A-Lign
DevSecOps Engineer
Panama - Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- PA
- Work mode
- Remote-friendly
- First seen by hirly
- 2 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About the Role
The DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. As the DevSecOps Engineer, you will provide exceptional technical and security strategies to help support the continued growth of our fast-paced company. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.
Reports to
Principal Security Engineer
Pay Classification
Full-Time
Responsibilities
Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications
Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments
Deliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation
Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation
Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools
Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply
Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence
Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification
Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows
Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams
Perform security impact analysis for production changes and maintain pre-production security deployment checklists
Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews
Minimum Qualifications
EDUCATION
Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience
EXPERIENCE
At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering
Experience developing production software in Go, Python, TypeScript, or a comparable modern programming language
Hands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting
Experience using Terraform or a similar infrastructure as code platform in production environments
Working knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration
Experience managing vulnerabilities and responding to penetration testing findings, including code-level remediation
Experience with scripting and automation using Python, shell, SQL, or similar tools
Experience working in regulated or compliance-driven environments preferred
Familiarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks
Familiarity with FIPS 140-2 or FIPS 140-3 requirements preferred
Experience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling preferred
Experience operating in a private equity-backed or high-growth environment preferred
CERTIFICATIONS
Preferred: CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification
SKILLS
Ability to translate security and compliance requirements into practical engineering changes and implement them directly
Ability to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs
Excellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks
Highly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams
Self-directed with strong follow-through in a fast-paced, deadline-driven environment
Ability to work individually as well as collaboratively across technical and business teams
Demonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification
Benefits
Employer Paid Life & Health Insurance
Competitive Bonus Structure
Home Office Reimbursement
Technology Allowance
Certification Reimbursement
BeneficiaT Discount Loyalty Program
Personalized Career Coaching
Generous Paid Time Off
Paid Office Closure December 25-January 1
Summer Hours
About A-LIGN
A-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com.
Come Work for A-LIGN!
Apply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn .
A-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply!
Similar jobs
- DevOps / SRE / DevSecOps Engineer (AWS) - Latin America, RemoteBluelightconsulting · Colón, PanamaFirst seen 15d agoremote
- DevOps / SRE / DevSecOps Engineer (AWS) - Latin America, RemoteBluelightconsulting · Panama City, PanamaFirst seen 15d agoremote
- Government and Infrastructure - Cybersecurity - DevSecOps EngineerEY · McLean, VA, USFirst seen today
- DevSecOps EngineerJobgether · USFirst seen todayremote
- DevSecOps Engineer II - SaaSEsri · Redlands, CAFirst seen yesterday
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job