1

Aws Devsecops Engineer Jobs in New York (NOW HIRING)

DevSecOps Engineer

Manhattan, NY ยท On-site

$140 - $195/hr

As a DevSecOps Engineer, you will sit at the intersection of development, security, and operations ... Implement infrastructure security best practices across cloud environments (AWS, GCP, or Azure ...

Senior DevSecOps Engineer

Manhattan, NY ยท On-site

$170 - $230/hr

Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY ยท On-site

$125K - $171K/yr

Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY ยท Hybrid

$125K - $171K/yr

Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

New York, NY ยท Hybrid

$125K - $171K/yr

Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key ... DevSecOps / Cloud Engineering delivering and securing production AWS and Azure environments ...

Senior DevSecOps Engineer

Manhattan, NY ยท On-site

$140 - $190/hr

Overview We're looking for a Senior DevSecOps Engineer to work closely with our Lead DevSecOps ... Design, build, and improve secure, scalable AWS infrastructure using infrastructure-as-code ...

Senior DevSecOps Engineer

New York, NY ยท Remote

$165K - $225K/yr

Overview We're looking for a Senior DevSecOps Engineer to work closely with our Lead DevSecOps ... Design, build, and improve secure, scalable AWS infrastructure using infrastructure-as-code ...

Senior DevSecOps Engineer

New York, NY ยท On-site

$165K - $225K/yr

Overview We're looking for a Senior DevSecOps Engineer to work closely with our Lead DevSecOps ... Design, build, and improve secure, scalable AWS infrastructure using infrastructure-as-code ...

DevSecOps Engineer

New York, NY ยท On-site

$180K - $200K/yr

We're hiring a DevSecOps engineer to own security architecture and practice across our AI and data ... Deep experience with cloud security (GCP preferred, AWS or Azure fine too), IAM design, network ...

Lead DevSecOps Engineer

Jersey City, NJ ยท On-site

$112K - $147K/yr

Proven experience in DevSecOps or a similar role ... Strong knowledge of AWS cloud platform. * Proficiency in programming languages such as Groovy DSL ...

Senior Security Engineer

Manhattan, NY ยท On-site

$120 - $150/hr

Senior Security Engineer New York New York Job ID: 20935 Our client is seeking a Senior Security ... AWS * DevSecOps and cloud security tooling Preferred Qualifications * Bachelor's degree in ...

next page

Showing results 1-20

Aws Devsecops Engineer information

What is an AWS DevSecOps Engineer?

An AWS DevSecOps Engineer is a professional who integrates security practices into the DevOps process on Amazon Web Services (AWS). They are responsible for automating security measures, monitoring system vulnerabilities, and ensuring compliance throughout the software development lifecycle. Their role bridges the gap between development, operations, and security teams, enabling faster and more secure deployment of applications. Typical tasks include configuring security tools, managing cloud infrastructure, and implementing best practices for secure code delivery.

How does an AWS DevSecOps Engineer typically collaborate with development and security teams in a cloud environment?

As an AWS DevSecOps Engineer, you'll work closely with both development and security teams to integrate security practices into the software development lifecycle. This often involves setting up automated security checks in CI/CD pipelines, advising developers on secure coding practices, and ensuring compliance with security policies. Regular meetings and collaborative troubleshooting are common, as you'll be bridging gaps between rapid development and stringent security requirements. By fostering communication and shared responsibility, you help create a culture where security is integrated rather than added as an afterthought.

What are the key skills and qualifications needed to thrive as an AWS DevSecOps Engineer?

To thrive as an AWS DevSecOps Engineer, you need a strong background in cloud infrastructure (especially AWS), security best practices, and automation, often supported by a degree in computer science or a related field. Familiarity with tools like AWS CloudFormation, Terraform, Jenkins, Docker, Kubernetes, and security frameworks such as CIS benchmarks or AWS Security Hub is typical, along with certifications like AWS Certified DevOps Engineer or AWS Certified Security Specialty. Strong problem-solving skills, effective communication, and a proactive approach to security make someone excel in this role. These skills are crucial for ensuring secure, efficient, and resilient cloud environments that support rapid development and deployment cycles.

