Senior Site Reliability Engineer, SecOps
Job Description
<p>CMT is looking for a <strong>Senior Site Reliability Engineer, SecOps </strong>to help us change the world. CMT has helped protect over 65 million drivers and prevent over 126,000 crashes worldwide. We build AI to solve some of the most difficult challenges in mobility — understanding and reducing risk, detecting crashes, and getting people life-saving help. The problems are hard. The impact is real. No matter your role, your work will matter at CMT. </p> <p><strong>Responsibilities:</strong><strong> </strong></p> <ul> <li>Use independent judgment and discretion to implement security tooling and controls in AWS as defined by the Security Engineering team, including deployment, configuration, agent coverage, and ongoing tooling health </li> <li>Implement IAM Roles and Policies, account-level guardrails, and secrets management in AWS in line with Security Engineering standards </li> <li>Remediate vulnerability, cloud security posture, and compliance findings across the AWS estate, tracking work to the remediation SLAs defined by the Security Engineering team</li> <li>Own the security telemetry pipeline — org-wide CloudTrail, GuardDuty, Security Hub, AWS Config, VPC Flow Logs, and application/audit logs — including coverage validation, retention and immutability requirements, routing into Lacework and Datadog, and managing ingest/retention cost </li> <li>Implement and maintain preventive controls — SCPs/RCPs, permission boundaries, Config rules and conformance packs, IaC policy-as-code in CI, and secret scanning — including drift detection, auto-remediation, and a documented exception/waiver process with expiry </li> <li>Implement network and data protection controls: security group and egress baselines, VPC segmentation, KMS key lifecycle and rotation, encryption-at-rest/in-transit standards, certificate lifecycle, and public-exposure prevention (S3 Block Public Access, IAM Access Analyzer external findings). </li> <li>Codify everything as infrastructure-as-code using Terraform and CI/CD pipelines, enabling updates through Pull Requests with approval workflows, while also automating maintenance tasks to reduce toil</li> <li>Provide secure-by-default Terraform modules and self-service paved paths so product teams inherit controls; consult on design reviews and threat models; act as the translation layer between Security Engineering standards and platform/application reality, feeding back where standards are impractical. </li> <li>Participate in incident response for security events, contribute to blameless postmortems and systemic remediation, including participating in an on-call rotation </li> <li>Complete any additional tasks as they arise </li> </ul> <p><strong>Qualifications:</strong><strong> </strong></p> <ul> <li>Bachelor’s degree or equivalent years of experience and/or certification in a related field</li> <li>4+ years of experience working in Site Reliability Engineering or Information Technology </li> <li>Write and review code to automate away problems within your team’s domain</li> <li>Intermediate to expert experience deploying and maintaining AWS services such as EC2, ECS, EKS, SQS, Lambda, Dynamo, RDS/Aurora, S3, and IAM</li> <li>Intermediate to expert experience monitoring services and applications using tools such as CloudWatch Metrics, CloudWatch Logs, and Datadog, including defining and configuring alerts and SLO reports</li> <li>Intermediate to expert experience implementing and maintaining security controls and tooling in AWS, such as IAM, KMS, Security Hub, GuardDuty, Inspector, and Config</li> <li>Intermediate to expert coding skills in at