{"schemaVersion":"jobsearcher.job.v1","id":"7cb61e3ec9bce99d85f48d2a","url":"https://jobsearcher.com/jobs/7cb61e3ec9bce99d85f48d2a","canonicalUrl":"https://jobsearcher.com/jobs/7cb61e3ec9bce99d85f48d2a","title":"Senior Staff Engineer - DevSecOps","description":"Job Summary\nWe are seeking a Senior Staff Engineer – DevSecOps to lead the design, implementation, and continuous improvement of cloud security and DevSecOps practices across AWS and Azure environments. This role will be responsible for securing cloud infrastructure, embedding security into CI/CD pipelines, leading incident response, and driving security best practices across the organization while ensuring compliance with regulatory standards.\n\nKey Responsibilities\n\nDesign and implement robust security architectures for cloud environments following best practices, industry standards, and regulatory requirements.\n\nLead cross-functional collaboration on technology initiatives to strengthen security across systems and operations, ensuring alignment with organizational objectives and industry best practices.\n\nLead the investigation and resolution of complex security events and incidents, including malware outbreaks, unauthorized access attempts, and significant security breaches. Develop and implement response strategies, coordinate cross-functional teams, and ensure lessons learned are integrated into security policies and controls.\n\nAnalyze security logs and events from various sources to proactively develop and implement security measures that address current and emerging threats.\n\nProvide updates to leaders on latest threat landscape, emerging trends, and propose cybersecurity solutions to proactively identify and mitigate potential security risks.\n\nEnhance the organization’s security posture by assessing vulnerabilities and recommending solutions to address identified weaknesses.\n\nCollaborate with internal teams, vendors, and partners to provide guidance and expertise on security best practices and incident response.\n\nEnsure compliance with industry standards and organizational policies, including SOX and FDA regulatory requirements, by following established procedures and controls.\n\nEducation\n\nBachelor’s degree in related discipline and 9 years of related experience; or\n\nExperience\n\nExperience with operation and implementation of cybersecurity tools.\n\nExperience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.\n\nExperience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead or management experience preferred.\n\nExperience in investigations and response to cyber events and incidents.\n\nExperience in enhancing organizational security awareness and resilience.\n\nExperience with cloud, system, and application security.\n\nExperience administering IT systems.\n\nExperience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).\n\nExperience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.\n\nKnowledge, Skills and Abilities\n\nAdvanced analytical, problem solving, organizational, and communication skills.\n\nGeneral knowledge of Agile, and Design-Thinking, User-centric Design methodologies.\n\nAble to plan, prioritize, and execute projects with minimum supervision and high reliability.\n\nStrong understanding of PII, PHI, and Sensitive Data concepts\n\nKnowledge of applicable laws and regulations such as GDPR and CPRA.\n\nStrong analytical, problem solving, organizational, and communication skills.\n\nAbility to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.\n\nAbility to multitask and work collaboratively.\n\nAbility to work with ambiguity.\n\nAbility to work with confidential data.\n\nAbility to continuously learn and improve.\n\nAbility to work with minimal guidance, to adapt to frequent priority changes, and response to ad-hoc requests\n\nArchitect secure cloud infrastructure using guardrails and golden paths using IaC patterns across AWS and Azure.\n\nIntegrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines and provide help and support\n\nAWS Certified Security - Specialty preferred\n\n#J-18808-Ljbffr","company":"Usefulbi Technology","rawCompany":"usefulbi technology","city":"Alameda","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-08-02T03:10:47.912Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Staff Engineer - DevSecOps","description":"Job Summary\nWe are seeking a Senior Staff Engineer – DevSecOps to lead the design, implementation, and continuous improvement of cloud security and DevSecOps practices across AWS and Azure environments. This role will be responsible for securing cloud infrastructure, embedding security into CI/CD pipelines, leading incident response, and driving security best practices across the organization while ensuring compliance with regulatory standards.\n\nKey Responsibilities\n\nDesign and implement robust security architectures for cloud environments following best practices, industry standards, and regulatory requirements.\n\nLead cross-functional collaboration on technology initiatives to strengthen security across systems and operations, ensuring alignment with organizational objectives and industry best practices.\n\nLead the investigation and resolution of complex security events and incidents, including malware outbreaks, unauthorized access attempts, and significant security breaches. Develop and implement response strategies, coordinate cross-functional teams, and ensure lessons learned are integrated into security policies and controls.\n\nAnalyze security logs and events from various sources to proactively develop and implement security measures that address current and emerging threats.\n\nProvide updates to leaders on latest threat landscape, emerging trends, and propose cybersecurity solutions to proactively identify and mitigate potential security risks.\n\nEnhance the organization’s security posture by assessing vulnerabilities and recommending solutions to address identified weaknesses.\n\nCollaborate with internal teams, vendors, and partners to provide guidance and expertise on security best practices and incident response.\n\nEnsure compliance with industry standards and organizational policies, including SOX and FDA regulatory requirements, by following established procedures and controls.\n\nEducation\n\nBachelor’s degree in related discipline and 9 years of related experience; or\n\nExperience\n\nExperience with operation and implementation of cybersecurity tools.\n\nExperience in designing, implementing, and managing security controls within cloud platforms, such as IAM, VPC, Zero Trust principles, IaC, IAAS, Security Groups, Key Management Services, SDLC, Ci/Cd pipelines and Network Security.\n\nExperience in IT Security or related infrastructure administration role in an enterprise environment. Technical lead or management experience preferred.\n\nExperience in investigations and response to cyber events and incidents.\n\nExperience in enhancing organizational security awareness and resilience.\n\nExperience with cloud, system, and application security.\n\nExperience administering IT systems.\n\nExperience working in Agile environments and using ticketing systems (e.g., JIRA, JSM).\n\nExperience in regulated industries (e.g., biotech, pharma) with knowledge of GxP and SOX compliance preferred.\n\nKnowledge, Skills and Abilities\n\nAdvanced analytical, problem solving, organizational, and communication skills.\n\nGeneral knowledge of Agile, and Design-Thinking, User-centric Design methodologies.\n\nAble to plan, prioritize, and execute projects with minimum supervision and high reliability.\n\nStrong understanding of PII, PHI, and Sensitive Data concepts\n\nKnowledge of applicable laws and regulations such as GDPR and CPRA.\n\nStrong analytical, problem solving, organizational, and communication skills.\n\nAbility to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability.\n\nAbility to multitask and work collaboratively.\n\nAbility to work with ambiguity.\n\nAbility to work with confidential data.\n\nAbility to continuously learn and improve.\n\nAbility to work with minimal guidance, to adapt to frequent priority changes, and response to ad-hoc requests\n\nArchitect secure cloud infrastructure using guardrails and golden paths using IaC patterns across AWS and Azure.\n\nIntegrate SAST, SCA, DAST, and dependency scanning into GitHub pipelines and provide help and support\n\nAWS Certified Security - Specialty preferred\n\n#J-18808-Ljbffr","datePosted":"2026-08-02T03:10:47.912Z","dateModified":"2026-08-02T03:10:47.912Z","hiringOrganization":{"@type":"Organization","name":"Usefulbi Technology","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Alameda","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7cb61e3ec9bce99d85f48d2a"},"url":"https://jobsearcher.com/jobs/7cb61e3ec9bce99d85f48d2a"}}