Epsilon ASI
Cloud Security / DevSecOps Engineer
United States · Posted 19h ago
Job Description
About the Role
We are seeking a Cloud Security / DevSecOps Engineer to help maintain and strengthen the security, compliance, and reliability of a FedRAMP-compliant environment running on AWS.
This is a highly hands-on role focused on cloud infrastructure, security automation, vulnerability remediation, and compliance. You’ll work across infrastructure and application security to identify and resolve vulnerabilities, address cloud misconfigurations, and ensure the environment continues to meet stringent security and compliance requirements.
This is also an opportunity for a high-performing engineer to take on increasing technical and organizational responsibility, with the potential to grow into a Head of Engineering role.
What You'll Do
Maintain and improve FedRAMP compliance within an AWS environment.
Manage and improve infrastructure using Terraform and infrastructure-as-code best practices.
Identify and remediate Golang/container vulnerabilities and other security issues.
Investigate and resolve cloud infrastructure misconfigurations.
Review systems and infrastructure against NIST security guidelines and controls.
Develop and maintain CI/CD automation using GitHub Actions.
Partner with engineering teams to integrate security into the software development lifecycle.
Monitor infrastructure and applications for security vulnerabilities and compliance gaps.
Help establish repeatable processes for security, compliance, and infrastructure management.
Contribute to architectural and engineering decisions as the organization scales.
Required Qualifications
Strong professional experience with Terraform and infrastructure as code.
Hands-on experience with Go (Golang).
Experience building or maintaining CI/CD pipelines using GitHub Actions.
Experience with AWS cloud infrastructure.
Strong understanding of cloud security and infrastructure security principles.
Experience identifying and remediating vulnerabilities in containers and cloud environments.
Familiarity with NIST security guidelines and frameworks.
Experience working in a security-conscious or regulated environment.
Preferred Qualifications
Experience maintaining FedRAMP-compliant environments.
Experience with AWS security services and controls.
Kubernetes and container security experience.
Experience with vulnerability management and remediation.
Familiarity with automated security testing and DevSecOps practices.
Experience working with government or highly regulated customers.
Experience with additional infrastructure/security tooling such as Rust is a plus.
What Will Set You Apart
We're looking for someone who is comfortable operating at the intersection of engineering, cloud infrastructure, security, and compliance.
The ideal candidate isn't simply checking compliance boxes—they can understand the underlying infrastructure, troubleshoot technical vulnerabilities, and work directly with engineering teams to implement practical solutions.
Strong Golang experience is particularly valuable for this role, as it will be used to address vulnerabilities and maintain components within the existing containerized environment.
Growth Opportunity
This role offers significant opportunity for growth. While the initial focus will be on AWS infrastructure, FedRAMP compliance, security remediation, and DevSecOps, the right candidate can take on broader technical leadership and architecture responsibilities over time.
For the right individual, there is a potential path toward Head of Engineering as the organization continues to grow.