DevSecOps Engineer

Uvik Software Verified Employer

Short-Term  Engagement, with potential ongoing advisory support

 

We are looking for a DevSecOps Engineer with 3+ years of experience to help audit, strengthen, and improve the security posture of a small but growing SaaS platform serving nonprofit and corporate clients.

OVERLAP 14:00–16:00 Mountain Time (MT)

 

This role is security-first, with DevOps responsibilities as a secondary layer. The main goal is to assess the current infrastructure, identify security and compliance gaps, and implement a practical roadmap to improve the platform’s overall resilience, compliance readiness, and long-term sustainability.


What we are looking for:

β€” 3+ years of hands-on experience in DevSecOps, DevOps with a strong security focus, or cloud/infrastructure security

β€” Strong experience with AWS and cloud security best practices

β€” Experience with GitHub Actions, CI/CD security, Docker, and container/image scanning

β€” Experience reviewing and securing hosted platforms, including PaaS environments such as Render or similar

β€” Solid understanding of IAM/access control, secrets management, DNS security, backups, disaster recovery, and infrastructure hardening

β€” Experience identifying and remediating security gaps in small or mid-sized SaaS environments

β€” Familiarity with SOC 2 controls and general compliance-oriented security practices

β€” Ability to recommend pragmatic, cost-conscious solutions for a small team

β€” Strong communication skills and ability to explain risks, tradeoffs, and priorities clearly to non-security stakeholders

β€” English level: B2 minimum

Project scope:

β€” Initial security and infrastructure audit

β€” Identify risks, vulnerabilities, and operational gaps

β€” Build and prioritize a remediation roadmap

β€” Implement key improvements over a 2–3 month engagement

β€” Potential for ongoing periodic security reviews and advisory support afterward
 

Current stack / environment:

β€” Git

β€” GitHub Actions

β€” Docker

β€” AWS

β€” Render
 

What you will do:

β€” Audit the current cloud and application setup from a security and DevSecOps perspective

β€” Review infrastructure, deployment processes, DNS configuration, access controls, and backup/disaster recovery practices

β€” Identify gaps related to SOC 2 readiness and help prepare for stronger enterprise security expectations

β€” Assess security controls around CI/CD, secrets management, container images, user access, and production environments

β€” Review existing vulnerability scanning practices and recommend improvements, including dynamic scanning where needed

β€” Help define and implement practical controls such as firewalling, hardening, monitoring, least-privilege access, and security hygiene improvements

β€” Investigate risks related to DNS, exposed services, stale records, misconfigurations, and other overlooked infrastructure issues

β€” Support the team in creating a sustainable, right-sized security approach for a small organization without overengineering

β€” Translate findings into an actionable roadmap with clear priorities, balancing risk, cost, and implementation effort

β€” Help improve confidence in responding to enterprise security questionnaires from large corporate clients
 

Required languages

English B2 - Upper Intermediate
Ukrainian Native
Published 17 March
70 views
Β·
6 applications
67% read
Β·
17% responded
Last responded yesterday
To apply for this and other jobs on Djinni login or signup.
Loading...