DevSecOps Engineer
Cedar Rapids, IA
Full Time
Mid Level
Job Title: DevSecOps Engineer
Department: Engineering
Reports To: Vice President of Engineering
Location: Remote (or Cedar Rapids, IA / Leesburg, VA / Columbia Falls, MT)
Job Summary
The DevSecOps Engineer is responsible for maintaining, operating, and optimizing cloud infrastructure while implementing and enforcing security policies developed by the CISO. This role is primarily a DevOps and cloud operations position with a strong operational security component. The DevSecOps Engineer will maintain AWS cloud services, manage deployments using internal tooling, perform cost controls, and implement security controls and compliance processes as directed by the CISO.
The DevSecOps Engineer will work closely with the Aviation Networks team and the CISO to embed security throughout the infrastructure and deployment lifecycle. This is a hands-on implementation role: the CISO defines security policies and compliance requirements, and the DevSecOps Engineer puts them into practice across the cloud environment. Deployment automation is managed through an internal deployment system maintained by a dedicated engineer; this role focuses on cloud operations, security implementation, and infrastructure reliability rather than deployment pipeline development.
Key Responsibilities
Bonus Range: 7.5% - 12.5%
Department: Engineering
Reports To: Vice President of Engineering
Location: Remote (or Cedar Rapids, IA / Leesburg, VA / Columbia Falls, MT)
Position Type: Full Time, Salaried, Exempt, IC3
Job Summary
The DevSecOps Engineer is responsible for maintaining, operating, and optimizing cloud infrastructure while implementing and enforcing security policies developed by the CISO. This role is primarily a DevOps and cloud operations position with a strong operational security component. The DevSecOps Engineer will maintain AWS cloud services, manage deployments using internal tooling, perform cost controls, and implement security controls and compliance processes as directed by the CISO.
The DevSecOps Engineer will work closely with the Aviation Networks team and the CISO to embed security throughout the infrastructure and deployment lifecycle. This is a hands-on implementation role: the CISO defines security policies and compliance requirements, and the DevSecOps Engineer puts them into practice across the cloud environment. Deployment automation is managed through an internal deployment system maintained by a dedicated engineer; this role focuses on cloud operations, security implementation, and infrastructure reliability rather than deployment pipeline development.
Key Responsibilities
- Maintain and optimize AWS cloud infrastructure, including cost analysis, resource right-sizing, and budget forecasting
- Manage and execute production deployments using internal deployment tooling, ensuring reliability and reproducibility
- Implement and manage logging, monitoring, and alerting systems for infrastructure and application events
- Collaborate with the deployment tooling engineer to integrate security validation steps into the deployment workflow
- Integrate SAST, DAST, and SCA tooling into the deployment process to enforce automated security validation, following policies established by the CISO
- Configure and maintain endpoint security, identity and access management (IAM), and secrets management across all environments per CISO-defined security policies
- Deploy and maintain cloud-native security tooling to continuously monitor and harden infrastructure in accordance with organizational security standards
- Collaborate with software engineering and security teams to participate in threat modeling and risk assessments, supporting the CISO in evaluating security posture across all phases of the development lifecycle
- Implement and document FISMA and FedRAMP security controls, continuous monitoring processes, and compliance evidence as directed by the CISO
- Work closely with the Aviation Networks team to support infrastructure needs for SAI deployments and FlightLine operations
- Execute security audits, vulnerability assessments, and incident response procedures established by the CISO
- Help define, document, evolve, and evangelize high engineering standards and best practices across multiple areas
- Other related duties as assigned.
- BS in Computer Science, Information Technology, related field or relevant work experience
- 3-7 years of proven experience in DevOps, SRE, or cloud infrastructure engineering roles
- AWS infrastructure experience (EC2, IAM, VPC, S3, CloudWatch, or equivalent cloud services)
- Linux System Administration
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience with deployment automation and reproducible build/release processes
- Experience with logging, monitoring, and observability tools
- Familiarity with compliance or audit processes (SOC 2, FISMA, FedRAMP, or similar frameworks)
- Excellent verbal and written communication skills
- Immediate authorization to work in the US
- Infrastructure as Code (Terraform, Pulumi, Nix, or CloudFormation)
- Ansible or similar configuration management tooling
- Experience with security scanning tools (SAST, DAST, SCA) integrated into deployment workflows
- Familiarity with IAM policies, secrets management, and least-privilege access models
- Container technologies (Docker, ECS, or EKS)
- Familiarity with network security principles, firewalls, and VPN configurations
- Grafana, Prometheus, Loki, or similar observability stack
- NodeJS, Bun, or web application deployment experience
- Experience with cost optimization strategies for cloud resources
- Willingness to learn federal compliance frameworks (FISMA, FedRAMP) and grow into a security-focused role
Physical Requirements
- Prolonged periods sitting at a desk and working on a computer.
- Must be able to lift up to 15 pounds at times.
Career Path
- This role provides foundational experience in cloud infrastructure and security implementation and typically progresses to Senior DevSecOps Engineer or Security Engineer with demonstrated performance, technical growth, and increased security ownership.
Bonus Range: 7.5% - 12.5%
Apply for this position
Required*