

DevOps Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a DevSecOps Engineer, remote (EST), with a 12-month contract at $65-75/hr. Requires 4-7 years in DevSecOps, CI/CD tools, IaC, and container security. Preferred: compliance frameworks and relevant certifications.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
-
ποΈ - Date discovered
September 26, 2025
π - Project duration
More than 6 months
-
ποΈ - Location type
Remote
-
π - Contract type
W2 Contractor
-
π - Security clearance
Unknown
-
π - Location detailed
United States
-
π§ - Skills detailed
#GitLab #Vault #Security #GCP (Google Cloud Platform) #GDPR (General Data Protection Regulation) #DevOps #AWS (Amazon Web Services) #Compliance #Kubernetes #Jenkins #Scripting #DevSecOps #Cloud #Monitoring #Automation #Azure #Python #Docker #Bash #Infrastructure as Code (IaC) #Terraform #Documentation #SaaS (Software as a Service) #Logging #GitHub
Role description
DevSecOps Engineer
Job Title: DevSecOps Engineer
Location: Remote (EST Time Zone)
Contract Duration: 12 months (with possibility to extend), no C2C
Seniority: Mid to Senior
Pay: 65-75p/hr
Responsibilities:
β’ Assess the current CI/CD pipelines and propose/implement improvements to integrate security checks early (SAST, DAST, SCA, etc.).
β’ Develop, configure, and maintain infrastructure as code (IaC) with embedded security best practices (least privilege, secure network rules, encryption).
β’ Harden containerization and orchestrated environments (Docker, Kubernetes) in terms of image security, secrets, access controls.
β’ Implement or improve secrets management (e.g. HashiCorp Vault, cloud provider secrets stores).
β’ Set up monitoring/logging/alerting for security events, assist with incident response and remediation.
β’ Collaborate with dev, QA, and operations teams to ensure security is shared responsibility; provide guidance and review pull requests, infrastructure changes, etc.
β’ Draft or refine security policies/documentation (coding standards, architecture guidelines, threat models).
β’ Provide regular status reporting on vulnerabilities, remediation progress, and security posture.
Required Qualifications:
β’ 4β7 years of experience in DevSecOps, Security Engineering, or related role.
β’ Strong experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions, etc.), and building pipelines with security gates.
β’ Experience with static code analysis, dynamic security testing, and dependency scanning.
β’ Handsβon with Infrastructure as Code tools (Terraform, CloudFormation, etc.).
β’ Container / Kubernetes experience: securing images, runtime, RBAC, secrets.
β’ Experience with secrets management tools (Vault, AWS Secrets Manager, Azure Key Vault, etc.).
β’ Proficiency in scripting languages (Python, Bash, etc.) for automation.
β’ Familiarity with cloud environments (AWS, Azure, or GCP) and cloud security best practices.
β’ Good communication skills; able to work remotely and collaborate across multiple teams.
Preferred Qualifications:
β’ Experience with compliance frameworks (SOC2, ISO 27001, GDPR, etc.).
β’ Prior experience doing threat modeling and secure architecture reviews.
β’ Experience with container scanning tools (e.g. Clair, Trivy) or Kubernetes security tools.
β’ Exposure to policy as code tools (OPA, etc.).
β’ Certifications like CISSP, CISM, CKAD/CKS, etc.
Project Overview:
A midβsized SaaS company is looking to enhance its security posture by embedding security throughout the software development lifecycle. The goal is to redesign the CI/CD pipelines, improve vulnerability detection, automate infrastructure security, and ensure compliance with relevant industry standards (e.g. ISO 27001, SOC2).
DevSecOps Engineer
Job Title: DevSecOps Engineer
Location: Remote (EST Time Zone)
Contract Duration: 12 months (with possibility to extend), no C2C
Seniority: Mid to Senior
Pay: 65-75p/hr
Responsibilities:
β’ Assess the current CI/CD pipelines and propose/implement improvements to integrate security checks early (SAST, DAST, SCA, etc.).
β’ Develop, configure, and maintain infrastructure as code (IaC) with embedded security best practices (least privilege, secure network rules, encryption).
β’ Harden containerization and orchestrated environments (Docker, Kubernetes) in terms of image security, secrets, access controls.
β’ Implement or improve secrets management (e.g. HashiCorp Vault, cloud provider secrets stores).
β’ Set up monitoring/logging/alerting for security events, assist with incident response and remediation.
β’ Collaborate with dev, QA, and operations teams to ensure security is shared responsibility; provide guidance and review pull requests, infrastructure changes, etc.
β’ Draft or refine security policies/documentation (coding standards, architecture guidelines, threat models).
β’ Provide regular status reporting on vulnerabilities, remediation progress, and security posture.
Required Qualifications:
β’ 4β7 years of experience in DevSecOps, Security Engineering, or related role.
β’ Strong experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions, etc.), and building pipelines with security gates.
β’ Experience with static code analysis, dynamic security testing, and dependency scanning.
β’ Handsβon with Infrastructure as Code tools (Terraform, CloudFormation, etc.).
β’ Container / Kubernetes experience: securing images, runtime, RBAC, secrets.
β’ Experience with secrets management tools (Vault, AWS Secrets Manager, Azure Key Vault, etc.).
β’ Proficiency in scripting languages (Python, Bash, etc.) for automation.
β’ Familiarity with cloud environments (AWS, Azure, or GCP) and cloud security best practices.
β’ Good communication skills; able to work remotely and collaborate across multiple teams.
Preferred Qualifications:
β’ Experience with compliance frameworks (SOC2, ISO 27001, GDPR, etc.).
β’ Prior experience doing threat modeling and secure architecture reviews.
β’ Experience with container scanning tools (e.g. Clair, Trivy) or Kubernetes security tools.
β’ Exposure to policy as code tools (OPA, etc.).
β’ Certifications like CISSP, CISM, CKAD/CKS, etc.
Project Overview:
A midβsized SaaS company is looking to enhance its security posture by embedding security throughout the software development lifecycle. The goal is to redesign the CI/CD pipelines, improve vulnerability detection, automate infrastructure security, and ensure compliance with relevant industry standards (e.g. ISO 27001, SOC2).