Role Description
The Cloud DevSecOps Engineer is responsible for keeping our multi-cloud platform fast, reliable, and transparent. This position will own the monitoring stack, automate incident response, and drive performance and cost optimization across production AWS/GCP workloads. Acting as the bridge between engineering, product, and compliance teams, the Cloud Operations and Observability Engineer will surface actionable insights and ensure compliance with relevant SOC 2 controls.
-
Design and maintain secure cloud foundations and shared platform services, including landing zones, IAM/service accounts, workload identity/OIDC, secrets management, network/security controls, and reusable Terraform modules.
-
Partner with DevOps and application teams to enable secure golden-pipeline deployments, troubleshoot infrastructure blockers, and ensure cloud services are provisioned through standardized, repeatable patterns.
-
Implement and maintain cloud security guardrails and policy-as-code, including controls such as Cloud Armor/WAF, least-privilege IAM, secrets rotation, vulnerability remediation, and infrastructure configuration standards.
-
Design, deploy, and maintain observability stacks (Prometheus/Grafana, CloudWatch, Stackdriver, Datadog, or similar).
-
Build and manage CI/CD pipelines and infrastructure-as-code (Terraform, CloudFormation, Pulumi).
-
Automate incident response with runbooks, chat-ops, and auto-remediation scripts (e.g., Lambda, Cloud Functions).
-
Ensure logging, alerting, and backup configurations meet SOC 2 / ISO 27001 controls.
-
Document evidence for audit requests (access reviews, vulnerability scans, disaster-recovery drills).
-
Participate in weekly on-call rotation (pager duty) and drive blameless incident retrospectives.
Qualifications
-
Bachelorβs degree in Computer Science, Engineering, or related field.
-
4+ years professional experience in cloud operations, SRE, or DevOps roles.
-
Hands-on experience with at least one major cloud provider (AWS, GCP, or Azure).
-
Proficiency in scripting or programming (Python, PowerShell, Bash, or similar).
-
Experience deploying and supporting monitoring/alerting platforms (Prometheus, Datadog, Grafana, New Relic, etc.).
Requirements
-
Experience with enterprise IAM, workload identity/OIDC, secrets management, cloud security controls, and Terraform-based landing-zone/platform engineering.
-
Certifications: AWS SysOps Administrator, Google Cloud DevOps Engineer, or Azure Administrator Associate.
-
Familiarity with Kubernetes, service mesh, and distributed tracing (Jaeger, OpenTelemetry).
Benefits
-
Travel Percentage: 10%
-
Pay Ranges:
-
USN: $102,600 - $171,000 USD Annual
-
US5: $107,700 - $179,600 USD Annual
-
US10: $112,900 - $188,100 USD Annual
-
US15: $118,000 - $196,600 USD Annual
-
US20: $123,100 - $205,200 USD Annual
-
US30: $133,400 - $222,300 USD Annual