{"id":1701386,"url":"https://alion.io/job/a-lign-devsecops-engineer","title":"DevSecOps Engineer","company":{"id":6431,"name":"A-LIGN","domain":"a-lign.com","url":"https://alion.io/company/a-lign","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":null,"employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Panama"],"countries":["PA"],"hiring_countries":["PA"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":75000,"max_usd":209000,"period":"year","method":null,"sample_n":2929},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"FedRAMP","optional":false},{"name":"GCP","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST 800-53","optional":false},{"name":"Python","optional":false},{"name":"SOC 2","optional":false},{"name":"SQL","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false}],"status":"live","first_seen_at":"2026-10-02T07:31:43Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-05T02:41:41Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"About the Role\nThe DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. As the DevSecOps Engineer, you will provide exceptional technical and security strategies to help support the continued growth of our fast-paced company. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.\nReports to\nPrincipal Security Engineer\nPay Classification\nFull-Time\nResponsibilities\nDesign, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications\nAuthor and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments\nDeliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation\nDesign and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation\nManage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools\nRemediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply\nTranslate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence\nMaintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification\nDevelop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows\nMaintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams\nPerform security impact analysis for production changes and maintain pre-production security deployment checklists\nParticipate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews\nMinimum Qualifications\nEDUCATION\nBachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience\nEXPERIENCE\nAt least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software engineering\nExperience developing production software in Go, Python, TypeScript, or a comparable modern programming language\nHands-on experience with GCP, AWS, or Azure, including identity and access management, containers or serverless services, build pipelines, secrets management, and log-based troubleshooting\nExperience using Terraform or a similar infrastructure as code platform in production environments\nWorking knowledge of OAuth 2.0, OpenID Connect, SAML, JSON Web Tokens, and identity provider administration\nExperience managing vulnerabilities and responding to penetration testing findings, including code-level remediation\nExperience with scripting and automation using Python, shell, SQL, or similar tools\nExperience working in regulated or compliance-driven environments preferred\nFamiliarity with FedRAMP, NIST 800-53, SOC 2, ISO 27001, or similar security and compliance frameworks\nFamiliarity with FIPS 140-2 or FIPS 140-3 requirements preferred\nExperience with fine-grained authorization models, governance, risk, and compliance platforms, or compliance as code tooling preferred\nExperience operating in a private equity-backed or high-growth environment preferred\nCERTIFICATIONS\nPreferred: CISSP, CCSP, GCP Professional Cloud Security Engineer, AWS Certified Security - Specialty, or a similar cloud security certification\nSKILLS\nAbility to translate security and compliance requirements into practical engineering changes and implement them directly\nAbility to troubleshoot across content delivery networks, web application firewalls, load balancers, runtime platforms, application code, and logs\nExcellent written and verbal communication skills, including the ability to prepare technical documentation, auditor responses, and repeatable runbooks\nHighly organized with the ability to manage release, remediation, and audit deadlines across multiple concurrent workstreams\nSelf-directed with strong follow-through in a fast-paced, deadline-driven environment\nAbility to work individually as well as collaboratively across technical and business teams\nDemonstrated experience using agentic artificial intelligence development tools to support coding, integrations, workflow automation, and output verification\nBenefits\nEmployer Paid Life & Health Insurance \nCompetitive Bonus Structure \nHome Office Reimbursement \nTechnology Allowance \nCertification Reimbursement \nBeneficiaTDiscount Loyalty Program \nPersonalized Career Coaching \nGenerous Paid Time Off \nPaid Office Closure December 25-January 1 \nSummer Hours \nAbout A-LIGN\nA-LIGN is the leading provider of high-quality, efficient cybersecurity compliance programs. Combining experienced auditors and audit management technology, A-LIGN provides the widest breadth and depth of services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. A-LIGN is the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor. To learn more, visit a-lign.com. \nCome Work for A-LIGN! \nApply online today at A-LIGN.com and learn about life at A-LIGN by following us on LinkedIn. \nA-LIGN is an Equal Opportunity Employer. Minorities, women, disabled, and veterans encouraged to apply!","description_format":"text","description_chars":6107,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Certification reimbursement","Equity","Health insurance","Home office"],"hiring_locations":[{"name":"Panama","iso":"PA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["DevSecOps","Security Compliance","Testing, Inspection & Certification"],"lifecycle":[{"event":"open","at":"2026-10-02T13:31:48Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":1,"expected_fill_days":52,"reasons":["conf:0","win:early"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/a-lign-devsecops-engineer","json_url":"https://alion.io/job/a-lign-devsecops-engineer.json","meta":{"generated_at":"2026-10-05T02:42:05Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3662,"day_limit":5000,"remaining_today":1338,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}