CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

DevSecOps Engineer

Casa • United States or Canada- Remote

Job Description

<p><strong>MEET CASA</strong></p> <p><a href="http://casa.io">Casa</a> is the secure home for your bitcoin. We’re the leading provider of Bitcoin self-custody solutions, the ultimate blend of security, privacy, and control. Our team combines deep security expertise, human-focused design, and exceptional customer service to empower our clients and build lifelong relationships. </p> <p><strong>THE ROLE</strong></p> <p>Casa is looking for a DevSecOps Engineer to help secure our customers, their data, and our company. As a member of our Security team, you will report to our Chief Security Officer and play a crucial role in overseeing our security architecture and culture. It will also be a unique opportunity to help develop an evolving security program consisting of efficient processes, training materials, and methodologies for all employees.</p> <p>The successful candidate has experience developing scalable security controls and approaches in accordance with industry standards.</p> <p>Compensation: $125,000-155,000 USD</p> <p><strong>WHAT YOU'LL DO: </strong></p> <ul> <li>Handle internal security requests and make sure employees have the tools and access they need without over-provisioning</li> <li>Ensure that employees have access to the tools and systems they need while maintaining least privilege access principles</li> <li>Onboard and offboard employees across internal systems</li> <li>Oversee our MDM system and stay on top of alerts</li> <li>Review and assess new technologies (tools, code frameworks, third-party providers, internal apps) through a security lens</li> <li>Help shape and refine security best practices across the org</li> <li>Triage and work through vulnerabilities surfaced by pen testing, static analysis, responsible disclosures, and automated alerts</li> <li>Keep security documentation and training materials fresh and useful</li> <li>Automate security processes and alerts wherever you can find the leverage</li> <li>Participate in a shared on-call rotation for critical production security issues</li> <li>Stay abreast of the latest security events and trends</li> <li>Participate in regular security training and certification acquisition </li> <li>Ensure our software development lifecycle remains secure as we continue to evolve its processes.</li> <li>Write infrastructure-as-code to automate deployment and management using Terraform, Ansible, or similar tools</li> <li>Stay current on emerging threats, security trends, and what's happening across our stack and industry</li> <li>Investigate and resolve infrastructure incidents to keep things running smoothly</li> </ul> <p> </p> <p><strong>WHO YOU ARE: </strong></p> <ul> <li>You have security certifications or equivalent real-world experience</li> <li>You think like an attacker, and a hacker mindset is genuinely how you approach problems</li> <li>Deep background across multiple facets of security</li> <li>5+ years implementing security in Linux-based infrastructures, AWS, and code</li> <li>Comfortable with open-source tooling, cloud environments, and multiple operating systems</li> <li>Experience building security solutions that actually scale</li> <li>Hands-on with one or more of: penetration testing, threat modeling, code analysis, system hardening, distributed patching, vulnerability scanning</li> <li>Familiar with hardening AI tooling to prevent security incidents</li> <li>Strong communicator who can present findings to both technical and non-technical audiences</l

Job Reference ID: CF-174181 • Posted on CloudFrame Job Scanner