Senior DevSecOps Engineer @Echelon Risk + Cyber
Devops
Salary unspecified
Remote Location
Employment Type full-time
Posted 4wks ago

[Hiring] Senior DevSecOps Engineer @Echelon Risk + Cyber

4wks ago - Echelon Risk + Cyber is hiring a remote Senior DevSecOps Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Mexico

Role Description

Senior DevSecOps Engineer with deep expertise in Microsoft Azure to embed security into every stage of our software development lifecycle. You'll design and maintain secure, automated CI/CD pipelines, harden cloud infrastructure, and act as the bridge between our development, operations, and security teams. This is a hands-on engineering role for someone who thinks like an attacker, builds like a developer, and operates like an SRE.

Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.

This is a remote position from anywhere in Mexico.

What You Will Do:

  • Design, build, and maintain secure CI/CD pipelines in Azure DevOps / GitHub Actions, integrating SAST, DAST, SCA, and container scanning at every stage.
  • Architect and manage secure infrastructure-as-code (IaC) using Terraform, Bicep, or ARM templates, applying security-by-design principles.
  • Implement and manage Azure security services: Microsoft Defender for Cloud, Azure Sentinel, Azure Key Vault, Azure Policy, Azure AD (Entra ID) Conditional Access, and Network Security Groups.
  • Automate vulnerability management, patching workflows, and compliance checks across cloud and hybrid environments.
  • Collaborate with development teams to shift security left - embedding threat modeling, secure coding practices, and secrets management into daily workflows.
  • Build and maintain container security practices for AKS (Azure Kubernetes Service), including image scanning, admission controls, and runtime protection.
  • Lead incident response efforts related to pipeline, cloud, or infrastructure security events.
  • Develop and enforce IAM best practices, least-privilege access models, and secrets rotation policies (Key Vault, Managed Identities).
  • Create and maintain security monitoring, logging, and alerting using Azure Monitor, Log Analytics, and SIEM integrations.
  • Mentor junior engineers and evangelize DevSecOps culture and practices across engineering teams.
  • Stay current on emerging threats, Azure security features, and industry compliance frameworks (SOC 2, ISO 27001, NIST, CIS Benchmarks).

Qualifications

  • 5+ years of experience in DevOps/DevSecOps roles, with 3+ years focused specifically on Microsoft Azure.
  • Proven experience building and securing CI/CD pipelines (Azure DevOps, GitHub Actions, or similar).
  • Strong hands-on experience with Azure security tooling: Defender for Cloud, Sentinel, Key Vault, Azure Policy, Entra ID/Azure AD.
  • Proficiency with Infrastructure-as-Code (Terraform, Bicep, or ARM templates).
  • Experience with containerization and orchestration (Docker, AKS/Kubernetes) and associated security controls.
  • Solid scripting/automation skills (PowerShell, Python, or Bash).
  • Working knowledge of security scanning tools (e.g., Trivy, Snyk, SonarQube, Checkmarx, Qualys, or similar).
  • Understanding of network security fundamentals (NSGs, firewalls, VPNs, private endpoints).
  • Familiarity with compliance/regulatory frameworks (SOC 2, ISO 27001, NIST, CIS, GDPR as applicable).
  • Excellent communication skills, able to translate security risk into business terms for both technical and non-technical stakeholders.
  • Strong English communication (C1/C2 Level) written and verbal.
  • Authorized to work in Mexico without visa sponsorship.

Preferred Qualifications

  • Azure certifications: AZ-400 (DevOps Engineer Expert), AZ-500 (Security Engineer Associate), or SC-100 (Cybersecurity Architect Expert).
  • Industry certifications: CISSP, CISM, CEH, or OSCP.
  • Experience with policy-as-code (OPA/Gatekeeper, Azure Policy).
  • Background in threat modeling (STRIDE, DREAD) and secure SDLC frameworks (OWASP SAMM, BSIMM).
  • Experience working in regulated industries (finance, healthcare, government).
  • Prior experience leading a security tooling migration or DevSecOps transformation initiative.

Benefits

  • Access to private medical insurance through MetLife.
  • Life insurance policy via MetLife.
  • 30-day Christmas bonus and a monthly technology stipend.
  • Contribution of 8% of the employee's salary to a savings fund.
  • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
  • Family-friendly benefits, extended parental leave for when you need to spend critical time with new family members, and employer-paid short-term and long-term disability.
  • Support for individual development through certifications, continued learning, conferences, and more.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Mexico
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior DevSecOps Engineer @Echelon Risk + Cyber
Devops
Salary unspecified
Remote Location
Employment Type full-time
Posted 4wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Mexico
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,048+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later