About this opportunity
NETFORCE Group lists this DevSecOps Engineer (Cloud Security and Compliance) opportunity in northern, Kentucky. Review the employer’s description below for duties, qualifications and application requirements.
Job description
DevSecOps Engineer (Cloud Security and Compliance)
SoftDoes is a U.S.-based custom software development company headquartered in Kansas City, Missouri. We build custom software, SaaS platforms, web and mobile applications, AI solutions, and cloud infrastructure for businesses across industries such as healthcare, fintech, construction, legal, and real estate.We work with modern technologies and focus on solving complex business problems through reliable, scalable software solutions.
SoftDoes is a U.S.-based custom software development company headquartered in Kansas City, Missouri. We build custom software, SaaS platforms, web and mobile applications, AI solutions, and cloud infrastructure for businesses across industries such as healthcare, fintech, construction, legal, and real estate.
We work with modern technologies and focus on solving complex business problems through reliable, scalable software solutions.
About the role
The company is moving deeper into enterprise work. We need a DevSecOps engineer who can help harden our infrastructure, implement security best practices, and drive compliance readiness so we can pass enterprise vendor reviews and pursue certifications like SOC 2 and ISO 27001. You will work closely with engineering and leadership across infrastructure, security, and compliance.
What you will do:
Build and maintain secure cloud infrastructure and CI/CD pipelines
Implement access control, least privilege, and secrets management across environments
Standardize logging, monitoring, alerting, and audit trails
Create and maintain secure SDLC practices, including code scanning, dependency scanning, and change control
Set up incident response basics, including runbooks, on-call expectations, and post-incident process
Compliance readiness for SOC 2 and ISO 27001 by implementing required technical controls and gathering evidence
Vulnerability management and patching routines for infrastructure and dependencies
Improve backup, disaster recovery, and business continuity practices
Support client security questionnaires with clear technical answers and evidence
Requirements:
Up to 2 years of DevSecOps experience with cloud infrastructure and deployment pipelines
Hands-on experience with AWS, including IAM, networking, compute, and logging services
Experience with Infrastructure as Code such as Terraform
Experience with containerization and orchestration, Docker and Kubernetes preferred
Comfort setting up security tooling, SAST, DAST, dependency scanning, secret scanning
Ability to document systems clearly and work with auditors or compliance tools when needed
English at B2 level or higher - you will collaborate directly with US client stakeholders
SOC 2 or ISO 27001 experience, even if you were the technical owner not the compliance PM
Experience with Vanta, Drata, Secureframe, or similar evidence automation tools
Experience working with HIPAA or other regulated client environments
AWS certifications such as Solutions Architect or Security Specialty
What We Offer:
Working hours aligned with US time zones, typically 16:00-23:59 Kyiv time
English lessons to support clear and confident communication
Paid vacation and sick days
Fully remote work
Opportunities for professional growth within the team
Structured, personalized onboarding to help you ramp up effectively
#J-18808-Ljbffr
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.