About the job
About the Role
We are seeking a skilled DevOps Security Engineer to integrate security at every level of our infrastructure and deployment pipeline. Your responsibilities will include cloud security, vulnerability management, secrets management, and CI/CD hardening—ensuring that security is a core foundation rather than an afterthought. Reporting to the DevOps Manager, you will collaborate closely with our engineering team. If you believe that security should enhance speed rather than hinder it, this is the perfect role for you.
Why ThreatAware?
At ThreatAware, we empower security teams with a single source of truth for all devices and tools within their organizations. With over 150 integrations, our platform deploys in under 30 minutes, providing real-time visibility across entire IT estates. Trusted by finance, legal, energy, and healthcare sectors, we are now expanding our capabilities. With six years of precise cyber asset data, we are layering AI to innovate how security teams interact with their data, automate workflows, and proactively manage risks before they escalate. Your role will be critical in establishing secure foundations for this growth.
Your Responsibilities
Design and implement secure-by-default infrastructure that enables engineers to deploy confidently.
- Establish and enforce AWS security best practices: IAM, VPC hardening, encryption, and least-privilege access across all environments.
- Integrate security scanning into CI/CD pipelines, including static analysis, dependency scanning, container image scanning, and artifact integrity checks.
- Design and maintain a secrets management architecture, ensuring zero hardcoded credentials across the codebase.
- Support incident response efforts by investigating security events, containing threats, conducting root-cause analysis, and refining runbooks.
- Build and maintain observability across infrastructure and security through monitoring, alerting, and dashboards that highlight issues before they escalate.
- Promote a security-focused culture within the engineering team by delivering training, creating guardrails, and simplifying the process for developers to write secure code.
What We Are Looking For
- Proven experience in DevSecOps or infrastructure security with practical expertise in AWS (IAM, VPC, Config).
- In-depth knowledge of CI/CD security, container security, and infrastructure-as-code security practices.
- Proficiency in TypeScript and/or PowerShell for automation.
- Experience with vulnerability scanning, secrets management tools, and compliance frameworks.
- Strong analytical and problem-solving skills, with a passion for security.

