Pending Spotlight Call: Friday, September 18th at 2:00 pm EST
Location: Remote
DevOps Engineer Data Platform & Security
Contract engagement, 6 12 months
Role Summary
We're looking for a DevOps Engineer to join a small, high-visibility team focused primarily on building out a new security remediation practice, with a lighter, secondary role supporting an in-flight reporting platform migration. This is a hands-on infrastructure and security tooling role focused on system health rather than new feature development implementing infrastructure-level security fixes as directed by ***'s internal security team, standing up and operating vulnerability scanning and remediation tooling, and keeping cloud infrastructure up to date. Success depends on someone comfortable moving between focused infrastructure and security tooling work and close coordination with a Technical Program Manager and a Software Developer on a shared backlog.
This role sits within a core team of three: a Technical Program Manager, who provides day-to-day delivery leadership, a Software Developer, and this position, who together own a shared system health backlog weighted toward the security remediation workstream.
Key Responsibilities
Security Remediation Infrastructure & Tooling
Implement infrastructure-level security measures and remediations across My*** applications as directed by ***'s internal security team.
Stand up, configure, and maintain security scanning and vulnerability management tooling across the My*** platform for example, dependency/software composition analysis (e.g., npm audit or similar), a vulnerability management platform (e.g., Nucleus), and dynamic application security testing (DAST); specific toolset to be finalized.
Patch, harden, and update underlying infrastructure, hosts, and cloud configurations tied to security findings.
Partner with the Software Developer to coordinate application-level and infrastructure-level fixes, and with the Technical Program Manager to keep related stories well-scoped and ready for sprint.
Evaluate and pilot AI-assisted tooling to speed up vulnerability triage, remediation guidance, or security monitoring where it can meaningfully reduce manual effort.
Monitor infrastructure and pipelines for new vulnerabilities using existing and newly adopted security tooling.
Platform Migration Support
Provide infrastructure support as needed for the migration of reporting to the new target data platform, in coordination with the Software Developer and Technical Program Manager.
Assist with CI/CD pipeline configuration for migration-related deployments as capacity allows; this is a secondary responsibility relative to the security workstream.
System Health & Technical Debt
Keep cloud infrastructure, CI/CD tooling, and platform components up to date across services.
Identify and remediate infrastructure-related technical debt across the My*** platform.
Maintain monitoring, alerting, and observability tooling to support ongoing system health.
Participate in Agile ceremonies (standups, sprint planning, retrospectives) with the broader My*** team, with a personal backlog focused primarily on security and secondarily on system health and tech debt stories.
Keep story status, comments, and acceptance criteria current in Jira so the Technical Program Manager can maintain an accurate delivery plan.
Qualifications
3 6 years of DevOps, infrastructure, or platform engineering experience.
Deep, hands-on experience with AWS services, including RDS, DynamoDB, API Gateway, Lambda, S3, IAM, and VPC.
Experience implementing security remediations and operating related tooling for example, dependency/vulnerability scanning (npm audit or similar), vulnerability management platforms (e.g., Nucleus), and DAST tools.
Experience building and maintaining CI/CD pipelines using GitHub Actions, AWS CodePipeline, or similar tools.
Experience with infrastructure as code (e.g., Terraform, CloudFormation, or AWS CDK).
Comfort working from a clearly defined, prioritized backlog picking up scoped stories, updating status, and flagging blockers.
Experience with monitoring and observability tooling such as Datadog or AWS CloudWatch.
Familiarity with SQL databases.
Strong communication and interpersonal skills, with comfort coordinating closely with a Technical Program Manager and Software Developer.
Ability to work both independently and as part of a small, tightly coordinated team.
Nice to Have
Hands-on experience with dependency/software composition scanning, vulnerability management platforms (e.g., Nucleus), or DAST tooling in a production environment.
Interest or hands-on experience evaluating AI-assisted security or DevOps tooling e.g., AI-assisted vulnerability triage, code scanning, or remediation suggestions.
Exposure to broader security vulnerability management, such as CVE triage, or experience working with enterprise security teams.
Familiarity with data platform or reporting migrations (e.g., Splunk, Snowflake, Sigma, or similar tools).
Experience with containerization and orchestration (e.g., Docker, ECS, Kubernetes).
Scripting experience (e.g., Python, Bash, Node) for automation and tooling.
Experience working on a cross-functional Agile Scrum team.
Engagement Details
Engagement type: Contract, 6 12 months.
Team composition: 1 Technical Program Manager, 1 Software Engineer, 1 DevOps Engineer (this role) (working within a broader My*** delivery team).
Primary tools: Jira and Confluence (day-to-day use required), plus AWS, GitHub, and security/vulnerability scanning tooling (specific toolset TBD).
Location and reporting structure: Remote; reports to the Technical Program Manager on this engagement.