Software Engineer (DevSecOps)
Sift
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role overview
You’ll be a Software Engineer specializing in DevSecOps, defining and implementing security posture, architecture, and practices for Sift’s products and infrastructure. You’ll build controls, automate compliance, and own security posture end-to-end, partnering with infrastructure/platform engineering and external compliance specialists.
Key missions
- Define security posture, security architecture, and security practices for products and infrastructure
- Build technical controls and automate compliance via continuous, production-grade processes
- Strengthen cloud-native systems and implement access controls with engineering partners
Responsibilities
- Own security posture end-to-end and set security standards
- Embed security directly into Infrastructure as Code, container platforms, and CI/CD workflows
- Drive incident response and support change management
- Collaborate with compliance specialists to map and implement frameworks (e.g., SOC 2, FedRAMP)
Requirements
- Proven track record shipping production-grade security automation in cloud-native environments (AWS strongly preferred)
- Deep experience implementing technical controls for SOC 2, FedRAMP, or similar frameworks in real production systems (not just compliance program management)
- Experience with incident response and change management
- Founding/early builder mindset: comfort operating in ambiguity; ability to own standards end-to-end
- Hands-on Infrastructure as Code (Terraform or equivalent), Kubernetes, and CI/CD with security embedded into pipelines
- 4–7+ years of hands-on experience in security engineering, platform/DevSecOps, or cloud infrastructure
Security domains (expected)
- Vulnerability scanning, policy-as-code, and continuous compliance
- Scripting/automation: Python, Go, Bash (or similar) and building custom tooling
- Encryption, key management, and secrets handling
- Access control, identity management, and least privilege
- Logging, monitoring, auditing, and security observability
Eligibility
- U.S. Person required: Must be a U.S. citizen, lawful permanent resident, or protected individual (asylee/refugee) to comply with ITAR/EAR regulations.
About Sift
Sift is a company building products and infrastructure where security posture and cloud-native engineering practices are critical. The role focuses on designing and implementing security automation, controls, and compliance processes across their products and infrastructure.
Scraped 5/20/2026