Logo for Zazz.io

DevSecOps Engineer – AWS, Terraform & Security Compliance - Contract

Role overview

Qualifications

  • Strong hands-on experience with AWS infrastructure and cloud environments.
  • Strong experience with Terraform and Infrastructure as Code.
  • Experience managing AWS IAM, permissions, security groups, and access controls.
  • Experience supporting production environments and live applications.

Responsibilities

  • Manage and support AWS infrastructure and environments.
  • Monitor production environments and take appropriate action when issues or security concerns are identified.
  • Manage access for new hires, terminated employees, and existing users.
  • Support annual and year-end SOC 2 compliance activities.

About the company

Zazz.io logo

Zazz.io

IT Services & IT Consulting

We at Zazz are triggering a Digital & Mobile revolution, by using code, passion, ideas, emotions, and the world’s most powerful technological platforms. We believe in crafting incredible experiences for the users, and our mission is to unleash unstoppable success and sustainable growth for our clients, all across the globe. Our 275+ strong team of UI/UX experts, talented programmers and dedicated business analysts, marketing mavericks, mobile app architects, solution engineers etc, based globally across the world. Wecreate scalable, powerful, and aesthetically stunning mobile apps and websites, powered with futuristic technologies such as Artificial Intelligence, Machine Learning, Internet Of Things, Metaverse and a lot more. If you’re still wondering Why Zazz? Well, because we are the change-makers, the disruptors of the status quo. We’re determined to provide the best in the class technological services to startups, SMEs, enterprises, and corporations all across the US and Canada. We’re the unfair advantage that you can have for the success of your company. Led by strong leadership, we at Zazz have incorporated a growth mindset, an agile working model, and a passion for delivering solutions and success, no matter how hard the challenge is. Team Zazz invites you to join forces with us because together, we can create a better, more beautiful, and breathtaking future. Join us, and experience the future of mobile and digital, right here, right now!

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

About the Role

We are looking for a Part-Time DevSecOps Engineer to support a growing technology company operating primarily in AWS, with a strong focus on security, compliance, infrastructure management, production support, and segregation of duties (SoD).

This role is particularly important from a governance and security perspective. The successful candidate will provide an independent technical function between development, infrastructure, production, and security/compliance activities, ensuring that production access, deployments, access management, monitoring, and audit requirements are handled appropriately.

The role is expected to average up to approximately 20 hours per week, with workload varying based on business requirements. Additional support may be required during SOC 2 audit preparation, evidence collection, DR testing, and other compliance periods.

The ideal candidate is someone who can operate independently, exercise sound security judgment, and take ownership of assigned infrastructure and compliance responsibilities without requiring constant direction.

Key Responsibilities

AWS Infrastructure & Infrastructure as Code

  • Manage and support AWS infrastructure and environments.

  • Work extensively with Terraform / Infrastructure as Code (IaC) for infrastructure provisioning, migrations, and deployments.

  • Manage AWS access, permissions, security groups, and related infrastructure controls.

  • Support production deployments and infrastructure changes while maintaining appropriate segregation of duties.

  • Troubleshoot infrastructure issues and provide production support for live applications.

  • Support client onboarding activities, including configuring environments and enabling secure data movement into AWS environments.

  • Maintain accurate AWS infrastructure and asset documentation.

DevSecOps & Production Support

  • Monitor production environments and take appropriate action when issues or security concerns are identified.

  • Support application and infrastructure deployments and migrations.

  • Participate in continuous monitoring of the production and security environment.

  • Work with development and engineering teams while maintaining appropriate separation between development and production access.

  • Investigate and resolve infrastructure/security-related issues.

  • Ensure changes are appropriately documented and controlled.

Security & Access Management

  • Manage access for new hires, terminated employees, and existing users.

  • Conduct periodic access reviews and ensure access remains appropriate based on role and responsibilities.

  • Manage AWS security groups and access controls.

  • Support the company's overall security environment and access-management processes.

  • Help maintain segregation of duties between development, infrastructure, and production activities.

  • Support endpoint/laptop security management through Scalefusion.

  • Maintain laptop and infrastructure inventories and related security documentation.

  • Monitor and maintain security posture using tools such as SecurityScorecard.

