SlipstreamJobsFresh Startup & VC-Backed Jobs

DevSecOps Engineer

Yardstik - Minneapolis, MN, United States - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 120,000 - 165,000 / annual

Yardstik is a venture-backed startup building trust and safety into the Internet Economy through innovative background screening, certification, and training solutions. The company has been recognized as a Best Place to Work for six consecutive years and named to Newsweek's America's Greatest Startup Workplaces. You will join the Infrastructure & Security team as a DevSecOps Engineer, owning and advancing the security posture of Yardstik's platform and infrastructure. This is a hands-on security engineering role where you'll work alongside engineering and operations teams to identify, mitigate, and prevent security risks across cloud environments, applications, and data systems. Key responsibilities include: - Own Yardstik's security posture across cloud infrastructure and applications - Detect, investigate, and respond to security incidents with on-call rotation participation - Harden cloud environments through least-privilege IAM, network segmentation, and security controls - Manage vulnerability scanners, SIEM, endpoint protection, and intrusion detection tools - Conduct threat modeling, vulnerability assessments, and penetration testing - Serve as a security subject matter expert, advising engineering teams on secure architecture and operational practices - Manage and harden AWS cloud infrastructure using Terraform and Infrastructure as Code with focus on security controls, audit logging, and compliance - Build and maintain security monitoring, alerting, and detection pipelines using SIEM tools, log aggregation, and anomaly detection - Perform vulnerability management: scanning, triaging, prioritizing, tracking remediation, and validating fixes - Design and enforce network security controls including VPCs, security groups, WAF rules, and DDoS mitigation - Automate security workflows, compliance checks, and operational tasks through scripting - Evaluate and implement new security tools, technologies, and processes - Collaborate with engineering to integrate security requirements into application design and infrastructure changes This is an early-stage opportunity to evolve with the company and see the direct impact of your work. REQUIREMENTS: Essential experience: - Cloud-native environments (AWS preferred) - SIEM management, log analysis, alert tuning, and incident response - Infrastructure as Code (Terraform, CloudFormation) - Vulnerability management: scanning, triage, remediation tracking, and reporting - Security scanning and assessment tools (Snyk, SonarQube, ZAP, Burp Suite, or similar) - Networking fundamentals (VPC, VPN, DNS, TLS) and web security (WAF, CDN, OWASP Top 10) - Monitoring and observability platforms (DataDog, Splunk, or similar) with security focus - Container security: image scanning, runtime security, and orchestration platforms (Kubernetes, EKS, ECS) - Proficiency with scripting languages for security automation (Python, Ruby, Bash) - On-call and incident response processes, including security-specific triage, containment, and post-mortems Preferred qualifications: - Strong Linux systems administration with security hardening experience (CIS) - Deep experience with AWS security services: IAM, GuardDuty, Security Hub, CloudTrail, Config, KMS - Expertise with IAM design principles: least-privilege, RBAC/ABAC, service control policies, and cross-account access patterns - Experience with identity and access management: SSO, OAuth/OIDC, SAML, and directory services - Familiarity with secrets management platforms (AWS Secrets Manager, HashiCorp Vault, or similar) - Experience with compliance frameworks (SOC 2, GDPR, or similar) and translating requirements into enforceable technical controls - Understanding of threat modeling methodologies (STRIDE, DREAD, attack trees) and vulnerability management lifecycle - Git-based source control proficiency and familiarity with GitOps methodologies - Experience with cloud infrastructure automation and configuration management - Security certifications such as AWS Security Specialty, CompTIA Security+, OSCP, CEH, CISSP, or similar - Familiarity with supply chain security practices (SBOM generation, dependency pinning, signed artifacts) Note: This role is not eligible for visa sponsorship.

Similar roles