yandex
alpaca
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
УдалённоПолная занятость

DevSecOps Engineer

Оценка ИИ

Отличная вакансия в быстрорастущем финтех-единороге с серьезным финансированием. Полная удаленка, работа с современным стеком технологий и прямое влияние на безопасность продукта мирового уровня делают это предложение крайне привлекательным.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубоких знаний на стыке DevOps и информационной безопасности, включая опыт работы с Kubernetes, Terraform и автоматизацией ИБ. Высокая ответственность за инциденты в финансовом секторе и необходимость взаимодействия с CISO повышают планку требований.

Анализ зарплаты

Медиана140 000 $
Рынок110 000 $ – 180 000 $
Оценка ИИ

Предлагаемая позиция в Alpaca, вероятно, соответствует верхнему эшелону рынка для удаленных DevSecOps инженеров, работающих на компании из США. Учитывая недавний раунд финансирования Series D, компания может предлагать конкурентоспособные условия, превышающие средние показатели по региону EMEA.

Сопроводительное письмо

I am writing to express my strong interest in the DevSecOps Engineer position at Alpaca. With over five years of experience in cloud security and infrastructure automation, I have a proven track record of embedding security controls directly into CI/CD pipelines and hardening Kubernetes environments. My background aligns perfectly with your mission to open financial services to everyone, as I am passionate about building resilient, secure-by-default systems that support rapid scaling.

In my previous roles, I have successfully implemented Infrastructure as Code (IaC) scanning, managed complex vulnerability remediation workflows, and championed a 'security as code' culture. I am particularly drawn to Alpaca's commitment to open-source and its distributed team model. I am confident that my technical expertise in Terraform, Go, and cloud-native security, combined with my experience in incident response, will allow me to make an immediate impact on your Security and Engineering teams.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в alpaca уже сейчас

Присоединяйтесь к Alpaca и станьте ключевым звеном в обеспечении безопасности глобальной финансовой инфраструктуры!

Описание вакансии

Who We Are:

Alpaca is a US-headquartered self-clearing broker-dealer and brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24/5 trading, and more. Our recent Series D funding round brought our total investment to over $320 million, fueling our ambitious vision.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 9 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We're deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by top-tier global investors, including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Unbound, SBI Group, Derayah Financial, Elefund, and Y Combinator.

Our Team Members:

We're a dynamic team of 230+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We're searching for passionate individuals eager to contribute to Alpaca's rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role:

We are seeking a DevSecOps Engineer to own the intersection of security, reliability, and DevOps. This role will design and implement resiliency across our cloud platform and CI/CD pipelines, embed “security as code,” help lead incident response for high-severity outages, and partner with engineering teams to enable safe, fast delivery at scale.

You will be hands-on and strategic: automating remediation, hardening deployments, owning observability, and driving measurable reductions in security/infra related incident impact. This role reports to the CISO, with a dotted line into Engineering and works closely with DevOps, Product, and Engineering leadership.

The Security Team is 100% distributed and remote.

Things You Get To Do:

The core responsibilities of the DevSecOps Engineer role are focused on embedding security throughout our infrastructure and software development lifecycle, enhancing cyber resilience, and driving a strong security culture.

Security Engineering & Automation:

  • Secure SDLC Integration: Embed security into CI/CD pipelines by implementing and owning secure controls, including Infrastructure as Code (IaC) scanning, Software Composition Analysis (SCA), secrets checks, policy-as-code, and deployment guardrails.
  • Vulnerability Management: Lead the process of vulnerability and patch management, automating discovery, prioritization, and remediation across all cloud workloads and their dependencies.
  • Platform Hardening: Strengthen cloud and Kubernetes environments through secure configurations, network segmentation, workload identity management, and automated compliance against industry standards (e.g., CSA Star).
  • Supply Chain Security: Advance the security of the software supply chain, focusing on generating Software Bill of Materials (SBOMs), artifact signing, dependency governance, and implementing integrity controls.
  • Secure Patterns: Create secure "paved roads" for developers, providing hardened IaC modules, templates, tooling, and comprehensive documentation.

Resilience, Detection, and Response:

  • Cyber Resilience: Own and validate cyber-resiliency standards (secure failover, secure backups, Disaster Recovery playbooks) through secure rehearsals to ensure both the availability and integrity of systems and data
  • Security Deployment: Develop secure deployment patterns, such as canary rollouts, automated safe rollbacks, and guardrails to minimize blast radius
  • Detection & Forensics: Improve detection and response capabilities by building high-signal alerts, enhancing forensic logging, and providing robust security telemetry. Partner with the SecOps team on incident handling
  • Offensive Security: Alongside the Security team, help manage offensive security engagements (penetration testing, red team, bug bounty) and ensure findings are fed directly into remediation pipelines and risk prioritization

Architecture, Identity, and Governance:

  • Design & Threat Modeling: Conduct security reviews and threat modeling for all new services and major architecture changes to ensure designs are secure-by-default
  • Identity & Access Management (IAM): Strengthen the identity and access model by enforcing the principle of least privilege, strong authentication, and secure secrets lifecycle management
  • Compliance & Audit: Support compliance and audit readiness by operationalizing security controls, producing necessary evidence, and maintaining the health of these controls

Leadership & Culture:

  • Security Champion: Champion a strong security culture by partnering with DevOps and Engineering teams to uplift secure coding practices and guide risk-based decision-making
  • Metrics & Reporting: Define key security performance indicators (KPIs) such as time to detect, time to remediate, exposure scores, and percentage of infrastructure covered by automated controls, and report measurable improvements to leadership

Who You Are (Must-Haves):