SOC 2, Compliance & Audit Support

  • Support annual and year-end SOC 2 compliance activities.

  • Review and recommend updates to:

    • IT Security Policies

    • Access Control Policies

    • Disaster Recovery (DR) Policies

    • Change Control Policies

  • Prepare recommendations and provide them to the appropriate leadership/COO for approval.

  • Review and update Security Awareness Training materials and obtain required approvals.

  • Conduct annual Security Awareness Training.

  • Support preparation for annual audits and review prior-year audit requirements and evidence requests.

  • Gather, organize, validate, and maintain audit evidence.

  • Support auditors and internal stakeholders with technical evidence and documentation as required.

Vulnerability Management & Disaster Recovery

  • Conduct vulnerability testing approximately twice per year using AppCheck.

  • Review vulnerability findings and support remediation activities where required.

  • Participate in and own assigned components of Disaster Recovery (DR) tests.

  • Verify that DR documentation is accurate, complete, and current.

  • Support increased DR-related workload during scheduled testing periods.

Employee Security Onboarding & Offboarding

  • Conduct security awareness and policy training for new hires.

  • Support secure onboarding processes and access provisioning.

  • Ensure terminated employees' access is appropriately removed.

  • Maintain documentation related to access, security training, and employee lifecycle controls.

SageMaker Environment

  • Understand and document the company's AWS SageMaker environment.

  • Support the ongoing management and maintenance of the SageMaker environment.

  • Maintain appropriate access controls and documentation.

  • Take ownership of assigned SageMaker infrastructure and operational activities.

Required Technical Skills & Experience

  • Strong hands-on experience with AWS infrastructure and cloud environments.

  • Strong experience with Terraform and Infrastructure as Code.

  • Experience managing AWS IAM, permissions, security groups, and access controls.

  • Experience supporting production environments and live applications.

  • Strong understanding of DevSecOps principles and practices.

  • Experience with cloud security and infrastructure security.

  • Experience with monitoring, troubleshooting, and incident response.

  • Experience with infrastructure migrations and deployments.

  • Experience with access management and user lifecycle management.

  • Experience working with security/compliance controls in a production environment.

  • Familiarity with SOC 2 requirements and audit evidence processes.

  • Experience with Disaster Recovery testing and documentation.

  • Experience with vulnerability assessment/testing tools; AppCheck experience is preferred.

  • Familiarity with AWS SageMaker and machine-learning infrastructure is preferred.

  • Experience with endpoint/device management platforms such as Scalefusion is preferred.

  • Familiarity with security posture management tools such as SecurityScorecard is preferred.

Security & Compliance Experience

The ideal candidate should understand that this is not purely an infrastructure engineering position. The role requires strong awareness of:

  • Segregation of duties (SoD)

  • Least-privilege access

  • Production access controls

  • Access reviews

  • Change management

  • Security policies and controls

  • SOC 2 compliance

  • Audit evidence management

  • Disaster Recovery

  • Vulnerability management

  • Security awareness

  • Secure employee onboarding/offboarding

Experience working within environments serving financial institutions, banks, or other security-sensitive clients is highly desirable.

Working Style

We are looking for someone who:

  • Can work independently with limited day-to-day supervision.

  • Takes ownership rather than waiting for detailed instructions.

  • Has strong attention to security, documentation, and compliance requirements.

  • Can balance engineering execution with governance and security controls.

  • Communicates clearly with technical and non-technical stakeholders.

  • Is comfortable working as an extension of an internal technology team.

  • Can provide reliable support during both normal operating periods and higher-demand audit/DR periods.

  • Understands the importance of controlled access to production environments and sensitive client data.

Preferred Qualifications

  • Experience supporting SOC 2 Type II environments.

  • Experience supporting financial services, banking, fintech, or other regulated environments.

  • AWS certifications such as AWS Solutions Architect, AWS Security Specialty, or equivalent experience.

  • Terraform certification or strong demonstrable Terraform experience.

  • Experience managing ML/cloud environments, particularly SageMaker.

  • Experience with security and compliance tools such as AppCheck, SecurityScorecard, and Scalefusion.

  • Previous experience working in a part-time DevSecOps or managed-services capacity.



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

DevSecOps Engineer Related jobs

Other jobs at Zazz.io

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.