Raya Logo

Raya

DevSecOps Engineer

Reposted 3 Days Ago
Remote
Hiring Remotely in USA
160K-190K Annually
Mid level
Remote
Hiring Remotely in USA
160K-190K Annually
Mid level
Own and harden cloud-native security across AWS/EKS and related systems. Triage and remediate scanner findings, embed security checks into CI/CD and PDLC, collaborate with DevOps and engineering, and expand guardrails to make security native to shipping workflows.
The summary above was generated by AI
We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya's vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you're excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings. 
 

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya's infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner's mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don't recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You're able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a "perfect" fix

Similar Jobs

9 Days Ago
Remote or Hybrid
United States
121K-204K Annually
Senior level
121K-204K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead DevSecOps engineer on the Infrastructure and Platform Services team responsible for implementing and operating global SaaS infrastructure security. Duties include file integrity monitoring, automating audit evidence collection, hardening base images, securing containerized applications, release automation, incident response via on-call rotation, and collaborating with engineering and cybersecurity to meet compliance (FedRAMP, ISO, SOC) and remediation SLAs.
Top Skills: AWSAzureChefContainerizationFile Integrity MonitoringIdsIpsJenkinsPuppetPythonRubySIEMSirpTerraformWaf
3 Days Ago
Easy Apply
Remote
United States
Easy Apply
130K-225K Annually
Senior level
130K-225K Annually
Senior level
Artificial Intelligence • Consumer Web • Digital Media • Fintech • Marketing Tech • Software • Financial Services
Lead and build the DevSecOps function: implement SOC 2 controls, automate compliance and evidence pipelines, own cloud security posture, CI/CD security gates, vulnerability management, and AI-assisted auto-remediation to embed security as code across the developer lifecycle.
Top Skills: Ai/LlmAspmCi/CdContainer ScanningCspmDrataIac ScanningIamInfrastructure-As-CodeKey ManagementLoggingMulti-CloudPrisma CloudSastSbomScaSecret ScanningSIEMSnykSoc 2TerraformVantaWiz
Yesterday
In-Office or Remote
120K-160K Annually
Senior level
120K-160K Annually
Senior level
Information Technology • Security
Design, build, and maintain automated CI/CD pipelines and scalable AWS infrastructure; integrate DevSecOps security practices (NIST, DoD SRG); implement monitoring and incident response; mentor engineers; define DevOps strategy, documentation, and deliverables for a large enterprise platform.
Top Skills: AnsibleAWSAws GovcloudCloudwatchDod SrgGitGithub ActionsJenkinsLinuxNistPHPPhp FrameworksPhp Package ManagersRelational DatabasesSonarqubeSplunkTerraform

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account