SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 165,000 / annual
Yardstik is a venture-backed startup building trust and safety into the Internet Economy through innovative background screening, certification, and training solutions. The company has been recognized as a Best Place to Work for six consecutive years and named to Newsweek's America's Greatest Startup Workplaces.
You will join the Infrastructure & Security team as a DevSecOps Engineer, owning and advancing the security posture of Yardstik's platform and infrastructure. This is a hands-on security engineering role where you'll work alongside engineering and operations teams to identify, mitigate, and prevent security risks across cloud environments, applications, and data systems.
Key responsibilities include:
- Own Yardstik's security posture across cloud infrastructure and applications
- Detect, investigate, and respond to security incidents with on-call rotation participation
- Harden cloud environments through least-privilege IAM, network segmentation, and security controls
- Manage vulnerability scanners, SIEM, endpoint protection, and intrusion detection tools
- Conduct threat modeling, vulnerability assessments, and penetration testing
- Serve as a security subject matter expert, advising engineering teams on secure architecture and operational practices
- Manage and harden AWS cloud infrastructure using Terraform and Infrastructure as Code with focus on security controls, audit logging, and compliance
- Build and maintain security monitoring, alerting, and detection pipelines using SIEM tools, log aggregation, and anomaly detection
- Perform vulnerability management: scanning, triaging, prioritizing, tracking remediation, and validating fixes
- Design and enforce network security controls including VPCs, security groups, WAF rules, and DDoS mitigation
- Automate security workflows, compliance checks, and operational tasks through scripting
- Evaluate and implement new security tools, technologies, and processes
- Collaborate with engineering to integrate security requirements into application design and infrastructure changes
This is an early-stage opportunity to evolve with the company and see the direct impact of your work.
REQUIREMENTS:
Essential experience:
- Cloud-native environments (AWS preferred)
- SIEM management, log analysis, alert tuning, and incident response
- Infrastructure as Code (Terraform, CloudFormation)
- Vulnerability management: scanning, triage, remediation tracking, and reporting
- Security scanning and assessment tools (Snyk, SonarQube, ZAP, Burp Suite, or similar)
- Networking fundamentals (VPC, VPN, DNS, TLS) and web security (WAF, CDN, OWASP Top 10)
- Monitoring and observability platforms (DataDog, Splunk, or similar) with security focus
- Container security: image scanning, runtime security, and orchestration platforms (Kubernetes, EKS, ECS)
- Proficiency with scripting languages for security automation (Python, Ruby, Bash)
- On-call and incident response processes, including security-specific triage, containment, and post-mortems
Preferred qualifications:
- Strong Linux systems administration with security hardening experience (CIS)
- Deep experience with AWS security services: IAM, GuardDuty, Security Hub, CloudTrail, Config, KMS
- Expertise with IAM design principles: least-privilege, RBAC/ABAC, service control policies, and cross-account access patterns
- Experience with identity and access management: SSO, OAuth/OIDC, SAML, and directory services
- Familiarity with secrets management platforms (AWS Secrets Manager, HashiCorp Vault, or similar)
- Experience with compliance frameworks (SOC 2, GDPR, or similar) and translating requirements into enforceable technical controls
- Understanding of threat modeling methodologies (STRIDE, DREAD, attack trees) and vulnerability management lifecycle
- Git-based source control proficiency and familiarity with GitOps methodologies
- Experience with cloud infrastructure automation and configuration management
- Security certifications such as AWS Security Specialty, CompTIA Security+, OSCP, CEH, CISSP, or similar
- Familiarity with supply chain security practices (SBOM generation, dependency pinning, signed artifacts)
Note: This role is not eligible for visa sponsorship.