Sr. DevSecOps Engineer
Boost your chances before you apply.
ioSENTRIX
US
Summary
Design and maintain secure, scalable AWS and on-premises infrastructure using Infrastructure-as-Code and automation. Implement security controls, vulnerability management, and disaster recovery strategies to ensure operational excellence.
Job Description
Job Title: Senior DevSecOps Engineer
Location: Flexible
Type: Full-Time Contract (40 hours per week)
Role Overview
We are seeking a highly skilled and hands-on DevOps/DevSecOps Engineer to design, implement, and maintain secure, scalable, and highly available infrastructure across AWS and on-premises environments. This role will be responsible for automation, monitoring, security hardening, and disaster recovery, with a strong emphasis on infrastructure-as-code and operational excellence.
The ideal candidate is proactive, automation-driven, and comfortable owning both infrastructure and security responsibilities end-to-end.
Key Responsibilities
Infrastructure & Automation
• Design and manage AWS infrastructure using Infrastructure-as-Code (Terraform)
• Automate configuration management and deployments using Ansible
• Support hybrid environments (AWS + on-prem data center infrastructure)
• Build and maintain CI/CD pipelines for application and infrastructure deployments
Security & DevSecOps
• Implement and manage security tools and controls including:
◦ AWS GuardDuty, WAF, IDS/IPS (e.g., Fortigate)
◦ DLP (Data Loss Prevention) solutions (Macie)
• Manage secrets using AWS Secrets Manager and HashiCorp Vault
• Implement and automate certificate lifecycle management (especially on-prem via Ansible)
• Establish vulnerability management processes and automated reporting (Both AWS and OnPrem)
• Design and enforce patch management processes across environments (Both AWS and On-Prem)
• VPN Management ( Setup VPN tunnels, Troubleshoot VPN issues)
Identity & Access Management
• Integrate and manage SSO solutions (Okta)
• Enforce least privilege access controls across systems using IAM roles
Disaster Recovery & Business Continuity
• Design and implement disaster recovery (DR) strategies
• Conduct DR testing and ensure RTO/RPO objectives are met
Monitoring, Alerting & Reliability
• Implement and manage monitoring/alerting using tools such as CloudWatch/NewRelic
• Ensure system availability and performance
• Set up proactive alerting for applications, APIs, and infrastructure
• Lead incident response and root cause analysis
Technical Requirements
Must-Have Skills:
• Strong hands-on experience with AWS (ECS, networking, security, cloud watch, Aurora RDS)
• Expertise in Terraform (infrastructure provisioning at scale)
• Experience with Ansible for automation and configuration management
• Experience with monitoring tools such as New Relic and CloudWatch
• Strong understanding of security best practices in cloud and hybrid environments
Experience with:
◦ AWS Secrets Manager
◦ HashiCorp Vault
◦ Ansible automation
• Hands-on experience with:
◦ WAF, IDS/IPS, GuardDuty, Fortigate (or similar)
◦ Vulnerability management and patching processes (Nessus Pro)
• Experience implementing SSO solutions (Okta)
• Familiarity with DLP tools and implementations
Programming/Scripting:
• Proficiency in Python and Java
• Strong scripting skills (Bash or similar)
Nice-to-Have
• Experience in healthcare or compliance-driven environments (HIPAA, SOC 2, HITRUST)
• Experience with containerization (Docker, ECS)
• Experience with SIEM tools and centralized logging
Key Traits
• Hands-on and execution-focused (not just architectural)
• Strong automation mindset
• Security-first approach (DevSecOps mentality)
• Ability to work across teams (Development, Operations, Security)
• Comfortable working in both cloud and on-prem environments
ioSENTRIX is a Cybersecurity Consulting firm.
Right now, a lot of businesses are looking at ioSENTRIX because they're faced with growing fears of data breaches and committed to protecting their customer's data from hackers and ransomware. We are helping a good number of companies who are concerned their current cybersecurity posture may no longer be adequate.
Here’s who we work with:
• CISOs and Deputy CISOs – Do you struggle to ensure that your organization and/or customer’s data is secure? We offer vulnerability assessment, penetration testing, and Fullstack assessments to uncover the hidden vulnerabilities and measure the effectiveness of implemented security controls.
• VP/Director/Head of Product Development – Is your team producing software, but you don’t know if it’s secure or not? We can help integrate security into you SDLC whether waterfall or agile to ensure defense in depth. Whether you are building one product or suites of products, we can design an application security program that fits your organization needs.
• Manager/Sr. Managers – Are you migrating to Cloud? Do you need to know whether server-side encryption is better or client-side encryption to protect your data? We offer Secure Design Reviews that evaluate flaws in your application’s architecture and propose remediation strategies to mitigate the outstanding risks.
• Innovators – Are you looking to build a serverless solution for your company? Have you developed a complex Thick Client solution such as virtual appliance, security device, medical device, a mobile application such as MDM or Cloud Solution such as online call center? We can help secure your application and infrastructure with our custom consulting services ranging from secure code review to DDOS testing.
If you are interested in cybersecurity consulting services such as penetration testing, vulnerability assessment, and training, email us at [email protected]
Founded
2017
Company size
11-50 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Herndon, Virginia
ioSENTRIX is a Cybersecurity Consulting firm.
Right now, a lot of businesses are looking at ioSENTRIX because they're faced with growing fears of data breaches and committed to protecting their customer's data from hackers and ransomware. We are helping a good number of companies who are concerned their current cybersecurity posture may no longer be adequate.
Here’s who we work with:
• CISOs and Deputy CISOs – Do you struggle to ensure that your organization and/or customer’s data is secure? We offer vulnerability assessment, penetration testing, and Fullstack assessments to uncover the hidden vulnerabilities and measure the effectiveness of implemented security controls.
• VP/Director/Head of Product Development – Is your team producing software, but you don’t know if it’s secure or not? We can help integrate security into you SDLC whether waterfall or agile to ensure defense in depth. Whether you are building one product or suites of products, we can design an application security program that fits your organization needs.
• Manager/Sr. Managers – Are you migrating to Cloud? Do you need to know whether server-side encryption is better or client-side encryption to protect your data? We offer Secure Design Reviews that evaluate flaws in your application’s architecture and propose remediation strategies to mitigate the outstanding risks.
• Innovators – Are you looking to build a serverless solution for your company? Have you developed a complex Thick Client solution such as virtual appliance, security device, medical device, a mobile application such as MDM or Cloud Solution such as online call center? We can help secure your application and infrastructure with our custom consulting services ranging from secure code review to DDOS testing.
If you are interested in cybersecurity consulting services such as penetration testing, vulnerability assessment, and training, email us at [email protected]
Founded
2017
Company size
11-50 employees
Industry
Computer and Network Security
Org type
Privately Held
Headquarters
Herndon, Virginia