DevSecOps Engineer
- šŗšø United States
- Hybrid
- Mid level
- 1 day ago
- Incident Response
- IAM
- SIEM
- Threat Modeling
- Penetration Testing
- AWS Cloud
- Terraform
- IaC
- Vulnerability Management
- Network Security
- VPC
- WAF
- DDoS Mitigation
- Python
- Ruby
- Bash
- triage
- AWS
- CloudFormation
- Snyk
- SonarQube
- Burp Suite
- DNS
- TLS
- OWASP
- Datadog
- Splunk
- Kubernetes
- EKS
- ECS
- Linux
- GuardDuty
- CloudTrail
- KMS
- RBAC
- ABAC
- OAuth
- OIDC
- SAML
- Secrets Management
- SOC2
- GDPR
- Git
- GitOps
- Configuration Management
- AWS Security Specialty
- CompTIA Security+
- OSCP
- CEH
- CISSP
- Health insurance
- Pension
Department:Technology Organization
Location:Ā Minneapolis, MN
Ā
Yardstik is a start-up software company with a mission of building trust and safety into the Internet Economy. The world of background screening, certification, and training has lacked innovation and weāre here to change that for our customers. Our enterprise-class technology allows us to provide a right-fit solution for our customers realistic for any platform, in any industry. Join us in our efforts to protect organizations and their people.
Ā
We are adding a SecOps Engineer to own and advance the security posture of our platform and infrastructure. You will work alongside engineering and operations teams to identify, mitigate, and prevent security risks across our cloud environment, applications, and data systems.
Ā
This position sits within our Infrastructure & Security team. Your primary focus will be protecting Yardstikās systems, data, and customers through hands-on security engineering, cloud hardening, threat detection, incident response, and compliance enablement while maintaining the operational reliability our platform depends on.
Ā
You are the right candidate if you are an experienced engineer who thinks security-first, is comfortable operating cloud infrastructure at scale, and wants to be the person the team turns to when something needs to be locked down, investigated, or hardened.
Ā
This is a unique opportunity to join the company at an early stage and we are looking for someone who wants to evolve with us. We are honored to have recently been named a MSPBJ Best Place to Work for the sixth year in a row and named to Newsweekās Americaās Greatest Startup Workplaces. Come be part of our amazing culture and join an environment where you can see and feel the impact of your work every day.Ā
Ā
This role is not eligible for visa sponsorship.
Ā
Essential Accountabilities:
Own Yardstik's security posture across cloud infrastructure and applications
Detect, investigate, and respond to security incidents
Harden cloud environments through least-privilege IAM, network segmentation, etc
Manage vulnerability scanners, SIEM, endpoint protection, and intrusion detection tools
Conduct threat modeling, vulnerability assessments, and penetration testing
Ā
What you will do in this role:
Serve as a security SME for the Technology organization, advising engineering teams on secure architecture, configurations, and operational practices
Manage and harden AWS cloud infrastructure using Terraform and IaC, with a focus on security controls, audit logging, and compliance
Build and maintain security monitoring, alerting, and detection pipelines using SIEM tools, log aggregation, and anomaly detection
Perform vulnerability management: scanning, triaging, prioritizing, tracking remediation, and validating fixes
Design and enforce network security controls including VPCs, security groups, WAF rules, and DDoS mitigation strategies
Automate security workflows, compliance checks, and operational tasks through scripting (Python, Ruby, Bash)
Respond to and lead security incident triage, including on-call rotations, with a focus on reducing MTTD and MTTR
Evaluate and implement new security tools, technologies, and processes.
Collaborate with engineering to integrate security requirements into application design and infrastructure changes
Ā
Your experience might look something like this:
Cloud-native environments (AWS preferred)
SIEM management, log analysis, alert tuning, and incident response
Infrastructure as Code (Terraform, CloudFormation)
Vulnerability management: scanning, triage, remediation tracking, and reporting
Security scanning and assessment tools (Snyk, SonarQube, ZAP, Burp Suite, or similar)
Networking fundamentals (VPC, VPN, DNS, TLS) and web security (WAF, CDN, OWASP Top 10)
Monitoring and observability platforms (DataDog, Splunk, or similar) with security focus
Container security: image scanning, runtime security, and orchestration platforms (Kubernetes, EKS, ECS)
Proficient with scripting languages for security automation (Python, Ruby, Bash)
On-call and incident response processes, including security-specific triage, containment, and post-mortems
Ā
Preferred Qualifications:
Strong Linux systems administration with security hardening experience (CIS)
Deep experience with AWS security services: IAM, GuardDuty, Security Hub, CloudTrail, Config, KMS
Expertise with IAM design principles: least-privilege, RBAC/ABAC, service control policies, and cross-account access patterns
Experience with identity and access management: SSO, OAuth/OIDC, SAML, and directory services
Familiarity with secrets management platforms (AWS Secrets Manager, HashiCorp Vault, or similar)
Experience with compliance frameworks (SOC 2, GDPR, or similar) and translating requirements into enforceable technical controls
Understanding of threat modeling methodologies (STRIDE, DREAD, attack trees) and vulnerability management lifecycle
Git-based source control proficiency and familiarity with GitOps methodologies
Experience with cloud infrastructure automation and configuration management
Security certifications such as AWS Security Specialty, CompTIA Security+, OSCP, CEH, CISSP, or similar
Familiarity with supply chain security practices (SBOM generation, dependency pinning, signed artifacts)
Ā
What we Offer:
Company Health Insurance Plan
401k Retirement Plan
Health Savings Account
Liberal Vacation Policy
Opportunity to accelerate your career
Compensation
At Yardstik, we are committed to ensuring that each employee's compensation reflects their unique experiences, performance, and skills in their role. Yardstik provides the annualized compensation range of $120,000 - $165,000 for this role.
Equal Employment OpportunityĀ
Yardstik is an Equal Opportunity Employer. Weāre committed to building a team based on talent, qualifications, and merit, welcoming all applicants without discrimination.
DevSecOps Engineer Ā· Yardstik