Senior DevOps Engineer
Salary: $150k-$180k
Location: Chicago, IL or Houston, TX
Hybrid: 3 days onsite, 2 days remote
- We are unable to provide sponsorship for this role*
Qualifications
- Bachelor’s degree
- 8+ years in DevOps, Cloud Engineering, Systems Engineering, or DevSecOps, including 5+ years integrating security into CI/CD pipelines.
- Deep experience with CI/CD platforms (e.g., Azure DevOps, GitHub Actions, Jenkins, GitLab) and embedding security controls throughout development workflows.
- Strong experience with cloud platforms (especially Microsoft Azure and/or AWS) and Infrastructure as Code practices.
- Hands-on experience with Docker and Kubernetes, including security best practices.
- Solid understanding of application security concepts, secrets management, authentication protocols, and policy enforcement tools (e.g., Azure Policy, Open Policy Agent (OPA), Sentinel).
- Proficiency in scripting languages such as PowerShell, Python, or Bash to drive automation and efficiency.
- Strong foundation in operating systems, networking, APIs, and distributed systems.
- Experience with platforms such as Dynatrace, Prometheus, Grafana, ELK Stack (Elasticsearch, Logstash, Kibana), Splunk, or Azure Monitor.
Responsibilities
- Secure CI/CD Enablement: Design, build, and maintain secure continuous integration/continuous delivery (CI/CD) pipelines that streamline application build, testing, and deployment.
- Security Integration: Embed security tooling into the software development lifecycle, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets scanning, and infrastructure security scanning.
- Infrastructure as Code (IaC): Develop and manage infrastructure using code with tools such as Terraform, Bicep, Azure Resource Manager (ARM), or CloudFormation.
- Cloud Security Management: Administer and secure cloud environments, primarily within Microsoft Azure, ensuring compliance and operational integrity.
- Container & Kubernetes Security: Implement and manage container and orchestration security, including image scanning, role-based access control (RBAC), and runtime protections.
- Standards & Governance: Establish and enforce secure coding, deployment, and access management standards across teams.
- Identity & Secrets Management: Secure and manage certificates, secrets, and identity/access controls using enterprise tools and best practices.
- Monitoring & Observability: Track system health and performance using monitoring and alerting platforms to proactively identify and resolve issues.
- Vulnerability Management: Coordinate remediation efforts and support compliance and regulatory initiatives.