Enter a job title or keyword

DevSecOps Engineer


Job Location:

Austin, TX - USA

Monthly Salary: Not provided by the employer
Posted: 27 August 2026 (15 hours ago)
Application Deadline: 24 November 2026
Vacancies: 1 Vacancy

Job Summary

Overview

We are designing the grid of the future!

We are seeking an experienced DevSecOps Engineer to strengthen the security of our cloud platforms software delivery pipelines and production environments. The ideal candidate will combine deep AWS Terraform Kubernetes and automation expertise with a strong security engineering mindset. This role will embed security throughout the software and infrastructure lifecycle automate security controls reduce cloud and application risk and help engineering teams ship securely without creating unnecessary delivery friction.

The DevSecOps Engineer will partner closely with software engineering Site Reliability Engineering platform security compliance and product teams to establish secure-by-default patterns improve visibility into risk and ensure that security controls are measurable scalable and operationally sustainable.

Responsibilities

Howyou can make an impact:

  • Cloud Security Engineering: Design implement and maintain security controls across AWS environments including IAM VPC networking encryption secrets management logging account governance and service configuration.
  • Infrastructure as Code Security: Build and maintain secure Terraform modules and policies that enforce approved infrastructure patterns least privilege encryption logging tagging network controls and configuration standards.
  • Secure CI/CD: Integrate security checks into CI/CD pipelines including static analysis dependency scanning container scanning secrets detection infrastructure-as-code scanning policy validation and deployment gates.
  • Kubernetes & Container Security: Harden EKS and Kubernetes environments through secure workload configuration RBAC admission controls image security runtime protections network policies secrets management and cluster lifecycle best practices.
  • Identity & Access Management: Develop and enforce least-privilege IAM patterns role-based access controls service identities access review processes and automated remediation for excessive or unused permissions.
  • Vulnerability Management: Establish processes and automation for identifying prioritizing tracking and remediating vulnerabilities across cloud infrastructure containers dependencies operating systems and application platforms.
  • Security Automation: Build Python Bash or other automation to detect misconfigurations validate controls collect evidence remediate security findings and reduce repetitive security operations work.
  • Cloud Detection & Monitoring: Implement and improve security monitoring logging alerting and detection capabilities using AWS-native and third-party tooling including CloudTrail GuardDuty Security Hub CloudWatch SIEM platforms or similar technologies.
  • Software Supply Chain Security: Improve software supply chain integrity through dependency controls artifact signing provenance trusted build pipelines image registries SBOM practices and secure release processes.
  • Secrets & Key Management: Establish secure patterns for credentials API keys certificates encryption keys and secrets using services such as AWS KMS Secrets Manager Parameter Store and related tooling.
  • Security Incident Response: Support investigation and response for cloud and application security incidents including containment root-cause analysis evidence collection remediation and post-incident corrective actions.
  • Compliance & Control Automation: Translate security and compliance requirements into technical controls and automated evidence collection for frameworks such as SOC 2 ISO 27001 PCI DSS or related standards.
  • Security Architecture & Reviews: Perform security reviews for infrastructure changes new services deployment patterns and application architectures; identify risk and recommend practical mitigations.
  • Developer Enablement: Create reusable security patterns documentation guardrails and tooling that make the secure implementation the easiest implementation for engineering teams.
  • Continuous Improvement: Track security posture recurring findings control effectiveness and operational trends to identify opportunities for better automation prevention and risk reduction

Qualifications

Bring your passion heres whats needed:

  • Experience: 3 years of experience in DevSecOps cloud security DevOps platform engineering Site Reliability Engineering or a related discipline including significant responsibility for production cloud environments.
  • AWS: Strong hands-on experience securing AWS services and architectures including IAM Organizations VPC EC2 S3 RDS EKS Lambda Route 53 CloudTrail KMS GuardDuty Security Hub and related services.
  • Terraform: Advanced proficiency with Terraform including secure reusable modules state management policy enforcement code review drift management and infrastructure lifecycle controls.
  • Kubernetes: Strong understanding of Kubernetes and EKS security including RBAC pod security admission controls secrets network policies workload identity image security and cluster hardening.
  • Security Engineering: Strong knowledge of cloud security principles least privilege defense in depth encryption network segmentation secrets management vulnerability management threat modeling and secure configuration.
  • Programming & Automation: Proficiency in Python Bash Go or another general-purpose language used to build security automation and operational tooling.
  • CI/CD Security: Experience integrating security controls into delivery pipelines using platforms such as GitHub Actions Jenkins GitLab CI Argo CD or similar tooling.
  • Security Tooling: Experience with tools for SAST SCA container scanning IaC scanning secrets detection CSPM SIEM or cloud-native security monitoring.
  • Linux & Containers: Strong Linux Docker and container fundamentals with the ability to troubleshoot security and configuration issues across hosts and workloads.
  • Incident Response: Experience investigating security events or production incidents and contributing to containment root-cause analysis remediation and follow-up actions.
  • Compliance: Working knowledge of security control frameworks and audit expectations including evidence collection access reviews logging change controls and technical control validation.
  • Communication: Strong written and verbal communication skills with the ability to explain security risk and recommended controls to both technical and non-technical stakeholders.

Preferred Qualifications

  • AWS security-focused certifications such as AWS Certified Security - Specialty AWS Certified Solutions Architect - Professional or AWS Certified DevOps Engineer - Professional.
  • Experience with policy-as-code tools such as Open Policy Agent (OPA) Conftest Sentinel Kyverno or Gatekeeper.
  • Experience with CSPM/CNAPP platforms vulnerability scanners SIEM platforms or cloud security posture management tooling.
  • Familiarity with supply chain security technologies and standards such as SBOMs SLSA artifact signing provenance and Sigstore/cosign.
  • Experience with GitOps practices and tools such as Argo CD or Flux.
  • Knowledge of security frameworks and standards such as CIS Benchmarks NIST CSF NIST 800-53 SOC 2 ISO 27001 or PCI DSS.

Be a part of an innovative team shaping the grid of the future through advanced energy intelligence. For more than half a century Electric Power Engineers (EPE) has partnered with power and energy clients across the globe providing consulting expertise and energy intelligence software solutions for complex engineering and grid modeling challenges. As leaders in the renewables space we are focused on building a modern secure and resilient grid. Join us in making an impact on the communities we serve and the environment in which we live. Together we can transform the future of energy.

How we support you:

  • Comprehensive health and wellness benefits including medical dental and vision with 100% premium coverage foryou
  • Generous PTO and paid holidays
  • MyShare Employee Ownership Program
  • Work with industry leaders
  • 401K up to a 4% match (100% vested from day 1)

Location: This position will be lRemote.

Travel: Occasional travel may be needed (10% or less)

EPE is an equal opportunity/AA/Disability/Veteran employer. The EEO is the Law poster and its supplement are available using the following links:EEOC is the Law Poster

Third-Party Recruiting Notification

EPE does not accept unsolicited resumes fromthird-party recruiters. Any unsolicited third-party resumes forwarded by recruiters to EPE via our career page or to any of our managers or employees will be considered public information may be treated as a direct application from the person identified in the resume and will not be eligible for placement fee payment to the will not pay a fee to a third-party recruiter or agencywithout a previously signed third-party agreementand has not coordinated their recruiting activity with the appropriate member of the Talent Acquisition team.


Required Experience:

IC