Principal DevSecOps Engineer

 (5+ years exp)
Published: 3 years ago
Avatar for Upgrade

Upgrade

Online Personal Loans and Cards

Job Location

Job Type

Full Time

Visa Sponsorship

Available

Hires remotely in

Relocation

Allowed

Hiring contact

Jennifer Montero

The Role

Upgrade is a fintech unicorn backed by a top 10 global bank and other leading fintech investors. Founded in 2017, Upgrade has already delivered $4 billion in consumer credit and achieved $125 million in annual revenue run rate and cash profitability.

Upgrade is building a neobank offering exceptional value to mainstream consumers, including affordable and responsible credit through cards and loans. In 4 short years 10 million people have already applied for an Upgrade Card or loan.

Upgrade has been named a “Best Place to Work in the Bay Area” by the San Francisco Business Times and Silicon Valley Business Journal 3 years in a row, and received “Best Company for Women” and “Best Company for Diversity” awards from Comparably.

We are looking for new team members who get excited about designing and implementing new and better products to join a team of over 400 talented and passionate professionals. Come join us if you like to tackle big problems and make a meaningful difference in people's lives.

Responsibilities:

  • Lead the security strategy governing the applications and cloud-based platform infrastructure.
  • Collaborate with other infrastructure, DevOps, InfoSec and application engineers to understand the product, technology and business needs.
  • Define and own guidance, alerts and security as code deployments to provide protection from malicious traffic, vulnerabilities and other attack vectors.
  • Oversee building and maintaining an AWS cloud infrastructure architecture aligning security, compliance, performance and resilience.
  • Own the management and remediation of identified security flaws within our development platforms.
  • Build and maintain monitoring, auditing, and reporting frameworks that produce artifacts that support security and compliance needs.
  • Architect procedures to automate security tasks which seamlessly integrate into code builds and deployments.
  • Build security utilities and tools for internal use that enable the DevSecOps team to operate at high speed and wide scale.
  • Develop security and compliance capabilities in support of DevOps processes.
  • Create and maintain documentation for security systems.
  • Participate in an on-call rotation for 24x7 support of security operations.
  • Research security industry trends and best practices to share with the organization through presentations and training sessions.

You are:

  • Highly motivated and self driven.
  • Enjoy collaborating and working in small teams and cross teams.
  • Technically strong and hands-on.
  • Good at multitasking and thrive in fast-paced environments.
  • Methodical, thorough, and solution oriented.
  • Enjoy learning new technologies and applying that to solving problems.
  • Excellent written and verbal communication skills.

Requirements:

  • At least 5+ years of relevant experience in modern DevSecOps space.
  • Expert level understanding of security best practices for client-server product architectures for cloud-based deployments.
  • In-depth knowledge of AWS services and hands-on experience.
  • Experience in performing security vulnerability assessments, good familiarity with PCI and SOX.
  • Knowledge of SSO methodologies (SAML, LDAPS, AD).
  • Experience in DevOps environments and maintaining security in CI/CD processes.
  • Experience in HashiCorp Vault.
  • Experience with Kubernetes and containerized applications.
  • Experience developing infrastructure as code (Terraform, Ansible).
  • Experience designing processes around DevSecOps tools.
  • Experience with cloud-based security management/IDS/IPS/SIEM tools (WAF, Inspector, GuardDuty, Twistlock, Splunk, Dome9, AlienVault, AlertLogic, Fortinet, Threat Stack, Sumologic, Imperva etc).
  • Knowledge of network based, system level, and application layer attacks and mitigation methods.
  • Experience extracting security data from SIEM solutions, audit logs.
  • Strong programming/scripting knowledge - Go, Python, Bash, etc.

Strong Plus:

  • Experience in OOP, TDD, design patterns, data structures and software security.
  • Experience with other IaaT platforms.
  • One or more recognized security and cloud specific certifications (e.g. CCSP, SSCP, CISSP, CCSK, GWAP, AWS Solutions Architect).

Benefits/Perks
Competitive salary and stock option plan.
100% paid coverage of medical, dental and vision insurance.
Unlimited vacation.
Learning stipend for personal growth and development.
Paid parental leave.

More about Upgrade

Perks and Benefits

Healthcare benefits
Generous vacation
Company events
image

Funding

AMOUNT RAISED
$202M
FUNDED OVER
4 rounds
Rounds
D
$40,000,000
Series D Jun 2020
image

Similar Jobs

Give Lively company logo
Give Lively
Reimagining the future of digital fundraising for nonprofits: powerful, practical & free
Recess company logo
Recess
Recess is a fully integrated fitness platform for instructors, gyms, and studios
Current company logo
Current
We're on a mission to change our members lives by creating better financial outcomes
Dodgeball company logo
Dodgeball
Dodge fraud & security issues with one integration
kimkim company logo
kimkim
kimkim is the next generation online travel agent (OTA) to book multi-day custom trips
Kero Sports company logo
Kero Sports
We help fans enjoy watching sports through in-game betting and social experiences
Gridspace company logo
Gridspace
State of the art voice technology and automation for customers, patients, and call centers