Kubernetes
AWS
GCP
Senior DevSecOps Engineer
Overview
Netlify’s SRE team is on a mission to scale Netlify’s infrastructure to support our next million users. We focus on ensuring application resiliency and delivering a robust compute and network platform at scale.
Job Description
Netlify is a remote-first company that values diversity and innovation. We are committed to building a better web by making it easier to build, deploy, and scale web applications. Our tech stack includes Kubernetes, AWS, GCP, Kafka, CDNs, and Golang-based microservices.
Responsibilities
- - Operate and manage security tools (e.g., SIEM, IDS/IPS) to monitor the organization''s security posture and detect suspicious activities
- - Manage full infrastructure lifecycle from design to decommission, ensuring systems are secure and compliant
- - Participate in an on-call rotation for the compute platform and related systems
- - Actively monitor security systems for anomalies and respond to security incidents
- - Automate routine tasks and develop tools to improve system efficiency and reduce the human intervention time on any tasks
- - Conduct system performance tuning and troubleshooting, as well as capacity planning, to ensure system reliability and efficiency
- - Participate in the creation and testing of disaster recovery plans
- - Perform regular security assessments and audits, including penetration testing and vulnerability scans
- - Educate team members on security best practices and emerging threats
Required Skills
- - Several years of experience in SRE, devops, security or related roles
- - Previous experience in a mixed role involving security and system operations
- - Proven experience working in hyperscale cloud environments
- - Demonstrated ability to lead security and infrastructure projects
- - Proficient in managing and securing cloud-based environments
- - Strong understanding of network protocols, configurations, and encryption technologies
- - Experience with automation tools (e.g., Ansible, Terraform) and scripting languages (e.g., Python, Bash, Golang)
- - Familiarity with compliance requirements and frameworks: PCI, ISO 2701, HIPAA, SOC 2
- - Experience automating component deployment across multiple environments using tools like Jenkins, CircleCI, or GitHub Actions
- - Proficient observability and log analysis techniques to detect and resolve security threats and system issues
- - Effective communication skills for both technical and non-technical stakeholders
Benefits
- - Remote work
- - Participation in Netlify’s equity plan
- - Comprehensive rewards package
About the company
Netlify is the essential platform for the delivery of exceptional and dynamic web experiences, without limitations.