Overflowremote

Salary
Posted
Jul 13, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A founding DevSecOps hire responsible for building and owning the platform and infrastructure layer at a fintech/SaaS company. Day-to-day work spans managing a containerized AWS environment, hardening CI/CD pipelines with automated security testing, and establishing observability and alerting systems. The role also carries significant compliance ownership, including maintaining SOC 2 controls and leading the technical groundwork for PCI Level 1 certification. Best suited to someone with a background in SRE or cloud platform engineering who has operated in a startup context before.

Senior level · 5+ years · Remote · Full-time

Must have (14)
AWSDockerAWS ECS FargateGitHub ActionsCI/CDIAMVPCWAFInfrastructure as Code, Terraform or PulumiSASTDASTSOC 2PCI-DSSobservability
Nice to have (2)
OWASP Top 10threat modeling

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 4,700 people nationally plausibly meet what this posting asks for (software developers). range 1,400–7,100

Applicant volume Light — Few people clear these requirements, so an application that does clear them gets looked at. Worth applying to even if you miss a nice-to-have.

What gives you an edge
SAST4%DAST4%WAF5%PCI-DSS6%IAM7%SOC 28%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Docker53%CI/CD45%GitHub Actions40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $138,970 (middle half $107,524–$175,762).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

SOC classification is a judgment call: the role is titled DevSecOps and emphasizes building CI/CD pipelines, IaC, and security tooling (code the team ships), which points to 15-1252 Software Developers. However, the SRE/cloud-operations framing and compliance-maintenance duties also carry meaningful 15-1244 weight — hence Medium confidence with 15-1244 as the runner-up.

Infrastructure as Code is required by firm language ('Refine existing infrastructure provisioning using IaC tools') but no specific tool is named; Terraform, Pulumi, and CloudFormation are listed as alternatives representing the most common substitutes.

Secret management, VPC, WAF, IAM, SAST, DAST, and observability are all called out under the core 'What You Should Have' / 'What You Will Do' requirements sections and are treated as hard gates.

OWASP Top 10 and threat modeling appear under the 'It'd Be Nice If You Had' section and are therefore preferred.

No compensation figures are stated; the posting references Carta Total Compensation benchmarks but gives no specific numbers.

The posting does not specify a degree requirement anywhere.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secret management.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