DevSecOps Engineer

1 hour, 55 minutes ago
Full-time
Mid Level
DevOps and Infrastructure
Typeform

Typeform

Typeform is a user-friendly platform for creating interactive forms and surveys with no coding required. It offers templates for quizzes, feedback, lead generation, and more, ensuring a positive user experience on any device.

Internet Software & Services
251-1K
Founded 2012
$187M raised

Description

  • Embed security into the software development lifecycle by partnering with engineering and AI teams.
  • Build and maintain CI/CD security automation, including SAST, DAST, secrets management, and artifact scanning.
  • Conduct vulnerability assessments, threat modeling, and code reviews for platform and AI workloads.
  • Advise teams on secure architecture patterns for infrastructure, agent systems, and model-serving pipelines.
  • Implement monitoring and incident response processes to detect and respond to security alerts quickly.
  • Define and maintain security standards, policies, and reusable infrastructure components.
  • Influence teams to adopt secure practices without slowing delivery and serve as an internal security advocate.

Requirements

  • Several years of experience in DevSecOps, security engineering, or cloud security.
  • Strong understanding of distributed systems, cloud-native infrastructure, and CI/CD pipelines.
  • Knowledge of threat modeling, vulnerability assessment, and incident response.
  • Experience with or strong willingness to learn AI/ML security, model-serving pipelines, or agent-based systems.
  • Familiarity with infrastructure as code (IaC), Kubernetes, and cloud platforms such as AWS, GCP, or Azure.
  • Excellent collaboration and communication skills for explaining security concepts to non-security teams.
  • Hands-on experience with AI security, model risk, or prompt injection mitigation is a plus.
  • Experience in high-velocity SaaS or PLG environments is preferred.
  • Contributions to open-source security tooling or frameworks are a plus.
  • Experience implementing automated security testing in CI/CD pipelines for code and infrastructure is a plus.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Security Engineer, Product Security

Mozilla 251-1K Internet Software & Services

Mozilla is hiring a Staff Security Engineer to protect Firefox, Mozilla VPN, and other mission-critical products by embedding security across the software development lifecycle for users in the US and Canada.

AWS Azure Burp Suite CI/CD GCP Go Java JavaScript Penetration Testing Python
10 minutes ago

Lead Security Engineer (AI-Native)

Nerdy 51-250 Diversified Consumer Services

Nerdy is hiring a Lead Security Engineer to lead enterprise security and infrastructure strategy for its AWS-first learning platform, balancing hands-on execution with cross-functional leadership to protect systems, ensure compliance, and support growth.

AWS Network Security
25 minutes ago

Lead Security Engineer (AI-Native)

Nerdy 51-250 Diversified Consumer Services

Lead Security Engineer at Nerdy, responsible for shaping and operating enterprise security and infrastructure in an AWS-first environment that supports scalable, reliable systems and company growth.

AWS Network Security
25 minutes ago

Lead Security Engineer (AI-Native)

Nerdy 51-250 Diversified Consumer Services

Lead Security Engineer at Nerdy responsible for driving enterprise security and infrastructure strategy in an AWS-first environment while protecting company assets, ensuring compliance, and supporting high-growth objectives.

AWS Cybersecurity Network Security
25 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers