{"schemaVersion":"jobsearcher.job.v1","id":"d4aa46a29821243a1411fc34","url":"https://jobsearcher.com/jobs/d4aa46a29821243a1411fc34","canonicalUrl":"https://jobsearcher.com/jobs/d4aa46a29821243a1411fc34","title":"DevSecOps / Infrastructure Engineer","description":"As we take on more government and defense work, the security and integrity of our infrastructure becomes its own discipline — and we want someone who owns it rather than spreading it thin across the product engineers. The \"sec\" in this role is the point: you'll be responsible for how sensitive data moves, where it lives, and who can see it, so the rest of the team can focus on building.What you'll doOwn our infrastructure and deployment pipeline — including deploying into containerized, customer-provided environments and on Azure.Own the security posture for controlled and sensitive data: data transmission, storage, access control, key management, and who can and can't see what.Drive our compliance program from identification into implementation — NIST controls (we're already tracking these in ControlMap), CMMC / SPRS, and recurring assessments like SOC 2 Type II.Partner with leadership and IT on compliance requirements and timelines, and turn a backlog of controls into an ongoing, sustainable program that doesn't grind product velocity to a halt.Take security concerns off the plates of full-stack and ML engineers so they can ship.What we're looking forU.S. citizenship (required). This role works with sensitive government Controlled Unclassified Information (CUI) and is subject to government contract requirements.Strong DevOps / infrastructure background — CI/CD, cloud (Azure especially), containerized deployments, and infrastructure-as-code.Hands-on security experience: access control, data segregation, secrets/key management, secure environments.Experience implementing and maintaining compliance frameworks — NIST 800-171 / CMMC, SOC 2, or similar — not just reading them.A pragmatic mindset about doing this well on a small team without over-building.Nice to haveDirect defense or government contracting experience and familiarity with CUI handling.CISO-adjacent experience defining data-access and data-residency policy.","company":"Arcessio","rawCompany":"arcessio","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-07-18T14:23:40.266Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"DevSecOps / Infrastructure Engineer","description":"As we take on more government and defense work, the security and integrity of our infrastructure becomes its own discipline — and we want someone who owns it rather than spreading it thin across the product engineers. The \"sec\" in this role is the point: you'll be responsible for how sensitive data moves, where it lives, and who can see it, so the rest of the team can focus on building.What you'll doOwn our infrastructure and deployment pipeline — including deploying into containerized, customer-provided environments and on Azure.Own the security posture for controlled and sensitive data: data transmission, storage, access control, key management, and who can and can't see what.Drive our compliance program from identification into implementation — NIST controls (we're already tracking these in ControlMap), CMMC / SPRS, and recurring assessments like SOC 2 Type II.Partner with leadership and IT on compliance requirements and timelines, and turn a backlog of controls into an ongoing, sustainable program that doesn't grind product velocity to a halt.Take security concerns off the plates of full-stack and ML engineers so they can ship.What we're looking forU.S. citizenship (required). This role works with sensitive government Controlled Unclassified Information (CUI) and is subject to government contract requirements.Strong DevOps / infrastructure background — CI/CD, cloud (Azure especially), containerized deployments, and infrastructure-as-code.Hands-on security experience: access control, data segregation, secrets/key management, secure environments.Experience implementing and maintaining compliance frameworks — NIST 800-171 / CMMC, SOC 2, or similar — not just reading them.A pragmatic mindset about doing this well on a small team without over-building.Nice to haveDirect defense or government contracting experience and familiarity with CUI handling.CISO-adjacent experience defining data-access and data-residency policy.","datePosted":"2026-07-18T14:23:40.266Z","dateModified":"2026-07-18T14:23:40.266Z","hiringOrganization":{"@type":"Organization","name":"Arcessio","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"d4aa46a29821243a1411fc34"},"url":"https://jobsearcher.com/jobs/d4aa46a29821243a1411fc34"}}