Archived listing. The details below describe a past opening.
SENIOR DEVSECOPS ENGINEER
JOB OVERVIEW:
Libryo is a regulatory-compliance (EHS) SaaS platform within ERM Group. We are looking for a Senior DevSecOps Engineer to automate and harden how we build, ship, and run software on AWS. You will own our CI/CD pipelines and Infrastructure as Code, drive automation across development and operations, and embed security as code at every stage. As a compliance platform, our own security and auditability are part of the product - so security is built into everything you ship, not bolted on afterwards.
KEY RESPONSIBILITIES:
- Own and continuously improve CI/CD pipelines, with security gates (SAST/DAST, dependency and container scanning, secrets detection, policy-as-code) embedded as standard.
- Manage Infrastructure as Code and automate provisioning, configuration, scaling, patching, backups, and disaster recovery - reducing manual toil across environments.
- Manage, monitor, and harden AWS infrastructure (network, IAM, encryption, logging) for security, reliability, performance, and cost efficiency.
- Operate containerized and orchestrated workloads with automation and security enforced as code.
- Harden systems at OS and application level - secure baselines, patching, framework/library and API security, and encryption in transit and at rest across multiple stacks.
- Stand up and maintain observability and security tooling (logging, alerting, threat detection, compliance monitoring), and support incident response and vulnerability management through to remediation.
- Map and evidence technical controls against ISO 27001:2022, SOC 2, and CIS benchmarks, and contribute to AI-security controls aligned to ISO/IEC 42001 and the OWASP LLM Top 10 as our AI workloads mature.
- Maintain documentation of systems, pipelines, controls, and runbooks suitable for audit.
REQUIREMENTS:
- Experience: Minimum 8 years in DevOps, cloud, or platform engineering, including substantial production experience operating workloads on AWS and a proven track record of securing cloud and application environments.
CLOUD & AUTOMATION (AWS) - REQUIRED
- Deep, hands-on AWS expertise across compute, networking, IAM, and data services.
- Proven end-to-end CI/CD ownership (e.g., GitLab CI, GitHub Actions) and strong Infrastructure as Code practice (e.g., Terraform, CloudFormation).
- Experience with containerization and orchestration (e.g., Docker, Kubernetes) and the judgement to adopt equivalent or successor tooling as the ecosystem evolves.
- Scripting and automation (Python, Bash), monitoring and logging (e.g., CloudWatch, GuardDuty, Prometheus/Grafana, ELK), and disciplined Git-based release workflows.
- A current AWS certification is required - Solutions Architect – Associate or higher, or SysOps/DevOps. Professional-level certification strongly preferred.
SECURITY - REQUIRED (CORE TO THE ROLE)
- Demonstrable experience securing cloud and application environments, not security-adjacent exposure.
- Working familiarity with OWASP, CIS benchmarks, and ISO 27001 controls.
- Strong grasp of secure network design (segmentation, VPNs, firewall rules, routing) and secure-coding and threat-modelling across multiple stacks (PHP, Python, Vue.js).
- Ability to integrate security into infrastructure and deployment by default, and excellent communication and collaboration across development and operations teams.
PREFERRED QUALIFICATIONS
- A security certification is a strong plus - AWS Certified Security – Specialty, CISSP, CCSP, or equivalent; plus AWS Professional-level certification, advanced AWS services (Lambda, ECS, RDS), and SaaS compliance exposure (SOC 2, ISO 27001) and AI/LLM security governance.
⠀
ERM is committed to creating an inclusive workplace where everyone feels valued, respected, and empowered to thrive, it’s an essential part of what makes ERM a great place to build a career and helps us create better solutions for our clients.
We welcome talent from all backgrounds and provide equal opportunities for every candidate. If you have a disability, are neurodivergent, or need accommodations during the selection process, we’re here to support you. Our commitment doesn’t stop at hiring. Once you join us, we’ll ensure you have the tools, support, and adjustments needed to succeed and feel a true sense of belonging. Learn more about our Diversity, Inclusion & Belonging (DIB) efforts by visiting our website or exploring our 2026 Sustainability Report.