Remote (Country)

Ethos is hiring a Senior DevSecOps Engineer

About the Role

DriveWhip is hiring a Senior DevSecOps Engineer to be the hands-on owner of security and reliability for the ThriveCart e-commerce platform. You will secure our infrastructure, automate our CI/CD pipelines, and ensure high availability through robust monitoring and incident response.

What You'll Do

  • Implement and maintain security scanning in CI/CD (SAST, dependency, container).
  • Harden AWS infrastructure (WAF, Security Groups) and manage network segmentation.
  • Monitor security advisories, coordinate patching, and track vulnerability remediation.
  • Manage encryption (rest/transit), secure compute resources, and audit IAM policies.
  • Provide security tooling/dashboards and assist developers with findings.
  • Maintain CloudWatch dashboards (Payment metrics, Database health, API performance).
  • Configure GuardDuty/Security Hub and build alerts for DDoS, intrusion, and anomalies.
  • Monitor production health, investigate anomalies, and perform root cause analysis.
  • Build investigation queries for security incidents and maintain response runbooks.
  • Monitor for penetration attempts, API abuse, and suspicious access patterns.
  • Manage AWS resources via Terraform (EC2, RDS, IAM, VPC) with security-first configurations.
  • Maintain zero-downtime CI/CD pipelines with integrated security gates and rollback mechanisms.
  • Administer MariaDB databases (performance tuning, backups, access controls).
  • Maintain Docker-based dev environments and secure container configurations.
  • Support compliance requirements (PCI-DSS) and manage evidence collection.

What We're Looking For

  • 3-5 years experience in production operations for high-traffic web apps with a focus on security.
  • Experience implementing security controls (WAF, IAM, scanning) in AWS environments.
  • Experience with Infrastructure as Code (Terraform) and CI/CD security integration.
  • Experience with database administration (MariaDB/MySQL) and container security (Docker).
  • Experience with DDoS mitigation, incident response, and compliance frameworks.
  • Skills in vulnerability assessment, threat detection, IAM design, and secrets management.
  • Skills in CloudWatch alerting, Terraform module development, Bash scripting, and log analysis.
  • Soft skills: Security-first mindset, calm under pressure, collaborative educator.

Technical Stack

  • AWS: GuardDuty, WAF, CloudWatch, EC2, RDS
  • Infrastructure as Code: Terraform
  • Containers: Docker
  • Database: MariaDB
  • Languages & Systems: Git, Linux, Bash, PHP 7.4
  • Security Tools: Snyk/SonarQube (SAST), Trivy (Container), Checkov (IaC), AWS Secrets Manager
  • Web & Caching: Nginx, Memcached
  • CI/CD & Automation: GitHub Actions, Let's Encrypt

Benefits & Compensation

  • Competitive salary
  • Equity
  • Security certification sponsorship (CISSP, AWS Security)

Work Mode

This is a local-country position open to candidates in South America.

DriveWhip is an equal opportunity employer.

Required Skills
AWSTerraformDockerLinuxGitMariaDBSAST (Snyk/SonarQube)Container Security (Trivy)IaC Security (Checkov)AWS Secrets ManagerAWS GuardDutyAWS WAFAWS CloudWatchEC2RDS
Looking for a remote dev community?

200+ professionals, 37 countries, one network

Working remotely doesn't mean working alone. Iglu connects you with developers, designers, and digital experts worldwide. Collaborate, learn, and grow together.

Global professional network
Knowledge sharing & collaboration
Regular community events
Cross-project opportunities
Join the community
37 countries represented
About company
Ethos

Ethos is a leading life insurance technology company on a mission to protect families by democratizing access to life insurance and empowering agents at scale. It offers instant, accessible life insurance products with a seamless online process requiring no medical exams.

Visit website
Job Details
Category infrastructure
Posted 2 months ago