
Senior DevSecOps Engineer
About us
Itero Group is a Women-Owned Small Business focused on simplifying complex transformations. We empower clients in the private and government sectors to become more optimized, digitally enabled, and data-driven organizations through our comprehensive business consulting and innovative delivery solutions.
Itero Group's dedicated team members are experienced thought leaders, tenacious workers, and creative thinkers. We hire people who are passionate about being catalysts for change - in our company, for our clients, throughout our career- and we empower people to express their ideas, create better practices, innovate better products, and become better professionals.
We have been named a Great Place to Work for six years, and offer a competitive salary and benefits package.
We are seeking a Senior DevSecOps Engineer to drive hands-on security automation for AWS delivery. This role will focus on building secure-by-default CDK constructs, CloudFormation templates, and compliance-as-code solutions aligned to CJIS and NIST standards. You will integrate security into CI/CD pipelines, deliver reusable guardrails, and provide evidence artifacts to support enterprise adoption. While AWS is the immediate priority, Azure support may be introduced in future phases.
Scope Boundaries
-
Does not own enterprise AWS Organizations or SCP operations.
-
Designs and builds reference guardrails and enforcement patterns deployable by enterprise teams.
-
Focuses on preventive controls and compliance automation, not incident response.
What You Will Deliver
First 90 Days
-
Pipeline security templates in GitHub Actions and Azure DevOps with SAST, SCA, IaC, container, and secret scanning gates.
-
Compliance as code in reference accounts using AWS Config rules and Security Hub standards aligned to CJIS and NIST 800-53, with documented exceptions workflow.
-
IaC reference modules with AWS CDK and CloudFormation for IAM least privilege, KMS, Secrets Manager, logging, and network baselines; provide Terraform equivalents where required.
-
Evidence exports tying checks to control IDs and producing auditor-ready artifacts.
Ongoing
-
Harden CDK/CFT modules and pipeline templates as compliance needs evolve.
-
Coach pilot teams to adopt templates.
-
Raise gaps to enterprise teams for org-level enforcement.
Day-to-Day Responsibilities
-
Author and maintain AWS CDK constructs and CloudFormation templates; provide Terraform versions as secondary.
-
Implement AWS Config conformance, Security Hub standards, and GuardDuty routing in reference accounts.
-
Integrate security scanning into CI/CD pipelines for application code, containers, and IaC.
-
Build reusable GitHub/Azure DevOps templates with enforcement gates and exception handling.
-
Generate posture and evidence reports mapped to CJIS and NIST controls.
Required Skills
-
5+ years of AWS security automation and DevOps experience.
-
Strong expertise in AWS CDK and CloudFormation; working proficiency in Terraform.
-
CI/CD pipeline authoring with GitHub Actions and Azure DevOps.
-
Proficient in Python and Bash; PowerShell for Windows automation.
-
Ability to read Java and C# for SAST/SCA integration and tuning.
-
Practical knowledge of CJIS and NIST 800-53 control families, including compliance automation and evidence generation.
Nice to Have
-
Security hardening patterns for EKS, ECS, and Lambda.
-
Familiarity with OPA/Conftest, Checkov, Trivy, Inspector, CodeQL, or equivalent.
-
Basic Azure security automation for future phases.
If you are looking for a role where you will lead with integrity, create and innovate, inspire excellence, be a respected member of the team, drive results, and have fun, we look forward to connecting with you!
Benefits at Itero Group
At Itero Group, we’re proud to offer a comprehensive benefits package designed to support your health, financial well-being, and work-life balance:
- Health & Wellness: Medical (BC-BS), dental, and vision plans to suit your needs.
- Paid Time Off: Generous PTO, paid holidays, and increasing PTO based on years of service.
- Retirement Savings: 401(k) plan with company match and auto-enrollment.
- Company-Paid Coverage: Short-term and long-term disability, life insurance, and AD&D insurance.
- Additional Options: Voluntary benefits including pet insurance and student loan assistance up to $1,000 annually.
- Perks: FSAs, HSAs, wellness programs, and more to enhance your work-life balance.
Join us and enjoy a benefits package designed with you in mind!
Itero Group is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, veteran status or political affiliation.
Create a Job Alert
Interested in building your career at Itero Group? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field