  • Excited about Alpaca’s mission and what we’re building
  • 5+ years of experience across DevSecOps, security engineering, or cloud security in a modern cloud-native environment
  • Strong hands-on experience with CSPs, Kubernetes, Terraform, and container security
  • Deep understanding of secure CI/CD, including IaC security, dependency/SCA, secrets scanning, and policy-as-code
  • Solid background in identity & access security
  • Experience automating vulnerability management and patching workflows across cloud and container ecosystems
  • Strong familiarity with detection engineering, logging/telemetry, and partnering in incident response
  • Proficient in a scripting/programming language (Python, Go, or similar) for automation and security tooling
  • Comfortable working cross-functionally with DevOps and Engineering teams, explaining risk in practical terms, and influencing secure design
  • Comfortable participating in on-call rotations

Who You Might Be (Nice-to-Haves):

  • Experience securing financial, trading, or other highly regulated platforms
  • Knowledge of regulatory frameworks common in fintech (SOC 2, ISO 27001, PCI)
  • Experience with supply-chain security (SBOMs, Sigstore, artifact signing) or software integrity programs
  • Familiarity with offensive security, bug bounty triage, or penetration testing
  • Security or cloud certifications (CISSP, OSCP, GIAC, GCP/AWS Security)
  • Bachelor's degree in Computer Science, Information Security, or equivalent experience.
  • Business acumen to be able to balance tradeoffs between stakeholders, technology feasibility and budget constraints

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • AWS
  • Python
  • Terraform
  • Kubernetes
  • CI/CD
  • IAM
  • Google Cloud Platform
  • Docker
  • Infrastructure as Code
  • Vulnerability Management
  • Cloud Security
  • Go
  • SCA

Возможные вопросы на собеседовании

Проверка практического опыта внедрения безопасности в процессы разработки.

Расскажите о вашем опыте внедрения инструментов SCA и IaC-сканирования в существующий CI/CD пайплайн: с какими трудностями вы столкнулись и как их преодолели?

Оценка навыков обеспечения безопасности в оркестрации контейнеров.

Какие стратегии вы используете для обеспечения сетевой сегментации и управления привилегиями (IAM) внутри кластера Kubernetes?

Проверка способности действовать в критических ситуациях.

Опишите ваш опыт участия в реагировании на инциденты (Incident Response). Как вы автоматизируете процесс сбора форензик-данных в облачной среде?

Оценка навыков автоматизации и разработки инструментов безопасности.

На каком языке (Python/Go) вы предпочитаете писать инструменты автоматизации безопасности и какой самый сложный скрипт или сервис вы разработали для нужд ИБ?

Проверка понимания специфики цепочки поставок ПО.

Как бы вы организовали процесс генерации и проверки SBOM (Software Bill of Materials) для обеспечения безопасности цепочки поставок в Alpaca?

Похожие вакансии

Комплексные технологии
200 000 ₽ – 220 000 ₽

DevOps Middle +/ Senior

SeniorУдалённоРоссия
SQL · Kubernetes · Docker · Ansible · Prometheus · Grafana · ELK stack · CI/CD · Java · Go · C++ · Bash · Terraform · SonarQube · SAST · Python · Linux · Windows Server · Cisco · MikroTik · Fortinet · Ubiquiti · TCP/IP · DNS · DHCP · BGP · OSPF · VLAN · NAT · Zero Trust · RBAC · SIEM · Zabbix · Wazuh · PowerShell · VMware · Proxmox · Hyper-V · KVM
+39 навыков
WMT Group
300 000 ₽ – 400 000 ₽

Senior DevOps/Mlops

SeniorУдалённоРоссия
Docker · Helm · Jenkins · GitLab CI · Python · Airflow · JupyterHub · MLflow · Seldon Core · CUDA · Kubernetes · Hadoop · Apache Spark · Apache Kafka · ELK stack · LLM · Computer Vision
+17 навыков
DstLab
240 000 ₽ – 280 000 ₽

Devops Middle+ / Senior

SeniorУдалённоРоссия
Kubernetes · Redis · Kafka · Keycloak · PostgreSQL · MonetDB · VK Cloud · GitLab CI · ArgoCD · HashiCorp Vault · Prometheus · Grafana · ELK stack · Linux
+14 навыков
Hi, Rockits!
300 000 ₽ – 400 000 ₽

Senior DevOps/SRE Engineer (On-Premise инфраструктура)

SeniorУдалённоРоссия
Kubernetes · Ansible · Terraform · GitLab CI/CD · PostgreSQL · Redis · RabbitMQ · ElasticSearch · Prometheus · Grafana · Linux · Go · Python · Kafka · Vault · NATS · Bash
+17 навыков
Volna.tech
268 000 ₽ – 294 000 ₽

DevOps - senior

SeniorУдалённоРоссия
Linux · RHEL · Debian · TCP/IP · Docker · Git · GitLab CI · GitHub Actions · TeamCity · Jenkins · Nexus · Artifactory · Terraform · Ansible · Chef · Puppet · OpenStack · AWS · Molecule · TestInfra · REST API
+21 навыков
Тезис
130 000 ₽ – 200 000 ₽

Junior+ / Middle DevOps Engineer

MiddleУдалённоРоссия
Kubernetes · Helm · Docker · Terraform · Linux · Bash · Python · Go · GitLab CI · PostgreSQL · Redis · Prometheus · Grafana · Loki · Ansible · Yandex Cloud · Selectel · ArgoCD · FluxCD · ClickHouse · MongoDB · Kafka · Vault · Trivy · Teleport · ETL · CDC · Debezium · PgBouncer · HAProxy · Velero · Cilium · ELK
+33 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

alpaca