DevSecOps Engineer
Overflow
—
Jul 13, 2026
—
Jul 21, 2026
What this job asks for AI summary
A founding DevSecOps hire responsible for building and owning the platform and infrastructure layer at a fintech/SaaS company. Day-to-day work spans managing a containerized AWS environment, hardening CI/CD pipelines with automated security testing, and establishing observability and alerting systems. The role also carries significant compliance ownership, including maintaining SOC 2 controls and leading the technical groundwork for PCI Level 1 certification. Best suited to someone with a background in SRE or cloud platform engineering who has operated in a startup context before.
Senior level · 5+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 4,700 people nationally plausibly meet what this posting asks for (software developers). range 1,400–7,100
Applicant volume Light — Few people clear these requirements, so an application that does clear them gets looked at. Worth applying to even if you miss a nice-to-have.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $138,970 (middle half $107,524–$175,762).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
SOC classification is a judgment call: the role is titled DevSecOps and emphasizes building CI/CD pipelines, IaC, and security tooling (code the team ships), which points to 15-1252 Software Developers. However, the SRE/cloud-operations framing and compliance-maintenance duties also carry meaningful 15-1244 weight — hence Medium confidence with 15-1244 as the runner-up.
Infrastructure as Code is required by firm language ('Refine existing infrastructure provisioning using IaC tools') but no specific tool is named; Terraform, Pulumi, and CloudFormation are listed as alternatives representing the most common substitutes.
Secret management, VPC, WAF, IAM, SAST, DAST, and observability are all called out under the core 'What You Should Have' / 'What You Will Do' requirements sections and are treated as hard gates.
OWASP Top 10 and threat modeling appear under the 'It'd Be Nice If You Had' section and are therefore preferred.
No compensation figures are stated; the posting references Carta Total Compensation benchmarks but gives no specific numbers.
The posting does not specify a degree requirement anywhere.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secret management.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.