CaVU Consulting logo
CaVU ConsultingPosted 1 month ago

DevSecOps Engineer / AWS Cloud Engineer (Serverless, CI/CD, IaC, ECS Fargate) | San Diego, CA

$145,000–$175,000 year

On-siteSan Diego, California, United States

Full TimeMid LevelSmall

Job Summary

Design and maintain secure, scalable AWS environments featuring serverless APIs, event-driven workflows, and containerized services on ECS Fargate. Build GitLab CI/CD pipelines with integrated security controls for automated testing, deployments, and rollbacks. Manage infrastructure using CloudFormation, enforce least-privilege IAM policies, and orchestrate MySQL/RDS databases with robust backup and connectivity patterns. Partner with application and security teams to deliver mission-critical systems with full observability and audit-ready traceability.

Required Qualifications

  • Hands-on expertise building serverless solutions with AWS Lambda, API Gateway, and Step Functions in production
  • Strong experience with AWS CloudFormation for provisioning and managing environments
  • Strong CI/CD experience, specifically building and operating GitLab CI/CD pipelines
  • Strong container expertise with Docker and running workloads on ECS Fargate (services, tasks, scaling, networking)
  • Demonstrated experience architecting secure AWS environments using IAM, VPC/networking, encryption, and logging/auditing best practices
  • Experience designing/operating MySQL / Amazon RDS in production
  • Strong scripting/automation skills (e.g., Python and/or Bash) to streamline workflows and reduce toil
  • Ability to collaborate effectively with frontend/backend engineering teams and translate requirements into secure, automated platform capabilities
  • Security+ or higher certification
  • AWS Cloud Practitioner certification or higher
  • TS security clearance or the ability to obtain one

Desired Qualifications

  • Familiarity with AWS CDK or Terraform (even if CloudFormation remains primary)
  • Experience with API security patterns: OAuth/OIDC integration, JWT authorizers, rate limiting/throttling, WAF, mTLS (where required)
  • Experience with secrets management (e.g., AWS Secrets Manager / SSM Parameter Store) and key management (KMS)
  • Observability stack experience beyond basics: structured logging, tracing (e.g., X-Ray/OpenTelemetry patterns), metrics-driven alerting
  • Experience implementing policy-as-code and governance (e.g., SCPs/Organizations, config rules, control frameworks)
  • Experience with performance/cost optimization for serverless and Fargate workloads
  • Prior experience in regulated environments requiring audit evidence and secure SDLC controls

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce