waypointjobs

Istari Digital

DevSecOps Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

We are seeking a DevSecOps Engineer to join our Engineering team. This role is critical to securing, hardening, and scaling the infrastructure that powers our platform across cloud-hosted production environments.

This engineer will work closely with platform, infrastructure, and security stakeholders to improve the security and operational maturity of our AWS and Kubernetes environments, support compliance and audit readiness, and help ensure our systems are reliable, secure, and maintainable as we grow. This role will also support environments serving regulated and security-sensitive customer needs, including an environment we host for a Government organization.

The ideal candidate combines strong hands-on infrastructure expertise with sound security judgment and a practical, execution-focused mindset. They should be comfortable working across cloud infrastructure, Kubernetes, operating systems, compliance controls, and production operations.

Core Responsibilities

Responsibilities include collaborating with the platform and engineering teams to secure and improve production infrastructure, harden cloud and host configurations, and build repeatable operational practices across environments. Key responsibilities include:

Design, implement, and maintain secure, scalable infrastructure in AWS

Manage, secure, and improve Kubernetes-based environments, including production workloads

Build and maintain infrastructure as code using Terraform

Harden production systems across cloud, compute, container, identity, and network layers

Develop and maintain secure baseline configurations for infrastructure and platform services

Support vulnerability management, patching, remediation, and configuration compliance efforts across environments

Configure, administer, and patch both Linux and Windows VMs

Support identity and access management practices, including least privilege, role design, and privileged access controls

Contribute to administration and integration of Active Directory domains where needed

Partner with engineering teams to improve security within CI/CD pipelines, deployment workflows, and operational processes

Support compliance initiatives, audits, evidence collection, and technical control validation

Develop and maintain documentation, operational runbooks, technical standards, and playbooks

Monitor, troubleshoot, and resolve complex infrastructure and security issues with clear and timely communication

Participate in incident response and post-incident analysis when infrastructure or platform issues arise

Stay current on cloud, infrastructure, and security best practices that can improve platform resilience and delivery

Required Qualifications

Minimum of 5 years of experience in DevOps, DevSecOps, Infrastructure Engineering, Platform Engineering, or Security Engineering

Strong hands-on experience with AWS in production environments

Proven experience with Kubernetes, preferably in production

Strong experience with Terraform and infrastructure-as-code practices

Experience hardening production environments and implementing secure configuration standards

Experience supporting compliance frameworks, audit preparation, evidence gathering, and control validation

Experience with vulnerability remediation, system patching, and operational security practices

Experience configuring and maintaining both Linux and Windows virtual machines

Strong understanding of IAM, secrets management, network security, logging, monitoring, and operational controls

Proven experience improving or securing CI/CD pipelines and deployment workflows

Excellent troubleshooting and problem-solving skills in complex production environments

Strong communication skills with the ability to explain technical concepts to both technical and non-technical stakeholders

Must live/work in the U.S.

Preferred Qualifications

Experience supporting environments with regulated, compliance-driven, or security-sensitive requirements

Familiarity with compliance or security frameworks such as SOC 2, NIST, ISO 27001, CMMC, or similar

Experience with EKS or other managed Kubernetes platforms

Experience configuring or supporting Active Directory Domain Services, Group Policy, or hybrid identity environments

Experience with automation and configuration management tools such as Ansible, PowerShell, or similar

Experience with PostgreSQL, cloud storage platforms, and production networking patterns

Scripting experience in Python, Bash, or PowerShell

Experience with security tooling related to container security, vulnerability management, or policy enforcement

Experience supporting customer-facing or mission-critical production infrastructure

Security+ Certification

Top Secret Security Clearance

About Istari Digital

Istari is a digital engineering software company building open, scalable infrastructure for engineering data. Our platform lets customers simply and securely integrate engineering models across disciplines, organizations, and security levels — whether they're designing prototypes, performing virtual testing, or training AI and autonomy for complex systems.

Focus is rewarded. Finish is remembered.

Facts are friendly. Even when they are not fun.

Fellowship is fundamental. Make others successful.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job