What is the difference between Aws Devsecops Engineer vs Cloud Security Engineer?

AspectAws Devsecops EngineerCloud Security Engineer
CertificationsAWS Certified DevOps Engineer, Security+CISSP, CCSP, AWS Security Specialty
Work EnvironmentDevOps teams, cloud infrastructure, automationSecurity teams, cloud environments, risk assessment
Primary FocusIntegrating security into DevOps pipelines on AWSImplementing and managing security measures in cloud platforms

The Aws Devsecops Engineer focuses on embedding security practices within DevOps workflows on AWS, emphasizing automation and continuous integration. In contrast, the Cloud Security Engineer concentrates on securing cloud infrastructure, managing security policies, and risk mitigation across cloud environments. Both roles require cloud security knowledge but differ in their primary responsibilities and work settings.

What job categories do people searching Aws Devsecops Engineer jobs in New York look for?

The top searched job categories for Aws Devsecops Engineer jobs in New York are:

What cities in New York are hiring for Aws Devsecops Engineer jobs?

Cities in New York with the most Aws Devsecops Engineer job openings:

Infographic showing various Aws Devsecops Engineer job openings in New York as of August 2026, with employment types broken down into 90% Full Time, 6% Part Time, and 4% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

DevSecOps Engineer

Lockedinai

Manhattan, NY โ€ข On-site

$140 - $195/hr

Other

Posted 4 days ago


Job description

Job TitleDevSecOps EngineerCompensation$140,000 โ€“ $195,000 USD / yr## Role OverviewWe are looking for a security-minded, automation-first DevSecOps Engineer to embed security into every stage of LockedIn AIโ€™s software development and deployment lifecycle. This is a shift-left security role โ€” you will ensure that security is not an afterthought bolted on at the end, but a fundamental part of how code is written, tested, built, deployed, and operated across a platform serving over 1 million users.As a DevSecOps Engineer, you will sit at the intersection of development, security, and operations. Your scope spans the entire software delivery pipeline โ€” from secure coding practices and automated security testing in CI/CD pipelines, to infrastructure hardening and container security, to runtime monitoring and incident response.The ideal DevSecOps Engineer combines strong software engineering and DevOps skills with deep security expertise. You automate everything โ€” from static and dynamic analysis in the build pipeline to vulnerability scanning in production. You understand that security at startup speed means building automated systems that protect without slowing anyone down.## Key Responsibilities### Secure CI/CD Pipeline Engineering* Design, implement, and maintain security-integrated CI/CD pipelines that automate security testing at every stage โ€” from code commit through build, test, staging, and production deployment* Embed SAST, DAST, SCA, and secret scanning into automated build pipelines โ€” ensuring vulnerabilities are caught before code reaches production* Implement container image scanning, infrastructure-as-code security validation, and dependency vulnerability checks as mandatory gates in the deployment pipeline* Build automated policy enforcement that blocks deployments failing security thresholds while providing developers with clear, actionable remediation guidance### Application Security & Secure Development Practices* Champion shift-left security practices โ€” working directly with development teams to integrate secure coding standards, threat modeling, and security reviews early in the development process* Conduct security code reviews, architecture reviews, and threat modeling sessions for new features and services โ€” identifying risks and recommending mitigations before code is written* Develop and maintain secure coding guidelines, security patterns, and reusable security libraries that make it easy for developers to build secure features by default* Track and remediate application vulnerabilities โ€” managing the vulnerability lifecycle from discovery through prioritization, remediation, and verification### Infrastructure Security & Cloud Hardening* Implement infrastructure security best practices across cloud environments (AWS, GCP, or Azure) โ€” including network segmentation, least-privilege IAM policies, encryption at rest and in transit, and security group management* Secure containerized environments โ€” hardening Docker images, configuring Kubernetes security policies (network policies, pod security standards, RBAC), and implementing runtime container security monitoring* Manage Infrastructure as Code (IaC) security