Avatar for UsefulBI
Enable Business Decisions
  • B2B
  • Growth Stage
    Expanding market presence

Senior Staff Engineer – DevSecOps

Posted: 1 month ago
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
IT Security
Iaas
Jira
Cloud Security
Network Security
Agile
SDLC
Azure
Application Security
AWS
Cloud Infrastructure
System Security
IAM
GDPR
IaC
Vpc
Zero Trust
DAST
SAST
PHI
CI/CD Pipelines
CPRA
SCA
Github Pipelines
Cybersecurity Tools
PII
Security Groups
Guardrails
Cyber Events
Dependency Scanning
JSM
IT Systems Administration
Incidents
Infrastructure Administration
IaC Patterns
Key Management Services
Golden Paths
Sensitive Data Concepts

About the job

Role: Senior Staff Engineer – DevSecOps

Work Model: Minimum 4 days/week onsite (5 days/week onsite preferred)

Job Summary

We are seeking a Senior Staff Engineer – DevSecOps to lead the design, implementation, and continuous improvement of cloud security and DevSecOps practices across AWS and Azure environments. This role will be responsible for securing cloud infrastructure, embedding security into CI/CD pipelines, leading incident response, and driving security best practices across the organization while ensuring compliance with regulatory standards.

Key Responsibilities

  • Design and implement robust security architectures for cloud environments following best practices, industry standards, and regulatory requirements.
  • Lead cross-functional collaboration on technology initiatives to strengthen security across systems and operations, ensuring alignment with organizational objectives and industry best practices.
  • Lead the investigation and resolution of complex security events and incidents, including malware outbreaks, unauthorized access attempts, and significant security breaches. Develop and implement response strategies, coordinate cross-functional teams, and ensure lessons learned are integrated into security policies and controls.
  • Analyze security logs and events from various sources to proactively develop and implement security measures that address current and emerging threats.
  • Provide updates to leaders on latest threat landscape, emerging trends, and propose cybersecurity solutions to proactively identify and mitigate potential security risks.
  • Enhance the organization’s security posture by assessing vulnerabilities and recommending solutions to address identified weaknesses.
  • Collaborate with internal teams, vendors, and partners to provide guidance and expertise on security best practices and incident response.
  • Ensure compliance with industry standards and organizational policies, including SOX and FDA regulatory requirements, by following established procedures and controls.

Education

  • Bachelor’s degree in related discipline and 9 years of related experience; or

Experience:

  • Experience with operation and implementation of cybersecurity tools.
  • Experience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.
  • Experience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead or management experience preferred.
  • Experience in investigations and response to cyber events and incidents.
  • Experience in enhancing organizational security awareness and resilience.
  • Experience with cloud, system, and application security.
  • Experience administering IT systems.
  • Experience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).
  • Experience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.

Knowledge, Skills and Abilities:

  • Advanced analytical, problem solving, organizational, and communication skills.
  • General knowledge of Agile, and Design-Thinking, User-centric Design methodologies.
  • Able to plan, prioritize, and execute projects with minimum supervision and high reliability.
  • Strong understanding of PII, PHI, and Sensitive Data concepts
  • Knowledge of applicable laws and regulations such as GDPR and CPRA.
  • Strong analytical, problem solving, organizational, and communication skills.
  • Ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.
  • Ability to multitask and work collaboratively.
  • Ability to work with ambiguity.
  • Ability to work with confidential data.
  • Ability to continuously learn and improve.
  • Ability to work with minimal guidance, to adapt to frequent priority changes, and response to ad-hoc requests
  • Architect secure cloud infrastructure using guardrails and golden paths using IaC patterns across AWS and Azure.
  • Integrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines and provide help and support
  • AWS Certified Security - Specialty preferred

About the company

UsefulBI company logo
Enable Business Decisions51-200 Employees
Company Location
San Ramon
Company Size
51-200
  • B2B
  • Growth Stage
    Expanding market presence
Learn more about UsefulBI image

Similar Jobs

Astranis company logo
Astranis
Building next-generation internet satellites to get the world online
Scale AI company logo
Scale AI
Accelerate the development of AI applications
Assured company logo
Assured
Automated claims are now a reality
Orchard Robotics company logo
Orchard Robotics
Securing America's food supply by building the AI farmer that automates our nation's farms
EliseAI company logo
EliseAI
Building AI agents that transform complex healthcare and housing systems
NumeralHQ company logo
NumeralHQ
Sales tax on autopilot for Ecommerce & SaaS ✨ Spend 5 mins or less per month on compliance
C3 AI company logo
C3 AI
C3 AI is a leading enterprise AI software provider for accelerating digital transformation