Role in brief
Alpaca, a financial services company with over $320 million in funding, seeks a Senior DevSecOps Engineer. This role involves enhancing security and resilience across cloud platforms and CI/CD pipelines, embedding security as code, and automating remediation. Candidates with strong experience in cloud security, Kubernetes, Terraform, and scripting with Python or Go, who can work remotely within EMEA, should apply.
About the role
This position focuses on integrating security practices throughout the development and operations lifecycle at Alpaca, a company that provides brokerage infrastructure to financial institutions globally. The role involves designing and implementing resilient systems, embedding security into continuous integration and delivery pipelines, and automating security processes. The goal is to proactively strengthen the cloud and Kubernetes environments and reduce the impact of security incidents.
A key aspect of this role is leading incident response for critical outages and driving improvements in observability to minimize the effects of security and infrastructure-related issues. The engineer will also be responsible for conducting security reviews and threat modeling for new services, ensuring that security is considered from the initial stages of development. This work contributes to maintaining a robust and secure platform for Alpaca's diverse client base.
Success in this role means consistently hardening deployments, effectively managing vulnerabilities and patching, and fostering a culture of 'security as code.' The individual will work cross-functionally with DevOps and engineering teams to achieve these objectives, contributing to Alpaca's mission of opening financial services worldwide with a secure and reliable infrastructure. The company emphasizes open-source contributions and a developer-friendly API.
The salary for this position ranges from $75,000 to $125,000 USD, in addition to stock options and health benefits.
Skills that matter here
- Kubernetes: The role requires strengthening and securing Kubernetes environments, along with container security.
- Terraform: Experience with Terraform is essential for managing infrastructure as code securely.
- Python: Proficiency in Python or similar languages is needed for automation and developing security tooling.
- Go: Proficiency in Go or similar languages is needed for automation and developing security tooling.
- CI/CD: The role involves embedding security into CI/CD pipelines and designing resilient pipelines.
- CSPs: Strong experience with Cloud Service Providers is required for enhancing cloud platform security.
Who this role suits
- A person with at least five years of experience specifically in DevSecOps, security engineering, or cloud security.
- Someone who is adept at automating security processes, including vulnerability management and patching workflows.
- An individual comfortable collaborating with DevOps and engineering teams to integrate security practices.
- A professional with a deep understanding of secure CI/CD, IaC security, and policy-as-code principles.
From the employer
- Design and implement resiliency across our cloud platform and CI/CD pipelines.
- Embed “security as code” and lead incident response for high-severity outages.
- Automate remediation and harden deployments.
- Own observability and drive reductions in security/infra related incident impact.
- Embed security into CI/CD pipelines and manage vulnerability and patch management.
- Strengthen cloud and Kubernetes environments.
- Conduct security reviews and threat modeling for new services.
- 5+ years of experience in DevSecOps, security engineering, or cloud security.
- Strong experience with CSPs, Kubernetes, Terraform, and container security.
- Deep understanding of secure CI/CD, including IaC security and policy-as-code.
- Solid background in identity & access security.
- Experience automating vulnerability management and patching workflows.
- Proficient in Python, Go, or similar for automation and security tooling.
- Comfortable working cross-functionally with DevOps and Engineering teams.
- Competitive Salary & Stock Options
- Health Benefits
- New Hire Home-Office Setup: One-time USD $500
- Monthly Stipend: USD $150 per month via a Brex Card
Questions about this role
What is the remote work policy for this role?
This is a fully remote position, specifically for candidates located within the EMEA region.
What level of seniority is expected for this position?
This is a senior-level role, requiring significant experience in DevSecOps or cloud security.
What kind of technical skills are important for this role?
Key technical skills include strong experience with Kubernetes, Terraform, cloud service providers, container security, and proficiency in Python or Go for automation.