Soft Does

DevSecOps Engineer (Cloud Security and Compliance)

віддалено
до 4000 USD
Форма роботи
повна зайнятість
Рівень
  • Middle
Знання мов
  • Англійська , Upper Intermediate
Навички
  • Docker
  • Terraform
  • Kubernetes
  • AWS
  • Security
8 days ago
Про компанію
Галузь Outsource
Розмір компанії 50-100

SoftDoes is a U.S.-based custom software development company headquartered in Kansas City, Missouri. We build custom software, SaaS platforms, web and mobile applications, AI solutions, and cloud infrastructure for businesses across industries such as healthcare, fintech, construction, legal, and real estate. We work with modern technologies and focus on solving complex business problems through reliable, scalable software solutions.

Про вакансію

SoftDoes is a U.S.-based custom software development company headquartered in Kansas City, Missouri. We build custom software, SaaS platforms, web and mobile applications, AI solutions, and cloud infrastructure for businesses across industries such as healthcare, fintech, construction, legal, and real estate.

We work with modern technologies and focus on solving complex business problems through reliable, scalable software solutions.

About the role

The company is moving deeper into enterprise work. We need a DevSecOps engineer who can help harden our infrastructure, implement security best practices, and drive compliance readiness so we can pass enterprise vendor reviews and pursue certifications like SOC 2 and ISO 27001. You will work closely with engineering and leadership across infrastructure, security, and compliance.

What you will do:

  • Build and maintain secure cloud infrastructure and CI/CD pipelines
  • Implement access control, least privilege, and secrets management across environments
  • Standardize logging, monitoring, alerting, and audit trails
  • Create and maintain secure SDLC practices, including code scanning, dependency scanning, and change control
  • Set up incident response basics, including runbooks, on-call expectations, and post-incident process
  • Compliance readiness for SOC 2 and ISO 27001 by implementing required technical controls and gathering evidence
  • Vulnerability management and patching routines for infrastructure and dependencies
  • Improve backup, disaster recovery, and business continuity practices
  • Support client security questionnaires with clear technical answers and evidence

 

Вимоги

Requirements:

  • Up to 2 years of DevSecOps experience with cloud infrastructure and deployment pipelines
  • Hands-on experience with AWS, including IAM, networking, compute, and logging services
  • Experience with Infrastructure as Code such as Terraform
  • Experience with containerization and orchestration, Docker and Kubernetes preferred
  • Comfort setting up security tooling, SAST, DAST, dependency scanning, secret scanning
  • Ability to document systems clearly and work with auditors or compliance tools when needed
  • English at B2 level or higher - you will collaborate directly with US client stakeholders
  • SOC 2 or ISO 27001 experience, even if you were the technical owner not the compliance PM

Буде плюсом
  • Experience with Vanta, Drata, Secureframe, or similar evidence automation tools
  • Experience working with HIPAA or other regulated client environments
  • AWS certifications such as Solutions Architect or Security Specialty
Ми пропонуємо

What We Offer:

  • Working hours aligned with US time zones, typically 16:00-23:59 Kyiv time
  • English lessons to support clear and confident communication
  • Paid vacation and sick days
  • Fully remote work
  • Opportunities for professional growth within the team
  • Structured, personalized onboarding to help you ramp up effectively