{"schemaVersion":"jobsearcher.job.v1","id":"40ca343f2a12a01a0e6d943d","url":"https://jobsearcher.com/jobs/40ca343f2a12a01a0e6d943d","canonicalUrl":"https://jobsearcher.com/jobs/40ca343f2a12a01a0e6d943d","title":"DevSecOps Engineer","description":"Job Description\n\nThe DevSecOps Engineer secures the platform that hardware engineering teams trust to ship every day. You'll own the security engineering layer of Duro's modern stack—cloud security posture, detection and threat hunting, security telemetry, and the security infrastructure that protects multi-tenant, dedicated, and regulated (GovCloud/ITAR) environments. This is a security-first role on a small, fast-moving team reporting into the CISO organization, where you'll partner closely with platform engineering, product, and compliance to make security an accelerator rather than a gate. We're looking for an engineer who thinks in adversaries and systems, automates relentlessly, and leverages modern AI-augmented workflows to build defenses that scale. This is a hybrid role based in Los Angeles, CA (3 days per week in office).\n\nA day in the life of our DevSecOps Engineer:\n\nCloud Security Engineering: Design and operate the security posture of Duro's AWS commercial and GovCloud environments—IAM and least-privilege access models, KMS/encryption policy, VPC segmentation, network controls, and secure-by-default guardrails across accounts and tenants.\nThreat Detection & Hunting: Proactively hunt across cloud, application, and identity telemetry for anomalous and adversarial behavior. Build and tune detections as code, reduce false positives, and turn hunt findings into durable, automated coverage.\nThreat Intelligence: Operationalize threat intelligence—integrate feeds, contextualize indicators and TTPs against Duro's attack surface, and drive proactive hardening ahead of emerging threats.\nLogging, Monitoring & Reporting: Architect and administer centralized logging, SIEM, and security monitoring across the stack. Own alerting pipelines, dashboards, and the security metrics and reporting that inform leadership, customers, and compliance evidence.\nSecurity Infrastructure Implementation & Administration: Implement, administer, and continuously improve the security tooling estate—CSPM, vulnerability management, endpoint and workload protection, secrets management, and cloud-native security services (GuardDuty, Security Hub, CloudTrail, Config, WAF, Inspector).\nApplication & Pipeline Security: Embed security into the SDLC and CI/CD—secure GitHub Actions pipelines, integrate SAST/DAST/SCA, enforce secrets hygiene, and secure container and Kubernetes workloads from build through runtime.\nSecurity as Code: Build reproducible, version-controlled security infrastructure and guardrails using Terraform, policy-as-code, and containerization—so controls are enforced automatically and drift is caught early.\nCompliance-Driven Controls: Partner with CISO leadership to implement and evidence controls mapped to SOC 2, ITAR, and GovCloud requirements, translating framework obligations into concrete technical enforcement.\nAI-Driven Security Engineering: Leverage AI-augmented workflows to accelerate detection engineering, triage, and control implementation while maintaining rigorous validation and review standards.\nIncident Response: Support detection, investigation, containment, and post-incident hardening—reducing mean time to detect and respond, and feeding lessons learned back into automated coverage.\n\nQualifications\n\nRequired:\n\n7+ years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure\nBachelor's degree in Computer Science or related field (or equivalent practical experience)\nDeep AWS security expertise—IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF—including hands-on experience across commercial and GovCloud environments\nDemonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code\nExperience operationalizing threat intelligence to drive proactive defense\nStrong background in logging, monitoring, and security reporting—centralized logging, SIEM design and administration, alerting, dashboards, and metrics\nExperience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection)\nApplication and pipeline security experience—securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads\nInfrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls\nAn innovative, adversarial mindset—you anticipate how systems break and automate the defense before it's needed\nStrong systems thinking and the ability to design scalable, secure, maintainable controls\nExcellent written and verbal communication skills\nComfort operating in autonomous, fast-paced environments\n\nNice to Have:\n\nRelevant certifications (AWS Security Specialty, CISSP, OSCP, GCIH/GCIA/GCFA, or similar)\nExperience with DuploCloud or similar tenant/cloud management platforms\nKnowledge of compliance frameworks such as SOC 2, FedRAMP, ITAR, or CMMC\nExperience building security for PLM, PDM, or hardware/manufacturing industry software\nBackground supporting compliance-driven or regulated (GovCloud, on-premises) deployments\nIncident response, digital forensics, or purple-team experience\nFamiliarity with observability tooling such as Datadog, PostHog, or Sentry, and event-driven systems (NATS, Redis, Kafka)\nPostgreSQL and Kubernetes operational familiarity sufficient to secure and reason about those workloads\n\nHow We Build\n\nWe don't just ship features. We build platforms that make shipping inevitable—and secure by default.