Skip to content

Open nowPosted 10 days ago

Dev Sec Ops Engineer

Peek12 open roles

Pay
MX$75,000 – MX$85,000 a year
Where
Mexico
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDev Sec Ops EngineerPeek · Mexico
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Peek's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Peek postings stay open a median of 20 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 10 days ago

Peek median: 20 days open

The posting

Peek is the operating system powering the experiences industry - from museums and attractions to tours and activities. With over $7B in bookings, Peek’s AI-powered platform has helped thousands of merchants to increase revenues, save time, and deliver seamless guest experiences. Customers include MoMA, Whitney Museum, Seattle Aquarium, Bryant Park & Looping Group. The company has raised over $150 million from institutional investors Westcap, Goldman Sachs, and SpringCoast Partners. Learn more at www.peek.com http://www.peek.com.

As a remote-first company recognized by Forbes as one of America's Best Startup Employers and by Built In as a 2025 and 2026 Best Place to Work, we are a global team of "Peeksters" who "Obsess Over Our Customers," "Accomplish Big Things," "Collaborate With Purpose," and "Get Better Every Day.

We're looking for a hands-on DevSecOps Engineer to embed security into our infrastructure, CI/CD pipelines, and cloud environment. You'll own the technical controls and evidence that keep us PCI DSS 4.0 and SOC 2 Type II compliant, drive vulnerability remediation across our container and VM fleet, and build out the disaster recovery testing program. This is a role for someone who's comfortable moving between hands-on technical remediation, audit-facing documentation, and cross-functional work with engineering, IT, and procurement.

Our team is 100% remote, however, we prefer candidates in the same time zones as the greater United States (UTC-10 to UTC-4).

We will occasionally require you to work outside of normal business hours on infrastructure upgrades and maintenance. We are committed to working with you to keep a healthy and balanced schedule.

About the Team

We’re a small DevOps team supporting the whole Engineering organization, building applications on top of GCP and AWS. We own all aspects of the SDLC but strive to automate self-service wherever possible. Being a small team, we also practice SRE, continuously improving our observability and building with Infrastructure-as-Code. Security and compliance best practices are integral to our workflows, ensuring systems are secure by design and meet regulatory and organizational standards. Our team is remote but highly organized to meet the demand of a fast-paced environment. Our primary business language is English, and we emphasize strong communication skills.

About You

You're a security-minded engineer who's as comfortable in a Kubernetes cluster or CI/CD pipeline as you are explaining a control to an auditor. You own remediation end to end, like automating away repetitive security work, and are energized by helping a growing company scale security without slowing the business down.

What You'll Do

- Own technical security controls across GCP and AWS: least-privilege IAM and RBAC, WAF, container and image security, and secure CI/CD.

- Drive vulnerability remediation end to end: triage, prioritize, and automate fixes, partnering with the rest of the DevOps team on production rollout.

- Build automated scanning and remediation into our pipelines.

- Tune WAF policies and the OWASP Core Rule Set to protect public-facing applications without blocking legitimate traffic.

- Run PCI DSS vulnerability scanning, including quarterly external ASV scans, and drive remediation of findings.

- Contribute to incident response planning and exercises, and ensure backups and recovery processes meet security requirements for encryption, access, and integrity.

- Produce and automate evidence for technical controls, and keep our cloud environments connected to our compliance platform (Drata).

- Serve as technical expert for audits, customer security reviews, and vendor assessments involving sensitive data.

Requirements

- 3+ years in DevSecOps, security engineering, cloud security, or a closely related role

- Hands-on experience securing GCP and/or AWS, including managed Kubernetes (GKE, EKS)

- Container and vulnerability management, including building automated remediation (tools such as Trivy, AWS Inspector, Amazon ECR scanning, GCP Artifact Analysis, ZAP)

- WAF configuration and OWASP Core Rule Set tuning (Cloud Armor, AWS WAF, Cloudflare, or similar)

- Least-privilege access management across cloud services (IAM, RBAC)

- Working Linux knowledge sufficient to remediate OS and package vulnerabilities in VMs and container images

- Scripting in Python, Bash, or similar

- CI/CD experience (GitLab CI, GitHub Actions, Jenkins, Codefresh, or similar)

- Experience working in a PCI DSS or SOC 2 environment, including producing evidence for technical controls

- Clear written communication with both technical and non-technical audiences

Nice to Haves

- Low-downtime patching approaches (rolling updates, blue/green, live patching such as kpatch or Livepatch)

- PCI ASV scanning with Tenable or a comparable platform

- Drata or a similar compliance automation platform

- Serverless platforms (Cloud Run, Cloud Functions, AWS Lambda)

- Cloud security posture tools such as ScoutSuite or Mondoo

- Contributing to third-party risk reviews involving PII

- Agentic or AI-assisted penetration testing

- Certifications such as OSCP, CISSP, CISM, or AWS/GCP Security Specialty

Peek Travel Inc. is an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, disability, or other legally protected status.

If you are unable to apply due to incompatible assistive technology or a disability, please contact us at [email protected]. We will make every effort to respond to your request for disability assistance as soon as possible.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Peek's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Peek's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Peek's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.