Senior DevOps Security Engineer
Cast & CrewAbout the role
About Us
At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production’s best ally every step of the way. #OneCastOneCrew
Job OverviewWe are seeking a highly skilled Senior DevOps Security Engineer to join our forward-thinking IT organization. This full-time role will focus on securing our DevOps pipelines, cloud infrastructure, applications, and database environments, with a strong emphasis on AWS and Azure cloud security. The ideal candidate will have 8-10 years of experience in DevOps, specializing in identifying and resolving security vulnerabilities in infrastructure, applications (Java, Node.js, .NET), and databases (MSSQL, MySQL, PostgreSQL) hosted on Azure and AWS RDS. You will bring expertise in ingress/egress network firewalls, security tools (e.g., Pentest, Orca, Nexus), and SOC controls to ensure our systems are robust and compliant. This role will collaborate with development, operations, and security teams to champion secure DevOps practices across the board. You will lead the design and implementation of secure, scalable cloud solutions, leveraging AWS EKS for container orchestration, AWS Control Tower for governance, and infrastructure-as-code practices using Terraform.
Key Responsibilities
- Design, implement, and maintain secure DevOps pipelines and infrastructure in AWS and Azure environments, adhering to cloud-native security best practices.
- Secure AWS RDS instances hosting MSSQL, MySQL, and PostgreSQL databases, including encryption, access controls, and vulnerability management.
- Identify, assess, and resolve security vulnerabilities in infrastructure, applications written in Java, Node.js, and .NET, and database systems.
- Configure and manage ingress/egress network firewalls to protect cloud, on-premises, and database environments from unauthorized access and threats.
- Utilize security tools such as Snyk, Pentest, Orca, Nexus, and others to perform vulnerability scans, penetration testing, and risk assessments across infrastructure and databases.
- Proven expertise in leading AWS-based solutions, including architecting and managing AWS EKS for Kubernetes workloads, AWS Control Tower for governance, and services like EC2, S3, VPCs, IAM, and Security Groups—AWS experience is mandatory.
- Hands-on experience designing, deploying, and securing AWS EKS clusters, including cluster autoscaling, logging (e.g., CloudWatch), monitoring, and integration with CI/CD pipelines.
- Demonstrated ability to implement and manage AWS Control Tower for multi-account governance, compliance, and security policy enforcement.
- Collaborate with development teams to integrate security into CI/CD pipelines, ensuring secure code deployment, infrastructure-as-code, and database configurations.
- Conduct security audits and ensure compliance with SOC controls (e.g., SOC 2), providing documentation and remediation plans for infrastructure and database security.
- Monitor and respond to security incidents using cloud security services and database-specific monitoring tools.
- Harden cloud infrastructure (e.g., IAM policies, encryption, network security groups) and database environments to mitigate risks and align with industry standards.
- Stay current on emerging security threats, tools, and best practices, providing actionable recommendations to enhance our security posture.
- Mentor team members on DevOps security practices, including database security, to foster a security-first mindset across the organization.
Required Skills and Qualifications
- Experience: 8-10 years of professional experience in DevOps with a strong focus on cloud and database security.
- AWS Cloud Security: Expertise in securing AWS environments, including EC2, S3, VPCs, IAM, and Security Groups—AWS experience is mandatory.
- AWS RDS Security: Proven experience securing AWS RDS instances running MSSQL, MySQL, and PostgreSQL, including encryption, auditing, and access management.
- Azure Cloud Security: Strong skills in securing Azure infrastructure, including Azure AD, Virtual Networks, Key Vault, and Sentinel—Azure experience is mandatory.
- Dat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s