Silpa Consulting LLC

DevSecOps Engineer

⭐ - Featured Role | Apply direct with Data Freelance Hub
This role is for a DevSecOps Engineer with a contract length of "unknown", offering a pay rate of "unknown". Key skills include CI/CD pipeline security, cloud infrastructure (Azure, AWS, GCP), Terraform, and container security. Preferred certifications include AWS Certified Security Specialty and Certified Kubernetes Administrator. Location is hybrid, with a preference for candidates in the Houston area.
🌎 - Country
United States
πŸ’± - Currency
$ USD
-
πŸ’° - Day rate
Unknown
-
πŸ—“οΈ - Date
March 6, 2026
πŸ•’ - Duration
Unknown
-
🏝️ - Location
Hybrid
-
πŸ“„ - Contract
Unknown
-
πŸ”’ - Security
Unknown
-
πŸ“ - Location detailed
United States
-
🧠 - Skills detailed
#Defender #Databases #"ETL (Extract #Transform #Load)" #Leadership #Data Management #Docker #AI (Artificial Intelligence) #Azure Security #Documentation #Observability #Datasets #GitHub #Python #Compliance #Jenkins #Azure DevOps #Cloud #Kubernetes #Security #DevSecOps #Deployment #Azure #DevOps #Logging #Scripting #Cybersecurity #AWS (Amazon Web Services) #Consulting #Automation #Network Security #Terraform #Vault #GitLab #Infrastructure as Code (IaC) #GCP (Google Cloud Platform) #IAM (Identity and Access Management) #MDM (Master Data Management) #Data Privacy #ML (Machine Learning) #Bash
Role description
Company Description Silpa Companies, LLC is a national IT consulting and staffing firm empowering organizations across multiple industries through a blend of AI adoption, Master Data Management, Data and Analytics, Cybersecurity, Cloud Engineering, DevSecOps/GitOps, Fractional C-Suite leadership, Digital Transformation, and M&A advisory for private equity and software ventures. Role Description Silpa Companies is seeking a hands-on DevSecOps Engineer for contract, project-based engagements across our cloud engineering, application security, and platform delivery portfolio. You will embed with client engineering teams to build, secure, and automate the pipelines, infrastructure, and delivery workflows that power modern software organizations. This role sits at the intersection of development, operations, and security. You are not a policy writer or an auditor. You are an engineer who builds secure systems, automates security controls into pipelines, and hardens cloud infrastructure across Azure, AWS, and GCP. You are comfortable writing Terraform, tuning a SIEM alert, reviewing a Dockerfile for security misconfigurations, and advising a development team on secrets management in the same week. Versatility and technical depth are what make this role work. Key Responsibilities CI/CD Pipeline Security and Automation β€’ Design, build, and maintain secure CI/CD pipelines using GitHub Actions, Azure DevOps, Jenkins, GitLab CI, or equivalent tooling. β€’ Integrate SAST, DAST, SCA, container scanning, and secrets detection tools directly into pipeline workflows. β€’ Enforce security gates, policy-as-code checks, and compliance controls as automated pipeline steps. β€’ Manage pipeline secrets, service credentials, and environment configurations using vault solutions (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault). β€’ Continuously improve pipeline performance, reliability, and security posture across client delivery environments. Cloud Infrastructure and Security β€’ Design and implement secure cloud infrastructure across Azure, AWS, and GCP using infrastructure-as-code (Terraform, Bicep, CloudFormation, Pulumi). β€’ Harden cloud environments against misconfigurations using tools such as Prisma Cloud, Wiz, Defender for Cloud, or AWS Security Hub. β€’ Implement and manage identity and access controls including IAM policies, service accounts, RBAC, and least-privilege enforcement. β€’ Configure and maintain network security controls including VPCs, security groups, private endpoints, and zero-trust network access patterns. β€’ Monitor cloud environments for security events, anomalies, and compliance drift using SIEM and cloud-native observability platforms. Container and Platform Security β€’ Secure containerized workloads and Kubernetes clusters including pod security policies, network policies, image scanning, and runtime protection. β€’ Manage and harden Kubernetes environments across AKS, EKS, and GKE. β€’ Enforce image provenance, vulnerability scanning, and supply chain security practices across container registries. β€’ Contribute to service mesh configuration and workload identity management in containerized environments. Collaboration and Engineering β€’ Partner with development teams to shift security left and build a culture of secure-by-default engineering. β€’ Conduct architecture reviews and threat modeling sessions to identify security risks early in the development lifecycle. β€’ Produce clear documentation for pipelines, runbooks, security controls, and infrastructure configurations. β€’ Support incident response activities including forensic data collection, environment containment, and post-incident hardening. AI and LLM Security β€’ Assess and harden AI-powered applications and LLM integrations against threats defined in the OWASP LLM Top 10 including prompt injection, insecure output handling, and model denial of service. β€’ Integrate AI-specific security scanning and validation controls into CI/CD pipelines for applications that consume LLM APIs or deploy ML models. β€’ Evaluate and enforce data privacy and access controls for AI workloads including RAG pipelines, vector databases, fine-tuning datasets, and model endpoints. β€’ Advise engineering teams on secure prompt design, input sanitization, and output filtering for LLM-integrated applications. β€’ Monitor AI and ML infrastructure for anomalous usage patterns, model misuse, and data exfiltration risks. β€’ Support secure deployment of AI services across Azure OpenAI, AWS Bedrock, and Google Vertex AI including network isolation, identity controls, and logging. What We Are Looking For β€’ 3 or more years of hands-on DevSecOps, platform engineering, or cloud security engineering experience. β€’ Proficiency with CI/CD tooling and the ability to build and modify pipelines, not just run them. β€’ Hands-on experience securing infrastructure and workloads across Azure, AWS, and GCP. β€’ Strong IaC skills with Terraform and at least one cloud-native IaC tool (Bicep, CloudFormation, or Pulumi). β€’ Experience with container security across Docker and Kubernetes, including cluster hardening and image scanning. β€’ Working knowledge of application security tooling including SAST, DAST, SCA, and secrets scanning solutions. β€’ Familiarity with AI and LLM security risks including OWASP LLM Top 10, prompt injection, data leakage through model outputs, and supply chain risks in ML pipelines. β€’ Familiarity with compliance frameworks (SOC 2, NIST, CIS Benchmarks) as they apply to cloud and pipeline environments. β€’ Strong scripting skills in Python, Bash, or PowerShell to automate security and operations workflows. Preferred Certifications β€’ AWS Certified Security Specialty β€’ Microsoft Certified: Azure Security Engineer Associate β€’ Google Cloud Professional Cloud Security Engineer β€’ Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS) β€’ HashiCorp Certified: Terraform Associate β€’ Certified DevSecOps Professional (CDP) or equivalent β€’ CompTIA Security+ or equivalent foundational security certification Eligibility Requirements β€’ Authorized to work in the U.S. β€’ Candidates located in the Houston, Texas area will be given preference; however, remote practitioners will also be considered. β€’ Reliable, secure internet connection and ability to travel to client sites as required by engagement scope. β€’ Available to mobilize within a standard engagement window and maintain consistent availability throughout project duration. Why Work With Us? Silpa Companies places DevSecOps Engineers on engagements where the work is real, the environments are complex, and your contributions directly improve how clients build and ship software. You will work across cloud platforms, pipeline toolchains, and security stacks that span multiple industries and technology maturity levels. No two engagements are the same. Engineers who bring technical depth and a security-first mindset build strong reputations within the Silpa network and are consistently prioritized for follow-on and expanded scope engagements.