Senior DevSecOps Engineer
BankrateAbout the role
<p><strong><em>*This role is open to remote or hybrid candidates (East Coast preference), with hybrid being central to our New York, NY or Charlotte area offices. Must be able to work Eastern Standard Time hours.</em></strong></p> <p>Platform Engineering builds the foundations our product teams ship on — deployment, infrastructure, and security. We're hiring a DevSecOps Engineer to be the technical owner of our security posture and a force multiplier for every engineer at the company. This is a build-the-function role, not a ticket-taking role. You'll treat security as code, bake it into the development lifecycle, and automate the toil away so teams can ship fast <em>and</em> safely. You'll have unusually broad ownership and unusually high impact.</p> <p><strong>What You’ll Do:</strong></p> <ul> <li>Own the engineering side of our compliance program (SOC 2 Type 2): implementing controls, collecting evidence, and keeping us audit-ready.</li> <li>Operate our compliance automation platform — integrations, evidence pipelines, and mapping controls to real implementation.</li> <li>Productize compliance: policy-as-code, automated evidence generation, and guardrails so passing audits doesn't slow product delivery.</li> <li>Own cloud security posture management and runtime security tooling: posture monitoring, container and IaC scanning, and runtime coverage across our environment.</li> <li>Triage and remediate findings against demanding SLAs, and design the automation and alerting that keeps pace with volume manual effort can't.</li> <li>Build auto-remediation workflows — including AI-assisted pipelines — that detect, file, and (where safe) fix findings with minimal human intervention.</li> <li>Build and maintain CI/CD security gates: SAST/SCA, secret scanning, SBOM generation, dependency management, and container/IaC scanning — implemented as reusable pipeline components and enforced through automated policy.</li> <li>Encode security and compliance controls into infrastructure-as-code and policy-as-code so the easy path is the secure path.</li> <li>Help close the prototype-to-production gap: turn fast-moving prototypes into production-grade, secure-by-default systems with automated guardrails.</li> <li>Make secure-by-default the norm through our internal tooling, so the right controls are applied automatically rather than relying on engineers to remember.</li> <li>Build the automation the team runs on — reusable modules, pipeline components, and AI/agentic tooling that turn manual security work into self-service capability.</li> <li>Partner with corporate security and GRC functions while building and maturing our in-house security capability, so the team can make sound security decisions quic
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s