Job Description

Responsibilities
  • Maintain and strengthen AWS infrastructure, including ECS and EKS, supporting the company's platform.
  • Own automated tests and validation checks that ensure ongoing compliance with security frameworks, including SOC 2 and ISO 27001.
  • Identify and flag security compliance issues while collaborating with the engineering team rather than directly leading audit remediation.
  • Embed security thinking throughout the software development lifecycle.
  • Improve the security, reliability, and scalability of the platform infrastructure.
  • Deliver infrastructure solutions independently with minimal oversight.
  • Collaborate closely with software engineers to enable secure-by-design and dependable software delivery.
  • Make sound technical and infrastructure design decisions while iterating quickly.
  • Take full ownership of infrastructure initiatives and contribute to long-term platform stability.
  • Requirements
  • 5+ years of experience in DevSecOps or a related role.
  • 5+ years of overall DevOps/DevSecOps experience.
  • Strong experience with AWS, including ECS and EKS.
  • Strong experience with Terraform.
  • Strong experience with Kubernetes or container orchestration.
  • Strong experience with Docker.
  • Strong experience with Ansible.
  • Strong experience with Prometheus and Grafana.
  • Strong experience building and maintaining CI/CD pipelines and automation.
  • Good understanding of security best practices and compliance frameworks, including SOC 2 and ISO 27001.
  • Ability to work independently, make technical decisions, and deliver with minimal supervision.
  • Strong problem-solving skills and a product-focused mindset.
  • Experience working in a fast-paced environment.
  • Ability to collaborate effectively with software engineering teams.
  • Nice To Have
  • Experience with EKS specifically.
  • Experience working within a SaaS or technology product company.
  • Previous experience leading infrastructure projects or taking ownership of major infrastructure initiatives.
  • Broader exposure to security and compliance practices beyond core operational responsibilities.