Logo
Envoy

Member of Technical Staff, Security/DevSecOps

Envoy, San Francisco, California, United States, 94199

Save Job

Member of Technical Staff, Security/DevSecOps This range is provided by Envoy. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$190,000.00/yr - $205,000.00/yr

Envoy builds workspace management technology that makes it simple to run secure, compliant, and connected workplaces across every location. Over 16,000 workplaces and properties around the world rely on Envoy to create great experiences for employees and visitors while meeting safety, security, and compliance needs at scale. From corporate headquarters and labs to manufacturing sites, Envoy powers the places where people work best together.

This is an L3 opportunity. Successful candidates often come from senior engineering roles and are experienced in leading complex projects, mentoring peers, and making architectural contributions across teams. This onsite position requires 4 days a week (Monday-Thursday) in our San Francisco HQ office.

You will

Design, implement, and continuously improve security controls in AWS, including IAM policies, VPC network segmentation, Security Groups, and secure service configuration (e.g., S3, RDS, Lambda).

Own WAF management (Cloudflare WAF) — authoring rules, tuning managed rulesets, and monitoring attacks.

Integrate automated security guardrails into CI/CD pipelines (GitHub Actions) for IaC, container images, and serverless deployments.

Implement and enforce Infrastructure‑as‑Code (IaC) security scanning using tools such as tfsec, Trivy, Checkov, or Terrascan, with gating for critical findings.

Lead container and orchestration security for Docker and Kubernetes/EKS, including image scanning, admission controls, runtime monitoring (Falco), and benchmark enforcement (kube‑bench).

Establish and operate secrets‑management best practices using tools like HashiCorp Vault, AWS Secrets Manager, or SOPS, ensuring least‑privilege access.

Deploy, tune, and maintain AWS security services — GuardDuty, Security Hub, Config, CloudTrail, IAM Access Analyzer — for continuous detection and compliance.

Conduct cloud threat modeling and risk assessments (STRIDE, AWS Well‑Architected Framework) to identify gaps and prioritize mitigations.

Automate security compliance reporting against frameworks such as CIS Benchmarks and NIST 800‑53 using IaC and policy‑as‑code (e.g., Open Policy Agent).

Collaborate with infrastructure and product engineering teams to embed security early and unblock delivery velocity.

You are

Autonomous and highly organized, thriving in a fast‑moving environment.

Passionate about enabling secure cloud engineering without blocking developer velocity.

Intellectually curious, always experimenting with new cloud security tooling and best practices.

A clear, concise communicator who can translate complex security topics for diverse stakeholders.

You have

Hands‑on expertise securing AWS workloads, multi‑account architectures, and VPC design.

Deep knowledge of IAM policy design, role‑based access control, and least‑privilege enforcement.

Proficiency with Terraform or CloudFormation and experience implementing IaC security scans in CI/CD.

Demonstrated experience managing WAF solutions and mitigating web‑layer attacks (OWASP Top 10, bot mitigation).

Experience hardening container images and Kubernetes/EKS clusters, plus familiarity with container runtime security.

Strong scripting skills in Python, Go, or similar for automation and tooling integration.

Experience performing cloud security risk assessments and threat modeling for new services.

Familiarity with AWS security tooling (GuardDuty, Config, Security Hub, Macie, Access Analyzer).

Excellent written and verbal communication skills and the ability to educate engineers on secure practices.

Preferred certifications: AWS Certified Security – Specialty, CISSP, GIAC Cloud Security Automation (GCSA).

You'll get

A high degree of trust in your ideas and execution

An opportunity to partner and collaborate with other talented people

An inclusive community where you feel welcomed and cared for as a person

The ability to make an immediate impact by helping customers create a great workplace experience

Support for your personal and professional growth

If you have any questions related to compensation, please contact Recruiting after you apply.

By applying for this position, you acknowledge that you have fully read and understand the job requirements and received the Envoy Privacy Notice for applicants, which is linked here. Completing this application requires you to provide personal data, such as your name and contact information, which is mandatory for Envoy to process your application. Envoy is an EEO Employer and does not discriminate on the basis of any characteristic protected by local, state or federal law.

Compensation Range: $190K - $205K

Seniority level

Mid-Senior level

Employment type

Full-time

Job function

Engineering and Information Technology

Industries: Software Development

#J-18808-Ljbffr