Senior DevSecOps Engineer
DFO ReferralsAbout the role
<p><strong>Senior DevSecOps Engineer </strong></p> <p><strong>Dalio Family Office</strong></p> <p><strong><u>Dalio Family Office Overview: </u></strong></p> <p>The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO’s culture is built around meaningful work and meaningful relationships and the family’s commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi. This is a hybrid position reporting primarily out of our New York City office location.</p> <p><strong><u>Position Summary: </u></strong></p> <p>Reporting to the Cybersecurity Lead, the Senior DevSecOps Engineer will design, deploy, and secure scalable AWS + Azure environments with a strong focus on Infrastructure as Code (IaC). The purpose of this role is to build secure cloud-native infrastructure from the ground up, operationalize AWS/Azure services, and automate the reliability and security of mission-critical systems. You will embed security-by-design across the SDLC by implementing secure CI/CD pipelines with automated testing, policy controls, and supply-chain protections (SBOMs, signed artifacts, provenance), while centralizing security telemetry into Microsoft Defender for Cloud for unified posture management, threat detection, and compliance. The role also secures cloud infrastructure, data, and key management using AWS KMS and Azure Key Vault, hardens AKS/EKS with policy-as-code (OPA/Gatekeeper) and runtime protections, and extends these controls to AI/LLM development and inference platforms including AWS Bedrock, AI Foundry, and vLLM.</p> <p><strong><u>Day-to-day responsibilities would include a combination of the following:</u></strong></p> <ul> <li>Embed security-by-design across the SDLC with automated controls and measurable security outcomes.</li> <li>Deliver a secure, compliant AWS/Azure cloud foundation with strong data protection and key management.</li> <li>Harden container and Kubernetes platforms with consistent policy enforcement and runtime protection.</li> <li>Build and maintain secure CI/CD pipelines with SAST/SCA, IaC + container scanning, secret detection, and policy gates, including threat modelling and secure design practices.</li> <li>Enforce software supply-chain security (SBOMs, signed images, provenance verification) and route pipeline/code telemetry into Microsoft Defender for Cloud.</li> <li>Secure AWS/Azure workloads across identity, network, compute, and storage; implement encryption, classification, retention, DL
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s