xelys jobs xelys jobs

Senior DevSecOps / Platform Security Engineer

DEFCON AI

full-remoteseniorpermanentdevopssecurity Full remote 74 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

DevSecOpsAWS SecurityKubernetes SecurityCI/CD SecuritySoftware Supply Chain SecurityTerraformIaC ScanningOPA/GatekeeperKyvernoSAST

About the role

Role Overview

Join DEFCON AI as a Senior DevSecOps / Platform Security Engineer. You’ll be hands-on building and operating production security controls across the company’s AWS and Kubernetes platform, with real ownership of critical platform security capabilities.

Key Missions & Responsibilities

  • Design & implement security controls across AWS and Kubernetes, with a focus on:
    • CI/CD security automation
    • Software supply chain security controls
  • Co-own AWS security guardrails and partner with Security/GRC to:
    • Interpret controls
    • Define/meet evidence requirements
  • Embed security into engineering systems and pipelines, implementing controls through engineering workflows
  • Developer enablement via:
    • Clear documentation
    • Lightweight design reviews and threat modeling
    • High-signal guidance embedded in tooling
  • Build durable, scalable guardrails (templates and controls) that improve delivery outcomes across teams

Requirements

  • Scripting/coding proficiency (e.g., Python, Go, Bash) to build integrations, automations, and internal tooling
  • 5+ years experience in DevOps/SRE/Platform Engineering and/or Security Engineering, with strong automation and delivery focus
  • Ability to communicate risk and tradeoffs clearly and pragmatically to engineers
  • Experience integrating security into CI/CD and developer workflows:
    • SAST, SCA, secrets scanning, container scanning, IaC scanning
  • Strong Kubernetes security experience (e.g., EKS):
    • RBAC
    • workload hardening
    • policy enforcement via admission control
  • Infrastructure as Code proficiency (Terraform, CloudFormation, CDK, or Pulumi**) and ability to embed guardrails into IaC workflows
  • Hands-on AWS security experience:
    • IAM least privilege
    • network controls
    • encryption (KMS)
    • centralized logging and detection
  • Agile methodology and comfort with version control tools
  • Experience with regulated delivery expectations and evidence-driven control implementation (e.g., NIST SP 800-171 / CMMC)

Nice-to-Haves / Additional Signals

  • Build “golden paths” or internal developer platforms to improve both velocity and security outcomes
  • Experience with Kubernetes policy-as-code tooling (OPA/Gatekeeper, Kyverno)
  • Secure workload identity patterns (OIDC/IRSA)
  • Software supply chain security experience (e.g., SBOM, signing/verification like cosign, provenance)
  • Strong analytical and problem-solving skills; effective communication across audiences
  • Continuous learner mindset and agility in adopting new technologies

Education

Formal education in Computer Science or related fields is a plus, but DEFCON AI emphasizes hands-on experience and demonstrable skills.

About DEFCON AI

DEFCON AI is a technology company focused on building and operating secure cloud and platform capabilities for its products and teams. The role indicates a strong engineering culture around DevSecOps, CI/CD security automation, and software supply chain protections on AWS and Kubernetes.

Scraped 5/12/2026