\n\nAt Duro, AI is integrated into our engineering and security workflows. Engineers leverage AI-powered environments to orchestrate tasks, structure context, and accelerate delivery and defense while maintaining high standards of operational and security excellence.\n\nWe value:\n\nAdversarial intuition — understanding how systems fail and how attackers think before building the defense Detection over hope — coverage you can measure, tune, and trust, expressed as code Precision in communication — clear control design produces reliable, auditable systems Pattern recognition — knowing when to abstract, automate, or simplify Operational discipline — building controls that are observable, resilient, and self-healing Intellectual curiosity — continuously improving how we secure and scale\n\nWe optimize for engineers who can build security that fades into the background—enabling teams to deploy daily with confidence, not friction.\n\nAdditional Information\n\nThe expected annual pay range for this position is $150,000-$160,000. This position is also eligible for bonus opportunities. Please note that final offer amount will be dependent on geographic location, applicable experience, and skillset of the candidate.\n\nRenesas offers a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, and pet insurance. In addition to elective benefit options, benefited employees receive company-paid life insurance and AD&D, LTD, short term medical benefits as well as paid sick time, paid holidays, and accrued paid vacation. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.\n\nRenesas is an embedded semiconductor solution provider driven by its Purpose ‘To Make Our Lives Easier.’ As the industry’s leading expert in embedded processing with unmatched quality and system-level know-how, we have evolved to provide scalable and comprehensive semiconductor solutions for automotive, industrial, infrastructure, and IoT industries based on the broadest product portfolio, including High Performance Computing, Embedded Processing, Analog & Connectivity, and Power.\n\nWith a diverse team of over 22,000 professionals in more than 30 countries, we continue to expand our boundaries to offer enhanced user experiences through digitalization and usher into a new era of innovation. We design and develop sustainable, power-efficient solutions today that help people and communities thrive tomorrow, ‘To Make Our Lives Easier.’\n\nAt Renesas, you can:\n\nLaunch and advance your career in technical and business roles across four Product Groups and various corporate functions. You will have the opportunities to explore our hardware and software capabilities and try new things.\nMake a real impact by developing innovative products and solutions to meet our global customers' evolving needs and help make people’s lives easier, safe and secure.\nMaximize your performance and wellbeing in our flexible and inclusive work environment. Our people-first culture and global support system, including the remote work option and Employee Resource Groups, will help you excel from the first day.\n\nAre you ready to own your success and make your mark?\n\nJoin Renesas. Shape Your Future with Us.\n\nRenesas Electronics is an equal opportunity and affirmative action employer, committed to celebrating diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by federal, state or local law. For more information, please read our Diversity & Inclusion Statement.\n\nRenesas Electronics deals with dual-use technology that is subject to U.S. export controls regulations. Under these regulations it may be necessary for Renesas to obtain U.S. government export license prior to release of technology to certain persons. The decision whether or not to file or pursue an export license application is at the sole discretion of Renesas.\n\nAltium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software-defined world with our industry-first cloud-based platform that unites every stakeholder and phase of electronics development.\n\nFrom startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.\n\nWe believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process.","company":"Altium","rawCompany":"altium","city":"Los Angeles","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-27T10:35:02.935Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps Engineer","description":"Job Description\n\nThe DevSecOps Engineer secures the platform that hardware engineering teams trust to ship every day. You'll own the security engineering layer of Duro's modern stack—cloud security posture, detection and threat hunting, security telemetry, and the security infrastructure that protects multi-tenant, dedicated, and regulated (GovCloud/ITAR) environments. This is a security-first role on a small, fast-moving team reporting into the CISO organization, where you'll partner closely with platform engineering, product, and compliance to make security an accelerator rather than a gate. We're looking for an engineer who thinks in adversaries and systems, automates relentlessly, and leverages modern AI-augmented workflows to build defenses that scale. This is a hybrid role based in Los Angeles, CA (3 days per week in office).