Raya Logo

Raya

DevSecOps Engineer

Reposted One Month Ago
Remote
Hiring Remotely in USA
160K-190K Annually
Mid level
Remote
Hiring Remotely in USA
160K-190K Annually
Mid level
Own and harden cloud-native security across AWS/EKS and related systems. Triage and remediate scanner findings, embed security checks into CI/CD and PDLC, collaborate with DevOps and engineering, and expand guardrails to make security native to shipping workflows.
The summary above was generated by AI
We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya's vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you're excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings. 
 

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya's infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner's mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don't recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You're able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a "perfect" fix

Similar Jobs

28 Days Ago
Remote or Hybrid
USA
Senior level
Senior level
Software
Lead DevSecOps role focused on embedding application security into the SDLC: implement SAST/DAST/SCA and secrets management, secure Azure deployments, integrate security into CI/CD, manage vulnerabilities and compliance, mentor teams, and automate secure infrastructure with IaC (Terraform).
Top Skills: Api SecurityAquaAzureAzure DevopsAzure Key VaultAzure Security CenterBlack DuckBurp SuiteCheckmarxCi/CdDastGithub Advanced SecurityHashicorp VaultMendMicroservicesOwasp ZapPrisma CloudSastScaSecrets ManagementSemgrepSnykSonarqubeTerraformVeracodeWiz
An Hour Ago
Remote
United States
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Cybersecurity
Supports secure software delivery by maintaining GitLab CI/CD pipelines, Kubernetes and Helm deployments, containerized environments, and security tooling. Troubleshoots build and deployment issues, integrates Fortify and SonarQube scans, collaborates with Angular and Java development teams, and creates runbooks and system documentation. Contributes to DevSecOps improvements, quality gates, tool evaluation, and onboarding. The role requires an active Secret clearance, Security+ CE, and experience with Linux, Bash, Kubernetes, Docker, and CI/CD automation.
Top Skills: AngularAWSBashDisa StigsDockerFortifyGitlab Ci/CdHelmJavaKubernetesLinuxRmfSonarqubeSpring BootTypescript
An Hour Ago
Remote
United States
110K-115K Annually
Senior level
110K-115K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Cybersecurity
Leads secure CI/CD, containerized deployments, and infrastructure automation for DoD case management systems in AWS GovCloud. Builds pipelines using Docker, Kubernetes, and Terraform or CloudFormation; integrates security scanning, monitoring, vulnerability management, and compliance checks aligned with RMF and DISA STIGs. Supports Zero Trust architecture, incident response, scalability, ATO documentation, and secure repository management while collaborating with engineering, development, cybersecurity, and systems administration teams.
Top Skills: AcasAgileAmazon GuarddutyAws CloudformationAws CloudwatchAws CodecommitAws CodepipelineAws GovcloudBashCi/CdDisa StigDockerElk StackGitlab CiHelmJenkinsKubernetesNessusPowershellPrometheusPythonRmfTerraformZero Trust

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account