Skip to content

Open nowPosted 8 hours agoWe saw it 13 min after it went up

DevSecOps Engineer

A-LIGN External12 open roles

Where
Panama - Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDevSecOps EngineerA-LIGN External · Panama - Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on A-LIGN External's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. A-LIGN External postings stay open a median of 30 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 hours ago

A-LIGN External median: 30 days open

The posting

About the Role

The DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. As the DevSecOps Engineer, you will provide exceptional technical and security strategies to help support the continued growth of our fast-paced company. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.

Reports to

Principal Security Engineer

Pay Classification

Full-Time

Responsibilities

  • Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications
  • Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments
  • Deliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation
  • Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation
  • Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools
  • Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply
  • Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence
  • Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification
  • Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows
  • Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams
  • Perform security impact analysis for production changes and maintain pre-production security deployment checklists
  • Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews

Minimum Qualifications

EDUCATION

  • Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience

EXPERIENCE

  • At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering
  • Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language
  • Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting
  • Experience using Terraform or a similar infrastructure as code platform in production environments
  • Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration
  • Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation
  • Experience with scripting and automation using Python, shell, SQL, or similar tools
  • Experience working in regulated or compliance-driven environments preferred
  • Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks
  • Familiarity with FIPS 140-2 or FIPS 140-3 requirements preferred
  • Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling preferred
  • Experience operating in a private equity-backed or high-growth environment preferred

CERTIFICATIONS

  • Preferred: CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification

SKILLS

  • Ability to translate security and compliance requirements into practical engineering changes and implement them directly
  • Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs
  • Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks
  • Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams
  • Self-directed with strong follow-through in a fast-paced, deadline-driven environment
  • Ability to work individually as well as collaboratively across technical and business teams
  • Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification

Benefits

  • Employer Paid Life & Health Insurance
  • Competitive Bonus Structure
  • Home Office Reimbursement
  • Technology Allowance
  • Certification Reimbursement
  • BeneficiaT Discount Loyalty Program
  • Personalized Career Coaching
  • Generous Paid Time Off
  • Paid Office Closure December 25-January 1
  • Summer Hours

About A-LIGN

A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.

Come Work for A-LIGN!

Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn.

A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply!

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against A-LIGN External's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on A-LIGN External's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    A-LIGN External's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.