\n\nA day in the life of our DevSecOps Engineer:\n\nCloud Security Engineering: Design and operate the security posture of Duro's AWS commercial and GovCloud environments—IAM and least-privilege access models, KMS/encryption policy, VPC segmentation, network controls, and secure-by-default guardrails across accounts and tenants.\nThreat Detection & Hunting: Proactively hunt across cloud, application, and identity telemetry for anomalous and adversarial behavior. Build and tune detections as code, reduce false positives, and turn hunt findings into durable, automated coverage.\nThreat Intelligence: Operationalize threat intelligence—integrate feeds, contextualize indicators and TTPs against Duro's attack surface, and drive proactive hardening ahead of emerging threats.\nLogging, Monitoring & Reporting: Architect and administer centralized logging, SIEM, and security monitoring across the stack. Own alerting pipelines, dashboards, and the security metrics and reporting that inform leadership, customers, and compliance evidence.\nSecurity Infrastructure Implementation & Administration: Implement, administer, and continuously improve the security tooling estate—CSPM, vulnerability management, endpoint and workload protection, secrets management, and cloud-native security services (GuardDuty, Security Hub, CloudTrail, Config, WAF, Inspector).\nApplication & Pipeline Security: Embed security into the SDLC and CI/CD—secure GitHub Actions pipelines, integrate SAST/DAST/SCA, enforce secrets hygiene, and secure container and Kubernetes workloads from build through runtime.\nSecurity as Code: Build reproducible, version-controlled security infrastructure and guardrails using Terraform, policy-as-code, and containerization—so controls are enforced automatically and drift is caught early.\nCompliance-Driven Controls: Partner with CISO leadership to implement and evidence controls mapped to SOC 2, ITAR, and GovCloud requirements, translating framework obligations into concrete technical enforcement.\nAI-Driven Security Engineering: Leverage AI-augmented workflows to accelerate detection engineering, triage, and control implementation while maintaining rigorous validation and review standards.\nIncident Response: Support detection, investigation, containment, and post-incident hardening—reducing mean time to detect and respond, and feeding lessons learned back into automated coverage.\n\nQualifications\n\nRequired:\n\n7+ years of hands-on experience in security engineering, cloud security, or DevSecOps with production ownership of security controls and infrastructure\nBachelor's degree in Computer Science or related field (or equivalent practical experience)\nDeep AWS security expertise—IAM, KMS, VPC/network security, GuardDuty, Security Hub, CloudTrail, Config, WAF—including hands-on experience across commercial and GovCloud environments\nDemonstrated experience in threat detection and threat hunting across cloud, application, and identity telemetry, including detection engineering / detection-as-code\nExperience operationalizing threat intelligence to drive proactive defense\nStrong background in logging, monitoring, and security reporting—centralized logging, SIEM design and administration, alerting, dashboards, and metrics\nExperience implementing and administering security infrastructure and tooling (CSPM, vulnerability management, secrets management, workload/endpoint protection)\nApplication and pipeline security experience—securing CI/CD (GitHub Actions), SAST/DAST/SCA integration, secrets management, and securing containerized/Kubernetes workloads\nInfrastructure-as-code proficiency with Terraform and containerization tools such as Docker, applied to security guardrails and controls\nAn innovative, adversarial mindset—you anticipate how systems break and automate the defense before it's needed\nStrong systems thinking and the ability to design scalable, secure, maintainable controls\nExcellent written and verbal communication skills\nComfort operating in autonomous, fast-paced environments\n\nNice to Have:\n\nRelevant certifications (AWS Security Specialty, CISSP, OSCP, GCIH/GCIA/GCFA, or similar)\nExperience with DuploCloud or similar tenant/cloud management platforms\nKnowledge of compliance frameworks such as SOC 2, FedRAMP, ITAR, or CMMC\nExperience building security for PLM, PDM, or hardware/manufacturing industry software\nBackground supporting compliance-driven or regulated (GovCloud, on-premises) deployments\nIncident response, digital forensics, or purple-team experience\nFamiliarity with observability tooling such as Datadog, PostHog, or Sentry, and event-driven systems (NATS, Redis, Kafka)\nPostgreSQL and Kubernetes operational familiarity sufficient to secure and reason about those workloads\n\nHow We Build\n\nWe don't just ship features. We build platforms that make shipping inevitable—and secure by default.