remote

Salary
$130,000–$145,000from the description
Posted
Jul 23, 2026
Location
Last confirmed open
Jul 25, 2026

What this job asks for AI summary

A DevSecOps engineering role focused on building and maintaining secure, automated infrastructure pipelines for a cloud platform. Core work involves creating hardened Linux golden images for VMs and containers, managing configuration drift, integrating security scanning into CI/CD workflows, and enforcing policy-as-code controls. Suited to engineers with strong Linux security backgrounds and hands-on experience with Kubernetes, configuration management, and build-time compliance automation.

Senior level · 5+ years · Remote · Full-time

Must have (11)
LinuxCIS benchmarksKubernetesCI/CDBashPythonpolicy-as-codegolden image pipelinesvulnerability scanningSBOMobservability

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 8,900 people nationally plausibly meet what this posting asks for (software developers). range 1,800–13,300

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
vulnerability scanning5%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%Linux45%CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $138,970 (middle half $107,524–$175,762). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

SOC classification is a genuine judgment call: the role is titled DevSecOps Engineer and spans both building automated pipelines/infrastructure-as-code (15-1252 Software Developers) and security analysis/hardening/compliance (15-1212 Information Security Analysts). The primary day-to-day work — designing and building golden image factories, CI/CD pipelines, and configuration management automation — tips toward 15-1252, but the security-analysis runner-up is real.

Role is fully remote but restricted to residents of the 36 listed US states; no single metro applies.

Configuration management tools are required but no specific tool (e.g. Ansible, Chef, Puppet, Salt) is named in the posting — captured generically.

Policy-as-code frameworks are required but no specific framework (e.g. OPA, Kyverno, Sentinel) is named — captured generically.

Observability/telemetry tooling is required but no specific product (e.g. Prometheus, Datadog, Grafana) is named — captured generically.

Golden image pipeline tooling is required but no specific tool (e.g. Packer, Kaniko) is named — captured generically.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): configuration management, secrets management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