Full-Time DevSecOps Engineer
Distributed is hiring a remote Full-Time DevSecOps Engineer. The career level for this job opening is Experienced and is accepting UK based applicants remotely. Read complete job description before applying.
Distributed
Job Title
Posted
Career Level
Career Level
Locations Accepted
Share
Job Details
DevSecOps Engineer – Industrial AI Platform Role Summary You'll own security implementation across our AI deployment pipelines - from AWS EC2 development environments to air-gapped industrial sites. This hands-on role combines security engineering, infrastructure automation, and operational reliability for a platform deploying mission-critical ML models at the edge.
Key Responsibilities
- Infrastructure Security Automation
- Develop and maintain OpenTofu modules for consistent VM provisioning across environments
- Harden EC2 and on-prem VM templates with Ansible security playbooks
- Implement least-privilege IAM policies and secure network configurations
- Design secure bootstrapping processes for production environments
- Kubernetes Deployment Security
- Secure our K3s clusters with proper pod security policies and network isolation
- Implement robust RBAC models with granular permissions
- Design secure inter-service communication patterns
- Build security monitoring for cluster components and workloads
- CI/CD Pipeline Hardening
- Integrate automated security scanning into build pipelines (container scanning, SCA, SAST)
- Implement secure artifact management with signing and verification
- Build proper secrets management for deployment pipelines
- Establish secure container base images and build processes
- Operational Security & Reliability
- Design secure update mechanisms for air-gapped environments
- Implement monitoring, alerting and incident response automation
- Build comprehensive logging and audit trails across environments
- Develop metrics for tracking security and reliability KPIs
- Security Reporting & Governance
- Create security dashboards for visibility into system security posture
- Build automated compliance validation for industrial requirements
- Develop practical security documentation and runbooks
- Run internal security reviews and share findings with engineering teams