DevSecOps Engineer
A-LIGN External · Panama - Remote · Remote
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About the Role
The DevSecOps Engineer works to execute security engineering activities across A-LIGN's cloud infrastructure, CI/CD pipelines, and production applications. In this role, you will be responsible for implementing and continuously validating security controls, delivering infrastructure and application improvements, and supporting continuous audit readiness. As the DevSecOps Engineer, you will provide exceptional technical and security strategies to help support the continued growth of our fast-paced company. A-LIGN will depend on you as the DevSecOps Engineer to support management, translate security and compliance requirements into practical engineering solutions, and automate security and audit evidence workflows.
Reports to
Principal Security Engineer
Pay Classification
Full-Time
Responsibilities
Design, implement, and continuously validate security controls across cloud infrastructure, CI/CD pipelines, and production applications
Author and maintain infrastructure as code using Terraform or similar tools across quality assurance, staging, and production environments
Deliver production code that addresses security requirements, including authentication, single sign-on, authorization, session security, and vulnerability remediation
Design and administer identity and access management solutions, including OAuth 2.0, OpenID Connect, SAML, identity providers, authorization models, and account lifecycle automation
Manage vulnerability remediation from triage through closure across static application security testing, dynamic application security testing, dependency scanning, and container scanning tools
Remediate penetration testing findings in code and infrastructure and prepare evidence-based technical responses when findings do not apply
Translate FedRAMP, NIST 800-53, and other framework requirements into deployed technical controls and repeatable audit evidence
Maintain cryptographic compliance through validated module configuration, certificate management, and TLS and DNS posture verification
Develop automation for security operations and evidence collection, including scripts, reports, API integrations, and verified artificial intelligence workflows
Maintain security architecture documentation, including authorization boundaries, network architecture, and data flow diagrams
Perform security impact analysis for production changes and maintain pre-production security deployment checklists
Participate in threat modeling, risk assessments, continuous monitoring, software bill of materials generation, software supply chain security, logging coverage, and user access reviews
Minimum Qualifications
EDUCATION
Bachelor's degree in information systems, cybersecurity, computer science, engineering, or a related field, or an equivalent combination of education and experience
EXPERIENCE
At least 4 years of combined experience in DevSecOps, security engineering, cloud engineering, or software…