Summary
ampliFI Loyalty Solutions provides outsourced, customized credit and debit card loyalty programs for banks and credit unions. The DevSecOps Engineer will embed automated security guardrails, vulnerability scanning, and compliance controls into cloud platforms and CI/CD pipelines while managing security tooling, automating vulnerability remediation, and establishing secure multi-cloud integrations.
Responsibilities
- Implement, configure, and maintain automated security scanning platforms (SAST, DAST, SCA, container scanning) across our development pipelines
- Triage security scan findings and automate remediation workflows to streamline vulnerability management across teams
- Partner with Architecture and Engineering to establish secure multi-cloud guardrails, including AWS-to-GCP identity federation, KMS key management, and API gateway access controls for AI platform integrations
- Enforce Infrastructure as Code (IaC) security automation (such as Terraform, Checkov, and Trivy) to embed policy-as-code across environments
- Serve as a Subject Matter Expert (SME) for cloud security tooling, CI/CD automation, and multi-cloud access patterns, providing technical guidance across the organization
- Proactively tune security tools to reduce false positives and eliminate operational noise for software delivery teams
- Serve as a secondary point of escalation for security and platform incidents, rather than participating in the primary on-call rotation
- Coordinate technical resolution during security events and contribute to post-mortem analysis to prevent recurrence
Skills
- 3 to 5+ years of experience in DevSecOps, cloud security, or platform security engineering
- Multi-cloud experience across public cloud platforms, with deep expertise in AWS and working experience in GCP (Google Cloud Platform)
- Deep experience with AWS core security infrastructure (IAM, KMS, Secrets Manager, VPC, EKS/ECS)
- Strong proficiency in Terraform or AWS CDK to enforce infrastructure guardrails as code across cloud environments
- Hands-on experience integrating security testing tools (SAST/DAST/SCA/Container scanning) into CI/CD pipelines (GitHub Actions, AWS CodeBuild, or Jenkins)
- Experience establishing identity flows, OAuth configurations, and Workload/Workforce Identity Federation across multi-cloud environments (AWS and GCP)
- Hands-on experience with container security, image scanning repositories (ECR, Trivy), and containerized application runtime security
- Proficiency in CloudWatch, SIEM log monitoring, and security findings triage
- Cross-Functional Collaborator: Able to navigate and work effectively across multiple departments (Security, Dev, Ops, Architecture), bridging technical gaps to ensure successful integrations
- Based at ampliFI's Naperville, IL Corporate office, this hybrid role requires onsite reporting Tuesday-Thursday weekly
- National remote opportunities require residency in one of the following states AZ, CO, FL, GA, IL, IN, MA, MT, NC, NE, NH, NJ, NY, OH, PA, SC, TX, UT, VA, or WI
- This role involves sitting or standing for extended periods, using computers, phones, and other office equipment
- Visual acuity and manual dexterity are needed for reading documents and handling materials
- Occasional lifting of items up to 20 lbs. and frequent phone communication is required
- Professional or Associate cloud or security certifications (such as AWS Certified Security Specialty, GCP Professional Cloud Security Engineer, CISSP, AWS SysOps Administrator, or DevOps Engineer)
- Hands-on experience implementing cross-cloud integration patterns between AWS workloads and GCP enterprise services (such as Google Gemini Enterprise Plus)
- High proficiency in scripting languages (Python, Go, Bash, or PowerShell) to automate security workflows and vulnerability triage
- Direct experience with container orchestration platforms (AWS ECS/Fargate or EKS) and microservice security
- Familiarity with database security controls and encrypted connectivity in cloud environments (Postgres, MySQL, DynamoDB)
Qualifications
Must Haves
- 3 to 5+ years of experience in DevSecOps, cloud security, or platform security engineering
- Multi-cloud experience across public cloud platforms, with deep expertise in AWS and working experience in GCP (Google Cloud Platform)
- Deep experience with AWS core security infrastructure (IAM, KMS, Secrets Manager, VPC, EKS/ECS)
- Strong proficiency in Terraform or AWS CDK to enforce infrastructure guardrails as code across cloud environments
- Hands-on experience integrating security testing tools (SAST/DAST/SCA/Container scanning) into CI/CD pipelines (GitHub Actions, AWS CodeBuild, or Jenkins)
- Experience establishing identity flows, OAuth configurations, and Workload/Workforce Identity Federation across multi-cloud environments (AWS and GCP)
- Hands-on experience with container security, image scanning repositories (ECR, Trivy), and containerized application runtime security
- Proficiency in CloudWatch, SIEM log monitoring, and security findings triage
- Cross-Functional Collaborator: Able to navigate and work effectively across multiple departments (Security, Dev, Ops, Architecture), bridging technical gaps to ensure successful integrations
- Based at ampliFI's Naperville, IL Corporate office, this hybrid role requires onsite reporting Tuesday-Thursday weekly
- National remote opportunities require residency in one of the following states AZ, CO, FL, GA, IL, IN, MA, MT, NC, NE, NH, NJ, NY, OH, PA, SC, TX, UT, VA, or WI
- This role involves sitting or standing for extended periods, using computers, phones, and other office equipment
- Visual acuity and manual dexterity are needed for reading documents and handling materials
- Occasional lifting of items up to 20 lbs. and frequent phone communication is required
Nice to Haves
- Professional or Associate cloud or security certifications (such as AWS Certified Security Specialty, GCP Professional Cloud Security Engineer, CISSP, AWS SysOps Administrator, or DevOps Engineer)
- Hands-on experience implementing cross-cloud integration patterns between AWS workloads and GCP enterprise services (such as Google Gemini Enterprise Plus)
- High proficiency in scripting languages (Python, Go, Bash, or PowerShell) to automate security workflows and vulnerability triage
- Direct experience with container orchestration platforms (AWS ECS/Fargate or EKS) and microservice security
- Familiarity with database security controls and encrypted connectivity in cloud environments (Postgres, MySQL, DynamoDB)
Benefits
- 401(k) with employer match
- Medical, dental, vision, and life insurance
- Voluntary café plans, including voluntary life, accident, hospital, critical care, and parking/transit options
- Tuition Reimbursement
- Paid time off, company holidays, and parental leave
- Employee Assistance Program
- Hybrid work environment with flexible hours
- Onsite perks including gym access and snacks
- Employee recognition programs celebrating milestones and achievements
- Growth opportunities within a supportive, team-oriented environment