Senior DevSecOps Engineer (Azure Experience) - Remote (Mexico)
Indexed description
Our next team member will be ready to roll up their sleeves and identify opportunities for our clients and for Echelon internally with unquestioned integrity. This team member will be passionate about cybersecurity and ready to use their knowledge to be an Entrepreneurial Problem Solver and work alongside their Echelon team members to build creative solutions.
At Echelon, you will have the opportunity to engage with clients, business partners and systems that are at the cutting edge of technology. We allow our employees to build from the ground up and make an impact across the organization. We look for driven and proactive people that are eager to contribute to a distinct and thriving Cybersecurity services organization, that can adapt to a rapid and changing environment
This is a remote position from anywhere in Mexico.
What You Will Do
Client Partnership & Liaison:
- Serve as the primary technical liaison between Echelon's Security Team and the client's application development team, embedded with a dedicated client on an extended engagement.
- Build trusted working relationships with client developers, DevOps engineers, architects, and engineering leadership; become the person they bring problems to before decisions get made.
- Translate Echelon security requirements into practical engineering guidance the client's teams can implement within their existing sprint cadence and release schedule.
- Represent Echelon in client ceremonies including sprint planning, architecture reviews, change advisory boards, and security design reviews.
- Escalate risks, blockers, and scope changes to Echelon leadership early, and keep client stakeholders informed through consistent status communication.
- Document decisions, standards, and remediation guidance so the work is transferable and the client retains value beyond the engagement.
- Contribute to additional application security engagements across Echelon's client portfolio as opportunities arise.
- Design, build, and maintain secure CI/CD pipelines in Azure DevOps and GitHub Actions, integrating SAST, DAST, SCA, and container scanning at every stage.
- Partner with client development teams to shift security left, embedding threat modeling, secure coding practices, and secrets management into daily workflows.
- Triage and prioritize scanner findings alongside developers, separating real risk from noise so remediation effort goes where it matters.
- Support secure code review, application threat modeling, and secure design guidance for new and existing client applications.
- Define and track application security metrics that demonstrate measurable improvement in the client's posture over the life of the engagement.
- Architect and manage secure infrastructure-as-code (IaC) using Terraform, Bicep, or ARM templates, applying security-by-design principles.
- Implement and manage Azure security services: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Key Vault, Azure Policy, Entra ID Conditional Access, and Network Security Groups.
- Build and maintain container security practices for Azure Kubernetes Service (AKS), including image scanning, admission controls, and runtime protection.
- Develop and enforce IAM best practices, least-privilege access models, and secrets rotation policies using Key Vault and Managed Identities.
- Extend the same security practices into AWS where client workloads are multi-cloud or mid-migration.
- Automate vulnerability management, patching workflows, and compliance checks across cloud and hybrid environments.
- Create and maintain security monitoring, logging, and alerting using Azure Monitor, Log Analytics, and SIEM integrations.
- Lead incident response efforts related to pipeline, cloud, or infrastructure security events.
- Mentor client and Echelon engineers, champion DevSecOps culture, and stay current on emerging threats, Azure security features, and compliance frameworks (SOC 2, ISO 27001, NIST, CIS Benchmarks).
- Experience delivering in a consulting, professional services, or managed services environment is required. This role sits inside a client's engineering organization, and success depends as much on client trust, communication, and judgment as on technical depth.
- Demonstrated ability to work as an embedded resource on a long-running client engagement, operating within the client's tools, processes, and release cadence rather than imposing your own.
- Comfort influencing without authority, driving security outcomes through developers and engineering leaders who do not report to you.
- Excellent communication skills, able to translate security risk into business terms for both technical and non-technical stakeholders.
- Only resumes in English will be considered.
- 5+ years in DevOps or DevSecOps roles, with 3+ years focused specifically on Microsoft Azure. Azure is the primary technical requirement for this role.
- AWS experience is a strong plus, particularly where client environments are multi-cloud or migrating between providers.
- Proven experience building and securing CI/CD pipelines (Azure DevOps, GitHub Actions, or similar).
- Strong hands-on experience with Azure security tooling: Defender for Cloud, Sentinel, Key Vault, Azure Policy, and Entra ID.
- Proficiency with Infrastructure-as-Code (Terraform, Bicep, or ARM templates).
- Experience with containerization and orchestration (Docker, AKS/Kubernetes) and the associated security controls.
- Solid scripting and automation skills (PowerShell, Python, or Bash).
- Working knowledge of application and cloud security scanning tools such as Trivy, Snyk, SonarQube, Checkmarx, or Qualys.
- Understanding of network security fundamentals (NSGs, firewalls, VPNs, private endpoints) and application security fundamentals (OWASP Top 10, API security).
- Familiarity with compliance and regulatory frameworks (SOC 2, ISO 27001, NIST, CIS, GDPR as applicable).
- Strong English communication (C1/C2 Level) written and verbal.
- Authorized to work in Mexico without visa sponsorship.
- Relevant cloud security and application security certifications are important for this role. Candidates should hold, or be actively working toward, credentials in both areas.
- Cloud security: AZ-500 (Azure Security Engineer Associate), SC-100 (Cybersecurity Architect Expert), AZ-400 (DevOps Engineer Expert), CCSP, or AWS Certified Security Specialty.
- Application security: CSSLP, GWAPT, GWEB, OSWE, or an equivalent secure development credential.
- Broader industry certifications such as CISSP, CISM, CEH, or OSCP are also valued.
- Prior experience as an embedded or dedicated consultant supporting a single enterprise client across a multi-month or multi-year engagement.
- Experience with policy-as-code (OPA/Gatekeeper, Azure Policy).
- Background in threat modeling (STRIDE, DREAD) and secure SDLC frameworks (OWASP SAMM, BSIMM).
- Experience working in regulated industries such as finance, healthcare, or government.
- Prior experience leading a security tooling migration or DevSecOps transformation initiative.
- Experience supporting multiple concurrent client engagements or transitioning between client accounts.
We Currently Offer The Following Benefits
- Access to private medical insurance through MetLife
- Life insurance policy via MetLife
- 30-day Christmas bonus and a monthly technology stipend
- Contribution of 8% of the employee's salary to a savings fund
- Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
- Family-friendly benefits, extended parental leave for when you need to spend critical time with new family members, and employer-paid short-term and long-term disability
- Support for individual development through certifications, continued learning, conferences, and more
Job Posted by ApplicantPro
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search