Zazz.io
IT Services & IT Consulting
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
This is a remote position.
We are looking for a Part-Time DevSecOps Engineer to support a growing technology company operating primarily in AWS, with a strong focus on security, compliance, infrastructure management, production support, and segregation of duties (SoD).
This role is particularly important from a governance and security perspective. The successful candidate will provide an independent technical function between development, infrastructure, production, and security/compliance activities, ensuring that production access, deployments, access management, monitoring, and audit requirements are handled appropriately.
The role is expected to average up to approximately 20 hours per week, with workload varying based on business requirements. Additional support may be required during SOC 2 audit preparation, evidence collection, DR testing, and other compliance periods.
The ideal candidate is someone who can operate independently, exercise sound security judgment, and take ownership of assigned infrastructure and compliance responsibilities without requiring constant direction.
Manage and support AWS infrastructure and environments.
Work extensively with Terraform / Infrastructure as Code (IaC) for infrastructure provisioning, migrations, and deployments.
Manage AWS access, permissions, security groups, and related infrastructure controls.
Support production deployments and infrastructure changes while maintaining appropriate segregation of duties.
Troubleshoot infrastructure issues and provide production support for live applications.
Support client onboarding activities, including configuring environments and enabling secure data movement into AWS environments.
Maintain accurate AWS infrastructure and asset documentation.
Monitor production environments and take appropriate action when issues or security concerns are identified.
Support application and infrastructure deployments and migrations.
Participate in continuous monitoring of the production and security environment.
Work with development and engineering teams while maintaining appropriate separation between development and production access.
Investigate and resolve infrastructure/security-related issues.
Ensure changes are appropriately documented and controlled.
Manage access for new hires, terminated employees, and existing users.
Conduct periodic access reviews and ensure access remains appropriate based on role and responsibilities.
Manage AWS security groups and access controls.
Support the company's overall security environment and access-management processes.
Help maintain segregation of duties between development, infrastructure, and production activities.
Support endpoint/laptop security management through Scalefusion.
Maintain laptop and infrastructure inventories and related security documentation.
Monitor and maintain security posture using tools such as SecurityScorecard.
Support annual and year-end SOC 2 compliance activities.
Review and recommend updates to:
IT Security Policies
Access Control Policies
Disaster Recovery (DR) Policies
Change Control Policies
Prepare recommendations and provide them to the appropriate leadership/COO for approval.
Review and update Security Awareness Training materials and obtain required approvals.
Conduct annual Security Awareness Training.
Support preparation for annual audits and review prior-year audit requirements and evidence requests.
Gather, organize, validate, and maintain audit evidence.
Support auditors and internal stakeholders with technical evidence and documentation as required.
Conduct vulnerability testing approximately twice per year using AppCheck.
Review vulnerability findings and support remediation activities where required.
Participate in and own assigned components of Disaster Recovery (DR) tests.
Verify that DR documentation is accurate, complete, and current.
Support increased DR-related workload during scheduled testing periods.
Conduct security awareness and policy training for new hires.
Support secure onboarding processes and access provisioning.
Ensure terminated employees' access is appropriately removed.
Maintain documentation related to access, security training, and employee lifecycle controls.
Understand and document the company's AWS SageMaker environment.
Support the ongoing management and maintenance of the SageMaker environment.
Maintain appropriate access controls and documentation.
Take ownership of assigned SageMaker infrastructure and operational activities.
Strong hands-on experience with AWS infrastructure and cloud environments.
Strong experience with Terraform and Infrastructure as Code.
Experience managing AWS IAM, permissions, security groups, and access controls.
Experience supporting production environments and live applications.
Strong understanding of DevSecOps principles and practices.
Experience with cloud security and infrastructure security.
Experience with monitoring, troubleshooting, and incident response.
Experience with infrastructure migrations and deployments.
Experience with access management and user lifecycle management.
Experience working with security/compliance controls in a production environment.
Familiarity with SOC 2 requirements and audit evidence processes.
Experience with Disaster Recovery testing and documentation.
Experience with vulnerability assessment/testing tools; AppCheck experience is preferred.
Familiarity with AWS SageMaker and machine-learning infrastructure is preferred.
Experience with endpoint/device management platforms such as Scalefusion is preferred.
Familiarity with security posture management tools such as SecurityScorecard is preferred.
The ideal candidate should understand that this is not purely an infrastructure engineering position. The role requires strong awareness of:
Segregation of duties (SoD)
Least-privilege access
Production access controls
Access reviews
Change management
Security policies and controls
SOC 2 compliance
Audit evidence management
Disaster Recovery
Vulnerability management
Security awareness
Secure employee onboarding/offboarding
Experience working within environments serving financial institutions, banks, or other security-sensitive clients is highly desirable.
We are looking for someone who:
Can work independently with limited day-to-day supervision.
Takes ownership rather than waiting for detailed instructions.
Has strong attention to security, documentation, and compliance requirements.
Can balance engineering execution with governance and security controls.
Communicates clearly with technical and non-technical stakeholders.
Is comfortable working as an extension of an internal technology team.
Can provide reliable support during both normal operating periods and higher-demand audit/DR periods.
Understands the importance of controlled access to production environments and sensitive client data.
Experience supporting SOC 2 Type II environments.
Experience supporting financial services, banking, fintech, or other regulated environments.
AWS certifications such as AWS Solutions Architect, AWS Security Specialty, or equivalent experience.
Terraform certification or strong demonstrable Terraform experience.
Experience managing ML/cloud environments, particularly SageMaker.
Experience with security and compliance tools such as AppCheck, SecurityScorecard, and Scalefusion.
Previous experience working in a part-time DevSecOps or managed-services capacity.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Marathon TS

Metabase

T-Rex Solutions, LLC

Tiger Resourcing Group

T-Rex Solutions, LLC

Zazz.io

Zazz.io

Zazz.io