xelys jobs xelys jobs

Software Engineer (DevSecOps)

Sift

full-remoteseniorpermanentdevopssecurity Full remote 66 days ago via WTTJ

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

AWSTerraformKubernetesCI/CDDevSecOpsSOC 2FedRAMPPolicy-as-CodeSecurity AutomationIncident Response

About the role

Role overview

You’ll be a Software Engineer specializing in DevSecOps, defining and implementing security posture, architecture, and practices for Sift’s products and infrastructure. You’ll build controls, automate compliance, and own security posture end-to-end, partnering with infrastructure/platform engineering and external compliance specialists.

Key missions

  • Define security posture, security architecture, and security practices for products and infrastructure
  • Build technical controls and automate compliance via continuous, production-grade processes
  • Strengthen cloud-native systems and implement access controls with engineering partners

Responsibilities

  • Own security posture end-to-end and set security standards
  • Embed security directly into Infrastructure as Code, container platforms, and CI/CD workflows
  • Drive incident response and support change management
  • Collaborate with compliance specialists to map and implement frameworks (e.g., SOC 2, FedRAMP)

Requirements

  • Proven track record shipping production-grade security automation in cloud-native environments (AWS strongly preferred)
  • Deep experience implementing technical controls for SOC 2, FedRAMP, or similar frameworks in real production systems (not just compliance program management)
  • Experience with incident response and change management
  • Founding/early builder mindset: comfort operating in ambiguity; ability to own standards end-to-end
  • Hands-on Infrastructure as Code (Terraform or equivalent), Kubernetes, and CI/CD with security embedded into pipelines
  • 4–7+ years of hands-on experience in security engineering, platform/DevSecOps, or cloud infrastructure

Security domains (expected)

  • Vulnerability scanning, policy-as-code, and continuous compliance
  • Scripting/automation: Python, Go, Bash (or similar) and building custom tooling
  • Encryption, key management, and secrets handling
  • Access control, identity management, and least privilege
  • Logging, monitoring, auditing, and security observability

Eligibility

  • U.S. Person required: Must be a U.S. citizen, lawful permanent resident, or protected individual (asylee/refugee) to comply with ITAR/EAR regulations.

About Sift

Sift is a company building products and infrastructure where security posture and cloud-native engineering practices are critical. The role focuses on designing and implementing security automation, controls, and compliance processes across their products and infrastructure.

Scraped 5/20/2026