โ€” scanning Terraform, Pulumi, or CloudFormation templates for misconfigurations, compliance violations, and security risks before deployment* Implement secrets management solutions (HashiCorp Vault, AWS Secrets Manager, or similar) that eliminate hardcoded credentials and enforce secure secret rotation and access controls### Security Monitoring, Detection & Incident Response* Build and maintain security monitoring and alerting systems โ€” implementing SIEM integration, log aggregation, and anomaly detection that provide real-time visibility into security events across the platform* Develop detection rules, correlation queries, and automated response playbooks that identify and respond to security incidents โ€” including unauthorized access, suspicious API activity, and infrastructure anomalies* Participate in on-call security rotations and lead security incident response โ€” coordinating investigation, containment, remediation, and post-incident review* Monitor for AI-specific security events โ€” including adversarial inputs to LLM systems, prompt injection attempts, and unauthorized model access### Vulnerability Management & Compliance* Own the vulnerability management lifecycle โ€” discovering, prioritizing, tracking, and driving remediation of vulnerabilities across applications, infrastructure, containers, and dependencies* Implement automated vulnerability scanning across the full stack โ€” including application code, third-party libraries, container images, cloud configurations, and AI model serving infrastructure* Ensure security controls and practices align with relevant compliance frameworks and industry best practices โ€” building toward formal compliance readiness as the company scales* Maintain security documentation โ€” including architecture diagrams, risk registers, security policies, and audit trails that support compliance and organizational knowledge sharing### Security Culture, Training & Cross-Functional Collaboration* Champion a โ€œsecurity as codeโ€ culture across the engineering organization โ€” making security practices automated, transparent, and developer-friendly* Develop and deliver security training and awareness programs for engineering teams โ€” including secure coding workshops, threat modeling sessions, and security tooling onboarding* Work closely with co-founders, engineering, product, and operations to align security priorities with business objectives and product roadmap* Stay current on the latest DevSecOps tools, security vulnerabilities, attack techniques, and industry best practices โ€” continuously improving LockedIn AIโ€™s security posture## Required Qualifications### Experience* 3+ years of experience in DevSecOps, application security, or a combined DevOps/security engineering role* Demonstrated experience integrating security tooling into CI/CD pipelines and automating security processes* Hands-on experience hardening cloud infrastructure, containerized environments, and software delivery pipelines* Experience working cross-functionally with engineering, security, and operations teams in a fast-moving environment* Startup or high-growth environment experience preferred โ€” comfort working in ambiguity, moving fast, and wearing multiple hats### Education* Bachelorโ€™s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field.* Relevant security certifications are a strong plus: CDP, OSCP, CKS, Security+, CISSP, or CEH โ€” we value demonstrated security engineering skill over credentials.### Technical Skills* Strong proficiency in Python, Bash, or Go with experience writing security automation, tooling, and infrastructure code* Deep experience with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins, ArgoCD, or similar) and integrating security scanning tools into automated pipelines* Hands-on expertise with containerization and orchestration security (Docker, Kubernetes) โ€” including image hardening, pod security, network policies, and runtime security monitoring* Experience with IaC tools (Terraform, Pulumi, CloudFormation) and IaC security scanning (Checkov, tfsec, or similar)* Proficiency with security scanning tools โ€” SAST (SonarQube, Semgrep), DAST (OWASP ZAP, Burp Suite), SCA (Snyk, Dependabot, Trivy), and secret scanning (GitLeaks, TruffleHog)* Experience with SIEM platforms, security monitoring, and log analysis (Splunk, Elastic, Datadog Security, or similar)### Strategic & Soft Skills* Security-first mindset with a developer-friendly approach: you build security systems that protect without creating friction โ€” making the secure path the easiest path for developers* Strong written and verbal communication โ€” you can write clear security policies, explain vulnerabilities to development #J-18808-Ljbffr