12 sep
|
Echelon Risk + Cyber
|
Ciudad de México
12 sep
Echelon Risk + Cyber
Ciudad de México
About us: At Echelon Risk + Cyber, we believe in defending basic human rights to security and privacy. We are seeking a Senior DevSecOps Engineer with deep expertise in Microsoft Azure to embed security into every stage of our clients' software development lifecycle. This is a client-facing consulting role. You will be embedded with a dedicated Echelon client for an extended engagement, serving as the key liaison between Echelon's Security Team and the client's application development team. You will design and maintain secure, automated CI/CD pipelines, harden cloud infrastructure, and connect development, operations, and security. This is a hands-on engineering role for someone who thinks like an attacker, builds like a developer, and operates like an SRE. As the engagement matures, there will be opportunities to contribute to additional application security engagements across Echelon's client portfolio.Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions. At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environmentThis is a remote position from anywhere in Mexico. What You Will Do:Client Partnership & Liaison:Serve as the primary technical liaison between Echelon's Security Team and the client's application development team, embedded with a dedicated client on an extended engagement.Build trusted working relationships with client developers, DevOps engineers, architects, and engineering leadership; become the person they bring problems to before decisions get made.Translate Echelon security requirements into practical engineering guidance the client's teams can implement within their existing sprint cadence and release schedule.Represent Echelon in client ceremonies including sprint planning, architecture reviews, change advisory boards, and security design reviews.Escalate risks, blockers, and scope changes to Echelon leadership early, and keep client stakeholders informed through consistent status communication.Document decisions, standards, and remediation guidance so the work is transferable and the client retains value beyond the engagement.Contribute to additional application security engagements across Echelon's client portfolio as opportunities arise.Secure SDLC & Application Security:Design, build, and maintain secure CI/CD pipelines in Azure DevOps and GitHub Actions, integrating SAST, DAST, SCA, and container scanning at every stage.Partner with client development teams to shift security left, embedding threat modeling, secure coding practices, and secrets management into daily workflows.Triage and prioritize scanner findings alongside developers,
separating real risk from noise so remediation effort goes where it matters.Support secure code review, application threat modeling, and secure design guidance for new and existing client applications.Define and track application security metrics that demonstrate measurable improvement in the client's posture over the life of the engagement.Cloud Security Engineering:Architect and manage secure infrastructure-as-code (IaC) using Terraform, Bicep, or ARM templates, applying security-by-design principles.Implement and manage Azure security services: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Key Vault, Azure Policy, Entra ID Conditional Access, and Network Security Groups.Build and maintain container security practices for Azure Kubernetes Service (AKS), including image scanning, admission controls, and runtime protection.Develop and enforce IAM best practices, least-privilege access models, and secrets rotation policies using Key Vault and Managed Identities.Extend the same security practices into AWS where client workloads are multi-cloud or mid-migration.Automation, Monitoring & Response:Automate vulnerability management, patching workflows, and compliance checks across cloud and hybrid environments.Create and maintain security monitoring, logging, and alerting using Azure Monitor, Log Analytics, and SIEM integrations.Lead incident response efforts related to pipeline, cloud, or infrastructure security events.Mentor client and Echelon engineers, champion DevSecOps culture, and stay current on emerging threats, Azure security features, and compliance frameworks (SOC 2, ISO 27001, NIST, CIS Benchmarks). Your knowledge, skills, and abilities:Consulting & Client-Facing Experience:Experience delivering in a consulting, professional services, or managed services environment is required. This role sits inside a client's engineering organization, and success depends as much on client trust, communication, and judgment as on technical depth.Demonstrated ability to work as an embedded resource on a long-running client engagement, operating within the client's tools, processes, and release cadence rather than imposing your ownfort influencing without authority, driving security outcomes through developers and engineering leaders who do not report to you.Excellent communication skills, able to translate security risk into business terms for both technical and non-technical stakeholders.Only resumes in English will be considered.Technical Experience:5+ years in DevOps or DevSecOps roles, with 3+ years focused specifically on Microsoft Azure. Azure is the primary technical requirement for this role.AWS experience is a strong plus, particularly where client environments are multi-cloud or migrating between providers.Proven experience building and securing CI/CD pipelines (Azure DevOps, GitHub Actions, or similar).Strong hands-on experience with Azure security tooling: Defender for Cloud, Sentinel, Key Vault, Azure Policy,
and Entra ID.Proficiency with Infrastructure-as-Code (Terraform, Bicep, or ARM templates).Experience with containerization and orchestration (Docker, AKS/Kubernetes) and the associated security controls.Solid scripting and automation skills (PowerShell, Python, or Bash).Working knowledge of application and cloud security scanning tools such as Trivy, Snyk, SonarQube, Checkmarx, or Qualys.Understanding of network security fundamentals (NSGs, firewalls, VPNs, private endpoints) and application security fundamentals (OWASP Top 10, API security).Familiarity with compliance and regulatory frameworks (SOC 2, ISO 27001, NIST, CIS, GDPR as applicable).Strong English communication (C1/C2 Level) written and verbal.Authorized to work in Mexico without visa sponsorship.Certifications:Relevant cloud security and application security certifications are important for this role. Candidates should hold, or be actively working toward, credentials in both areas.Cloud security: AZ-500 (Azure Security Engineer Associate), SC-100 (Cybersecurity Architect Expert), AZ-400 (DevOps Engineer Expert), CCSP, or AWS Certified Security Specialty.Application security: CSSLP, GWAPT, GWEB, OSWE, or an equivalent secure development credential.Broader industry certifications such as CISSP, CISM, CEH, or OSCP are also valued.Preferred Qualifications:Prior experience as an embedded or dedicated consultant supporting a single enterprise client across a multi-month or multi-year engagement.Experience with policy-as-code (OPA/Gatekeeper, Azure Policy).Background in threat modeling (STRIDE, DREAD) and secure SDLC frameworks (OWASP SAMM, BSIMM).Experience working in regulated industries such as finance, healthcare, or government.Prior experience leading a security tooling migration or DevSecOps transformation initiative.Experience supporting multiple concurrent client engagements or transitioning between client accounts.Why Echelon? We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values is "People with Personality," and we want to allow you the space to bring your full self to work.We Currently Offer The Following Benefits: Access to private medical insurance through MetLifeLife insurance policy via MetLife30-day Christmas bonus and a monthly technology stipendContribution of 8% of the employee's salary to a savings fundFlexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.Family-friendly benefits, extended parental leave for when you need to spend critical time with new family members, and employer-paid short-term and long-term disabilitySupport for individual development through certifications, continued learning, conferences, and moreWe value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status, or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.
Job Posted by ApplicantPro
📌 Senior DevSecOps Engineer (Azure Experience) - Remote (Mexico)
🏢 Echelon Risk + Cyber
📍 Ciudad de México