313b30ffbc027a4cc391-medium_jpg.jpg)
![Gridspace company logo](/cdn-cgi/image/width=128,height=128,fit=contain,gravity=0.5x0.5,quality=90,format=auto/https://photos.wellfound.com/startups/i/523636-8ca98db90c0b0c48665b4aa67f977e5f-medium_jpg.jpg)