Jobiglo

No results.

Dev Sec Ops Engineer

peek

New Remote
Remote Mid 🇬🇧 English
GCP AWS Kubernetes GKE EKS IAM RBAC WAF Cloud Armor Cloudflare Trivy AWS Inspector Amazon ECR scanning GCP Artifact Analysis ZAP Python Bash GitLab CI GitHub Actions Jenkins Codefresh PCI DSS SOC 2 Drata

Job description

About the role

Peek is seeking a hands‑on DevSecOps Engineer to embed security into its cloud infrastructure, CI/CD pipelines, and overall development lifecycle. The role is fully remote, supporting a fast‑growing experiences platform that must stay PCI DSS 4.0 and SOC 2 Type II compliant.

Key responsibilities

  • Own and implement technical security controls across GCP and AWS, including least‑privilege IAM, RBAC, WAF, and container image security.
  • Drive end‑to‑end vulnerability remediation: triage, prioritize, automate fixes, and coordinate production roll‑outs with the DevOps team.
  • Build automated scanning and remediation into CI/CD pipelines using tools such as Trivy, AWS Inspector, and GCP Artifact Analysis.
  • Run PCI DSS vulnerability scans, manage quarterly external ASV scans, and produce evidence for compliance platforms like Drata.
  • Contribute to incident‑response planning, disaster‑recovery testing, and ensure backup processes meet encryption and integrity requirements.

Required profile

  • 3+ years of experience in DevSecOps, cloud security, or a closely related engineering role.
  • Hands‑on experience securing GCP and/or AWS environments, including managed Kubernetes (GKE or EKS).
  • Comfortable communicating technical controls to auditors and non‑technical stakeholders.
  • Ability to work across time zones (UTC‑10 to UTC‑4) and occasionally outside normal business hours for infrastructure upgrades.

Required skills

  • GCP and AWS cloud platforms, IAM, RBAC, and WAF configuration (Cloud Armor, AWS WAF, Cloudflare).
  • Kubernetes orchestration and container image scanning (Trivy, Amazon ECR scanning, GCP Artifact Analysis, ZAP).
  • Scripting in Python or Bash for automation.
  • CI/CD pipeline tools such as GitLab CI, GitHub Actions, Jenkins, or Codefresh.
  • Experience with PCI DSS, SOC 2 compliance, and evidence generation for platforms like Drata.

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec peek.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 12 hours ago

Expires 1 month from now

5 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

peek