DevSecOps Engineer
Short-Term Engagement, with potential ongoing advisory support
We are looking for a DevSecOps Engineer with 3+ years of experience to help audit, strengthen, and improve the security posture of a small but growing SaaS platform serving nonprofit and corporate clients.
OVERLAP 14:00β16:00 Mountain Time (MT)
This role is security-first, with DevOps responsibilities as a secondary layer. The main goal is to assess the current infrastructure, identify security and compliance gaps, and implement a practical roadmap to improve the platformβs overall resilience, compliance readiness, and long-term sustainability.
What we are looking for:
β 3+ years of hands-on experience in DevSecOps, DevOps with a strong security focus, or cloud/infrastructure security
β Strong experience with AWS and cloud security best practices
β Experience with GitHub Actions, CI/CD security, Docker, and container/image scanning
β Experience reviewing and securing hosted platforms, including PaaS environments such as Render or similar
β Solid understanding of IAM/access control, secrets management, DNS security, backups, disaster recovery, and infrastructure hardening
β Experience identifying and remediating security gaps in small or mid-sized SaaS environments
β Familiarity with SOC 2 controls and general compliance-oriented security practices
β Ability to recommend pragmatic, cost-conscious solutions for a small team
β Strong communication skills and ability to explain risks, tradeoffs, and priorities clearly to non-security stakeholders
β English level: B2 minimum
Project scope:
β Initial security and infrastructure audit
β Identify risks, vulnerabilities, and operational gaps
β Build and prioritize a remediation roadmap
β Implement key improvements over a 2β3 month engagement
β Potential for ongoing periodic security reviews and advisory support afterward
Current stack / environment:
β Git
β GitHub Actions
β Docker
β AWS
β Render
What you will do:
β Audit the current cloud and application setup from a security and DevSecOps perspective
β Review infrastructure, deployment processes, DNS configuration, access controls, and backup/disaster recovery practices
β Identify gaps related to SOC 2 readiness and help prepare for stronger enterprise security expectations
β Assess security controls around CI/CD, secrets management, container images, user access, and production environments
β Review existing vulnerability scanning practices and recommend improvements, including dynamic scanning where needed
β Help define and implement practical controls such as firewalling, hardening, monitoring, least-privilege access, and security hygiene improvements
β Investigate risks related to DNS, exposed services, stale records, misconfigurations, and other overlooked infrastructure issues
β Support the team in creating a sustainable, right-sized security approach for a small organization without overengineering
β Translate findings into an actionable roadmap with clear priorities, balancing risk, cost, and implementation effort
β Help improve confidence in responding to enterprise security questionnaires from large corporate clients
Required languages
| English | B2 - Upper Intermediate |
| Ukrainian | Native |