Staff DevSecOps Engineer

1 hour, 50 minutes ago
Full-time
Lead
DevOps and Infrastructure
Counterpart

Counterpart

Counterpart specializes in providing innovative management and professional liability insurance solutions tailored for the modern workplace, including coverage for directors and officers, employment practices, and various professional liabilities.

Insurance
11-50
Founded 2019
$40M raised

Description

  • Own the organization's security posture by defining, implementing, and maintaining security controls, policies, and practices.
  • Own the SOC 2 Type 2 and HIPAA compliance programs, including audits, evidence collection, and ongoing compliance automation.
  • Continuously evaluate the security posture against emerging threats, regulations, and AI-specific attack vectors.
  • Own IT operations end-to-end, including onboarding, offboarding, device provisioning, access controls, and identity management.
  • Serve as a hands-on member of the DevOps team securing platform infrastructure.
  • Build and maintain sandbox architecture for safe experimentation without impacting production systems.
  • Design and implement secure environments for AI agent workloads, including trust boundaries and protections against prompt injection and data exfiltration.
  • Translate security and compliance requirements into engineering decisions and communicate risks to non-technical stakeholders.
  • Help build the in-house security function from the ground up and grow into full ownership.

Requirements

  • 10+ years of experience in DevSecOps, security engineering, or a combination of DevOps, security, and IT roles.
  • Hands-on experience with cloud infrastructure and security on AWS.
  • Experience owning or co-owning SOC 2 and HIPAA compliance programs.
  • Experience managing IT operations, including device management, identity and access management, and internal tooling.
  • Strong familiarity with security frameworks and compliance standards.
  • Hands-on awareness of AI agent risks such as prompt injection, data poisoning, and adversarial inputs.
  • Ability to communicate security risks clearly to non-technical stakeholders.
  • Drive to build a security function from the ground up and take full ownership over time.
  • Domain curiosity about insurance or a willingness to learn how insurance works.
  • Experience working with distributed, remote teams.

Benefits

  • Unlimited vacation and flexible time off.
  • Fully distributed, work-from-anywhere setup.
  • Stock options.
  • Health, dental, and vision coverage.
  • 401(k) retirement plan.
  • Parental leave.
  • Home office allowance.
  • Book stipend.
  • Professional development reimbursement.
  • Take your birthday off.
  • Charitable contribution matching.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior DevOps Engineer

Riskified 251-1K Internet Software & Services

Riskified is hiring a DevOps Engineer to own the cloud infrastructure behind its real-time fraud and risk decisioning platform, with a focus on architecture, reliability, and delivery at scale.

Argo CD AWS CI/CD Cloudflare Go Helm Kubernetes Machine Learning Microservices Node.js
5 minutes ago

Director of Platform Engineering

Overstory 11-50 Utilities

Overstory is hiring a Director of Platform & Infrastructure to lead the company’s core engineering foundations as it scales its AI- and satellite-imagery-based platform for utility customers.

CI/CD GCP Kubernetes Machine Learning MLOps
20 minutes ago

Senior Backend Engineer (RoR), SSCS: Pipeline Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Backend Engineer to lead backend and infrastructure work on the Pipeline Security team, with primary ownership of its native Secrets Manager for GitLab CI/CD pipelines.

CI/CD Go GraphQL HashiCorp Vault Helm Kubernetes Ruby on Rails Secrets Management
1 hour, 5 minutes ago

Manager, Infrastructure Security (USA)

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Manager for its Infrastructure Security team to secure internal cloud infrastructure and the FedRAMP-authorized GitLab Dedicated for Government offering.

Ansible AWS Chef CI/CD Docker GCP Kubernetes Serverless Terraform
1 hour, 35 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers