Back to all roles

[Remote] DevSecOps Engineer – Security Automation & Pipeline Development, 37294688

Remote-first Full-time Now hiring

Note: The job is a remote job and is open to candidates in USA. Cypress HCM is seeking a DevSecOps Engineer to enhance security within their AWS EKS Kubernetes environment and CI/CD pipeline in preparation for a FedRAMP High audit. The role involves upgrading vulnerable containers, maintaining security settings, and developing automated patching pipelines while ensuring compliance with security standards.

Responsibilities

  • Upgrade vulnerable containers in collaboration with the DevSecOps team, testing and promoting updates to production
  • Apply cloud hardening and maintain Terraform/Ansible code to enforce security settings across AWS services and Kubernetes nodes per STIG and CIS benchmarks
  • Design and maintain automated container patching pipelines including base image refresh, rebuild triggers, and automated PR generation
  • Build and maintain vulnerability scanning workflows using Grype and/or Trivy as pipeline gates blocking promotion of images exceeding CVE thresholds
  • Build and manage Argo Workflows orchestrating end-to-end patch automation from scanning through remediation, rebuild, and deployment
  • Write Python-based tooling supporting pipeline logic, scan result parsing, notification routing, and patch orchestration
  • Own GitHub-based development workflow: branch strategy, PR creation/review, code quality standards, and merge gate enforcement
  • Conduct code reviews ensuring changes meet security, quality, and operational standards before production promotion
  • Maintain production readiness practices including testing, peer review, rollback procedures, and deployment validation
  • Analyze Kubernetes IAM configurations and RBAC policies to identify overprivileged roles, misconfigurations, and deviations from least-privilege principles
  • Review and harden Kubernetes network setup and segmentation including network policies, namespace isolation, and inter-service communication controls
  • Audit certificate usage across the cluster and pipeline, ensuring proper issuance, validity, and automated rotation; verify secrets are rotated on schedule and not hardcoded or overexposed
  • Scan codebases, repos, and infrastructure configs for exposed secrets using open source tools such as Hedgehog and equivalent secret detection utilities
  • Scan S3 buckets for exposed secrets and sensitive data, remediating findings and implementing preventive controls
  • Review network, WAF, and Istio logs to map existing traffic flows and service communication patterns in preparation for network segmentation and a deny-by-default lockdown posture
  • Develop automations for WAF rule creation and tuning based on observed traffic patterns and threat intelligence
  • Leverage Claude to accelerate security research, organize remediation plans, and develop Python-based tooling for non-production-impacting automation and analysis tasks

Skills

  • Deep familiarity with container technology and security
  • Upgrade vulnerable containers in collaboration with the DevSecOps team, testing and promoting updates to production
  • Apply cloud hardening and maintain Terraform/Ansible code to enforce security settings across AWS services and Kubernetes nodes per STIG and CIS benchmarks
  • Design and maintain automated container patching pipelines including base image refresh, rebuild triggers, and automated PR generation
  • Build and maintain vulnerability scanning workflows using Grype and/or Trivy as pipeline gates blocking promotion of images exceeding CVE thresholds
  • Build and manage Argo Workflows orchestrating end-to-end patch automation from scanning through remediation, rebuild, and deployment
  • Write Python-based tooling supporting pipeline logic, scan result parsing, notification routing, and patch orchestration
  • Own GitHub-based development workflow: branch strategy, PR creation/review, code quality standards, and merge gate enforcement
  • Conduct code reviews ensuring changes meet security, quality, and operational standards before production promotion
  • Maintain production readiness practices including testing, peer review, rollback procedures, and deployment validation
  • Analyze Kubernetes IAM configurations and RBAC policies to identify overprivileged roles, misconfigurations, and deviations from least-privilege principles
  • Review and harden Kubernetes network setup and segmentation including network policies, namespace isolation, and inter-service communication controls
  • Audit certificate usage across the cluster and pipeline, ensuring proper issuance, validity, and automated rotation; verify secrets are rotated on schedule and not hardcoded or overexposed
  • Scan codebases, repos, and infrastructure configs for exposed secrets using open source tools such as Hedgehog and equivalent secret detection utilities
  • Scan S3 buckets for exposed secrets and sensitive data, remediating findings and implementing preventive controls
  • Review network, WAF, and Istio logs to map existing traffic flows and service communication patterns in preparation for network segmentation and a deny-by-default lockdown posture
  • Develop automations for WAF rule creation and tuning based on observed traffic patterns and threat intelligence
  • Leverage Claude to accelerate security research, organize remediation plans, and develop Python-based tooling for non-production-impacting automation and analysis tasks
  • AWS EKS
  • Kubernetes
  • Terraform
  • Ansible
  • ArgoCD
  • Argo Workflows
  • GitLab
  • GitHub
  • FedRAMP
  • STIG
  • CIS Benchmarks
  • RBAC
  • IAM
  • Okta/OIDC
  • SAML
  • WAF
  • Istio
  • Network Segmentation
  • Certificate Management
  • Secrets Rotation
  • Least Privilege
  • Grype
  • Anchore
  • Hedgehog
  • S3 Scanning
  • Vulnerability Scanning
  • Secrets Detection
  • Python
  • CI/CD Pipelines
  • Code Review
  • PR Management
  • Patch Automation
  • Claude
  • AI-Assisted Coding

Company Overview

  • Cypress HCM is a staffing and recruiting company providing technology and creative recruiting solutions. It was founded in 2005, and is headquartered in Walnut Creek, California, USA, with a workforce of 51-200 employees. Its website is http://cypresshcm.com.
  • Apply To This Job

    More remote roles

    [Remote] Prinicipal Piping Mechanical Engineer

    Remote-first Full-time

    [Remote] Oncology Solution Technical Architect – Growth & Expansion Team (Remote)

    Remote-first Full-time

    [Remote] Lead Director, Field Marketing & Operations

    Remote-first Full-time

    [Remote] Business Development Manager

    Remote-first Full-time

    [Remote] Sr. Legacy Modernization Technical Architect / Solution Assurance Consultant

    Remote-first Full-time

    [Remote] Instructional Designer

    Remote-first Full-time

    [Remote] Customer Success Architect, Cortex

    Remote-first Full-time

    [Remote] Member Financial Specialist

    Remote-first Full-time

    [Remote] Principal Engineer, Cloud Systems

    Remote-first Full-time

    [Remote] Field Operations Program Director, California Connect

    Remote-first Full-time

    Analista Junior de SEO Analista Junior de SEO

    Remote-first Full-time

    Video Editor:in Social Ads (m/w/d)

    Remote-first Full-time

    Customer Support Advocate - Ongoing (Remote) at arenaflex

    Remote-first Full-time

    Customer Support Director

    Remote-first Full-time

    Manager, Information Security

    Remote-first Full-time

    Experienced Amazon Data Entry Specialist – Remote Opportunity with arenaflex

    Remote-first Full-time

    Remote Entry-Level Live Chat Support Specialist – Real‑Time Customer Engagement & Sales Assistance

    Remote-first Full-time

    Senior Family Law Litigation Paralegal

    Remote-first Full-time

    Experienced Data Entry Clerk for 17-Year-Olds – Entry-Level Position at Hirevector About Hirevector At Hirevector, we are driven by a mission to be the world's most customer-centric company. We strive to offer our customers the lowest possible prices, the best available selection, and the utmost convenience. Established in 1994, we’ve grown from an online bookstore into a global powerhouse that specializes in e-commerce, cloud computing, digital streaming, and artificial intelligence. Your Opportunity Awaits We are excited to announce our Data Entry Clerk position specifically tailored for 17-year-olds! This is a unique opportunity to start your career with one of the world's leading companies while improving your computer skills and gaining real-world experience. Position Overview As a Data Entry Clerk at Hirevector, you will play a crucial role in our operations by managing various forms of data input and validation. This position is an excellent opportunity for motivated and detail-oriented teenagers looking to build valuable work experience in a fast-paced environment. Key Responsibilities: Accurately enter customer data into our internal systems. Review and verify data for accuracy and completeness. Organize and maintain data files and records. Assist in organizing information and preparing reports. Communicate effectively with team members to resolve discrepancies. Who We Are Looking For This role is perfect for a responsible 17-year-old who is eager to learn and grow. We are looking for candidates who meet the following criteria: Essential Qualifications: Must be 17 years old by the time of application. High School student or recent graduate preferred. Basic computer skills and familiarity with Microsoft Office Suite. Strong attention to detail and organization skills. Ability to work independently as well as a part of a team. Effective communication skills—both written and verbal. Willingness to learn and accept feedback. What We Offer Working at Hirevector comes with unique benefits tailored to help you thrive: Benefits and Perks: Flexible working hours that can accommodate your school schedule. A competitive hourly wage. Professional development opportunities and training. A supportive work environment with a focus on teamwork. Networking and potential career advancement within the company. Diversity and Inclusion At Hirevector, we value diversity and strive to create an inclusive work environment. We believe that the more diverse our workforce, the better we can serve our customers. We are proud to be an Equal Opportunity Employer where everyone can find success. Your Next Steps If you’re excited about the opportunity to gain skills and be part of an innovative team, we encourage you to apply! This position is a fantastic way for 17-year-olds to gain essential work experience and a chance to contribute to a global leader in technology. Career Growth Opportunities At Hirevector, we believe in investing in our employees' growth and development. As a Data Entry Clerk, you will have the opportunity to learn and grow with our company, taking on new challenges and responsibilities as you progress in your career. Work Environment and Culture Our work environment is fast-paced and dynamic, with a focus on teamwork and collaboration. We encourage open communication, creativity, and innovation, and we strive to create a positive and inclusive work environment for all employees. Compensation, Perks, and Benefits We offer a competitive hourly wage, flexible working hours, and a range of benefits and perks to support your well-being and career development. We also provide comprehensive training and professional development opportunities to help you succeed in your role. Conclusion Data entry jobs for 17-year-olds at Hirevector represent a valuable starting point for any young aspiring professional. With the right guidance and opportunity, you can not only develop practical skills essential for your career but also join a company that embraces innovation and creativity. This is your chance to take those first steps toward a bright future. Don’t hesitate—apply today and be part of something bigger! FAQs Q: What is the minimum age requirement for this position? A: You must be at least 17 years old to apply for this position. Q: Do I need prior experience in data entry to apply? A: No prior experience is necessary, but basic computer skills and a willingness to learn are important. Q: What are the working hours for this role? A: The working hours are flexible and can be arranged to fit around your school schedule. Q: Will training be provided? A: Yes, comprehensive training will be provided to ensure you are fully prepared for your responsibilities. Q: What growth opportunities exist within this role? A: There are numerous opportunities for career advancement within Hirevector, especially for dedicated employees who excel in their roles. Apply Now! Ready to take the first step in your career? Apply now for the Data Entry Clerk position at Hirevector and join our team of innovative and dedicated professionals!

    Remote-first Full-time

    Copy of Healthcare Recruiter

    Remote-first Full-time