Senior DevSecOps / Platform Security Engineer
DEFCON AI
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Join DEFCON AI as a Senior DevSecOps / Platform Security Engineer. You’ll be hands-on building and operating production security controls across the company’s AWS and Kubernetes platform, with real ownership of critical platform security capabilities.
Key Missions & Responsibilities
- Design & implement security controls across AWS and Kubernetes, with a focus on:
- CI/CD security automation
- Software supply chain security controls
- Co-own AWS security guardrails and partner with Security/GRC to:
- Interpret controls
- Define/meet evidence requirements
- Embed security into engineering systems and pipelines, implementing controls through engineering workflows
- Developer enablement via:
- Clear documentation
- Lightweight design reviews and threat modeling
- High-signal guidance embedded in tooling
- Build durable, scalable guardrails (templates and controls) that improve delivery outcomes across teams
Requirements
- Scripting/coding proficiency (e.g., Python, Go, Bash) to build integrations, automations, and internal tooling
- 5+ years experience in DevOps/SRE/Platform Engineering and/or Security Engineering, with strong automation and delivery focus
- Ability to communicate risk and tradeoffs clearly and pragmatically to engineers
- Experience integrating security into CI/CD and developer workflows:
- SAST, SCA, secrets scanning, container scanning, IaC scanning
- Strong Kubernetes security experience (e.g., EKS):
- RBAC
- workload hardening
- policy enforcement via admission control
- Infrastructure as Code proficiency (Terraform, CloudFormation, CDK, or Pulumi**) and ability to embed guardrails into IaC workflows
- Hands-on AWS security experience:
- IAM least privilege
- network controls
- encryption (KMS)
- centralized logging and detection
- Agile methodology and comfort with version control tools
- Experience with regulated delivery expectations and evidence-driven control implementation (e.g., NIST SP 800-171 / CMMC)
Nice-to-Haves / Additional Signals
- Build “golden paths” or internal developer platforms to improve both velocity and security outcomes
- Experience with Kubernetes policy-as-code tooling (OPA/Gatekeeper, Kyverno)
- Secure workload identity patterns (OIDC/IRSA)
- Software supply chain security experience (e.g., SBOM, signing/verification like cosign, provenance)
- Strong analytical and problem-solving skills; effective communication across audiences
- Continuous learner mindset and agility in adopting new technologies
Education
Formal education in Computer Science or related fields is a plus, but DEFCON AI emphasizes hands-on experience and demonstrable skills.
About DEFCON AI
DEFCON AI is a technology company focused on building and operating secure cloud and platform capabilities for its products and teams. The role indicates a strong engineering culture around DevSecOps, CI/CD security automation, and software supply chain protections on AWS and Kubernetes.
Scraped 5/12/2026