Role Description
The DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.
Responsibilities
-
Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications
-
Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments
-
Deliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation
-
Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation
-
Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools
-
Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply
-
Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence
-
Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification
-
Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows
-
Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams
-
Perform security impact analysis for production changes and maintain pre-production security deployment checklists
-
Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews
Qualifications
-
Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience
-
At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering
-
Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language
-
Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting
-
Experience using Terraform or a similar infrastructure as code platform in production environments
-
Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration
-
Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation
-
Experience with scripting and automation using Python, shell, SQL, or similar tools
-
Experience working in regulated or compliance-driven environments preferred
-
Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks
-
Familiarity with FIPS 140-2 or FIPS 140-3 requirements preferred
-
Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling preferred
-
Experience operating in a private equity-backed or high-growth environment preferred
-
Preferred: CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification
Skills
-
Ability to translate security and compliance requirements into practical engineering changes and implement them directly
-
Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs
-
Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks
-
Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams
-
Self-directed with strong follow-through in a fast-paced, deadline-driven environment
-
Ability to work individually as well as collaboratively across technical and business teams
-
Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification
Benefits
-
Employer Paid Life & Health Insurance
-
Competitive Bonus Structure
-
Home Office Reimbursement
-
Technology Allowance
-
Certification Reimbursement
-
Discount Loyalty Program
-
Personalized Career Coaching
-
Generous Paid Time Off
-
Paid Office Closure December 25-January 1
-
Summer Hours