About the job
Join Our Team at ThriveCart!
About ThriveCart:
ThriveCart stands as the premier no-code sales platform tailored for digital course creators, coaches, entrepreneurs, and online businesses eager to optimize revenue streams, enhance conversion rates, and expand their audience reach. With a remarkable track record, ThriveCart supports over 65,000 businesses and has facilitated the enrollment of 12 million students, generating an impressive $2 billion in annual sales. Our platform is equipped with all essential tools for crafting high-converting checkout experiences, managing robust affiliate campaigns, and providing seamless user experiences via our integrated learning management system, Learn/Learn+.
Job Overview:
We are seeking a proactive Senior DevSecOps Engineer dedicated to securing and overseeing ThriveCart's e-commerce platform infrastructure. You will play a pivotal role in automating deployments, enhancing production observability, and implementing security measures to ensure our infrastructure's integrity and availability.
Key Responsibilities:
Infrastructure & Systems Security
- Implement and uphold security scanning protocols within our CI/CD processes (SAST, dependency checks, container security).
- Fortify AWS infrastructure using WAF and Security Groups while managing network segmentation.
- Monitor security advisories, coordinate timely patching, and ensure vulnerability remediation.
- Manage encryption processes (both in transit and at rest), secure compute resources, and audit IAM policies.
- Provide security dashboards and tooling to assist developers in addressing security findings.
Threat Detection & Observability
- Maintain CloudWatch dashboards for monitoring payment metrics, database health, and API performance.
- Configure GuardDuty and Security Hub to build alerts for DDoS attacks, intrusion attempts, and anomalies.
- Oversee production health, investigate anomalies, and conduct root cause analysis.
- Develop investigation queries for security incidents and maintain response runbooks.
- Monitor for potential penetration attempts, API misuse, and suspicious access patterns.
Infrastructure as Code & Operations
- Manage AWS resources utilizing Terraform (EC2, RDS, IAM, VPC) with a security-first approach.
- Ensure zero-downtime CI/CD pipelines with integrated security gates and rollback mechanisms.
- Administer MariaDB database and oversee operational tasks.

