DevSecOps Engineer
Changent
full-remotemidpermanentdevopssecurity United States 2 days ago via LinkedIn
82,000 - 98,400 USD/annual
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
AzureAzure DevOpsBicepInfrastructure as Code (IaC)CI/CDRBACAzure Key VaultAzure Entra IDSIEMPowerShell
About the role
DevSecOps Engineer (Remote, U.S.)
Build, secure, and maintain Azure cloud infrastructure with a focus on automation, compliance, and monitoring.
Responsibilities
Cloud Infrastructure Engineering & Automation
- Convert existing Azure resources into modular, reusable Bicep templates
- Develop and maintain Infrastructure as Code (IaC) for core components (VMs, VNets, NSGs, Firewalls, RBAC)
- Build/maintain CI/CD workflows for infrastructure deployments using GitHub or Azure DevOps
- Use safe deployment practices (e.g., “what-if” preview)
- Implement automated patch management for Azure VMs and remote devices
- Maintain standardized golden images for VM provisioning
- Harden identity and infrastructure (e.g., Active Directory, Azure RBAC)
- Evaluate and adopt AI-assisted tools/workflows to improve efficiency and reliability
Security, Compliance & Monitoring
- Use Azure Key Vault for secrets, certificates, and credentials
- Enforce and audit least-privilege access across services and databases
- Configure Conditional Access in Azure Entra ID
- Build monitoring dashboards for patch compliance, health, and security posture
- Integrate SIEM capabilities and support responses to automated alerts/threats
- Support SOC 2-related documentation and customer/security questionnaires
Collaboration, Documentation & Operational Support
- Document infrastructure standards, IaC modules, patching procedures, and access models
- Collaborate across IT, Data Engineering, Analytics, and Security
- Contribute to CI/CD workflows supporting data pipelines and database artifacts
- Cross-train within the DevOps team and provide coverage
Requirements
- 4+ years Azure infrastructure engineering, DevOps, or cloud security
- 3+ years IaC with Bicep, ARM templates, or Terraform
- 3+ years building/maintaining CI/CD pipelines with GitHub or Azure DevOps
- Strong Azure networking knowledge (VNets, NSGs, Firewalls) and RBAC
- Windows Server administration experience and automated patching workflows
- Experience with Azure Key Vault (or similar secrets management)
- Scripting proficiency in PowerShell and/or Azure CLI
- Familiarity with EDR/SIEM tooling (examples mentioned: SentinelOne, “Adlumin…”)
Nice to Have
- Experience integrating AI-driven tools/workflows for automation/monitoring/provisioning
- Experience with SOC 2 compliance processes
Scraped 4/9/2026