\n\nAt Duro, AI is integrated into our engineering and security workflows. Engineers leverage AI-powered environments to orchestrate tasks, structure context, and accelerate delivery and defense while maintaining high standards of operational and security excellence.\n\nWe value:\n\nAdversarial intuition — understanding how systems fail and how attackers think before building the defense Detection over hope — coverage you can measure, tune, and trust, expressed as code Precision in communication — clear control design produces reliable, auditable systems Pattern recognition — knowing when to abstract, automate, or simplify Operational discipline — building controls that are observable, resilient, and self-healing Intellectual curiosity — continuously improving how we secure and scale\n\nWe optimize for engineers who can build security that fades into the background—enabling teams to deploy daily with confidence, not friction.\n\nAdditional Information\n\nThe expected annual pay range for this position is $150,000-$160,000. This position is also eligible for bonus opportunities. Please note that final offer amount will be dependent on geographic location, applicable experience, and skillset of the candidate.\n\nRenesas offers a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, and pet insurance. In addition to elective benefit options, benefited employees receive company-paid life insurance and AD&D, LTD, short term medical benefits as well as paid sick time, paid holidays, and accrued paid vacation. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.\n\nRenesas is an embedded semiconductor solution provider driven by its Purpose ‘To Make Our Lives Easier.’ As the industry’s leading expert in embedded processing with unmatched quality and system-level know-how, we have evolved to provide scalable and comprehensive semiconductor solutions for automotive, industrial, infrastructure, and IoT industries based on the broadest product portfolio, including High Performance Computing, Embedded Processing, Analog & Connectivity, and Power.\n\nWith a diverse team of over 22,000 professionals in more than 30 countries, we continue to expand our boundaries to offer enhanced user experiences through digitalization and usher into a new era of innovation. We design and develop sustainable, power-efficient solutions today that help people and communities thrive tomorrow, ‘To Make Our Lives Easier.’\n\nAt Renesas, you can:\n\nLaunch and advance your career in technical and business roles across four Product Groups and various corporate functions. You will have the opportunities to explore our hardware and software capabilities and try new things.\nMake a real impact by developing innovative products and solutions to meet our global customers' evolving needs and help make people’s lives easier, safe and secure.\nMaximize your performance and wellbeing in our flexible and inclusive work environment. Our people-first culture and global support system, including the remote work option and Employee Resource Groups, will help you excel from the first day.\n\nAre you ready to own your success and make your mark?\n\nJoin Renesas. Shape Your Future with Us.\n\nRenesas Electronics is an equal opportunity and affirmative action employer, committed to celebrating diversity and fostering a work environment free of discrimination on the basis of sex, race, religion, national origin, gender, gender identity, gender expression, age, sexual orientation, military status, veteran status, or any other basis protected by federal, state or local law. For more information, please read our Diversity & Inclusion Statement.\n\nRenesas Electronics deals with dual-use technology that is subject to U.S. export controls regulations. Under these regulations it may be necessary for Renesas to obtain U.S. government export license prior to release of technology to certain persons. The decision whether or not to file or pursue an export license application is at the sole discretion of Renesas.\n\nAltium Limited, a part of the Renesas Group and headquartered in San Diego, California, is a global software company accelerating the pace of electronics innovation. We are redefining electronic product creation in a software-defined world with our industry-first cloud-based platform that unites every stakeholder and phase of electronics development.\n\nFrom startups to world’s technology giants, our digital platforms give more power to PCB designers, supply chain, and manufacturing, letting them collaborate as never before. At Altium, our teams are empowered to innovate, collaborate globally, and help create the future of electronics development.\n\nWe believe in rewarding our employees with a competitive benefits package alongside their salary. More information will be provided during the hiring process.","datePosted":"2026-08-27T10:35:02.935Z","dateModified":"2026-08-27T10:35:02.935Z","hiringOrganization":{"@type":"Organization","name":"Altium","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Los Angeles","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"40ca343f2a12a01a0e6d943d"},"url":"https://jobsearcher.com/jobs/40ca343f2a12a01a0e6d943d"}}