latchhire

Senior DevSecOps Engineer

Panopto · Remote - US
Remote · US$150k+ senior devsecops
Apply on Panopto →
Company Overview: At Panopto, we are the most customer-centric learning technology company in the world. As the leader in visual and audio-based learning , we empower organizations to share knowledge effortlessly in a capture and post-capture world. We don’t just build software; we obsess over our users’ goals to deliver solutions that truly matter. Our mission is simple: to attract the brightest talent, people like you, to Elevate the Craft and do the most impactful work of your career. To enhance our team we are seeking an experienced Senior DevSecOps Engineer who thrives at the intersection of engineering and security. In this role, you’ll own the security posture of a platform used by millions, partnering closely with developers to build secure systems from the ground up. Position Summary: In this role, you will have the opportunity to do meaningful work in your career, elevating your craft while contributing to a team that values lifelong learning. As a Senior DevSecOps Engineer , you are a critical guardian of the platform that powers video knowledge management for global universities and businesses. You will not operate in an isolated silo or an "ivory tower." Instead, you will elevate the craft of security by embedding automated security controls directly into the development lifecycle and CI/CD pipelines. You will bridge the gap between compliance standards (ISO 27001, SOC 2, TX-RAMP) and high-velocity software engineering, ensuring our security posture is pragmatic, scalable, and built on Clarity over Complexity . Driving an AI-first mindset, you will leverage modern automation tools and AI workflows to eliminate manual security tasks, accelerate threat modeling, and simplify system architectures. You'll also have opportunities to contribute to other initiatives that directly advance our core values and support you in elevating your craft. How You’ll Contribute: In this role, you will have the opportunity to… Design Secure Systems: Lead hands-on threat modeling assessments on new features across many different AWS services, ensuring security is baked into application design from the first line of code. Drive Proactive Defense & CI/CD Security: Build, maintain, and enforce automated static (SAST), dynamic (DAST), and dependency (SCA) security testing frameworks within our AWS delivery pipelines to catch vulnerabilities before code reaches production. Secure Cloud & Container Infrastructure: Design and manage security guardrails across AWS environments, Kubernetes clusters, Docker containers, and CloudFormation/CDK/Terraform Infrastructure-as-Code (IaC) deployments. Own Policy & Automated Governance: Lead the technical implementation of policy-as-code and compliance guardrails (ISO 27001, SOC 2, TX-RAMP), translating complex regulatory requirements into simple, actionable engineering standards. Leverage AI Security Tools: Evaluate and integrate AI-assisted tools to accelerate code reviews, log analysis, and vulnerability triage, while establishing secure usage guidelines for developer AI tools. Lead Incident Response: Act with ownership during security events by conducting investigations and root-cause analysis, using collective wisdom to prevent future incidents. Mentor Engineering Teams: Coach developers on secure coding practices, threat identification, and vulnerability remediation through practical mentorship and reusable design patterns. What Success Looks Like: Within 6 Months: Execute threat modeling assessments for active feature releases. Complete an audit of our current CI/CD pipelines, assume technical ownership of cloud security standards, and establish working relationships with lead developers. Within 1 Year: Automate at least one major vulnerability triage workflow in the build pipeline. Your Legacy: Establish fully automated policy-as-code guardrails across AWS and Kubernetes environments, demonstrating a measurable reduction in security debt during architectural reviews. Values in Action Customer First, Always : You proactively surface friction points in the customer experience before they are escalated — and propose solutions, not just reports. Thrive Together : You share work-in-progress for early feedback, knowing that challenge improves the outcome. You separate critiques of ideas from critiques of people. Elevate the Craft : You hold the bar high on your own work and invest in developing those around you. You treat every project as an opportunity to learn something new. Act with Ownership : You define success by outcomes, not activity. You flag problems early and bring a proposed path forward, not just the problem. Clarity Over Complexity : You default to the simpler solution. Your written communication — internal or external — is direct, specific, and free of filler. How We Thrive: You’ll work with a team of talented engineers with a variety of areas of expertise, from devops to design, architecture to accessibility. The team’s experience level ranges from seasoned developers with well over a decade in industry to junior developers and contractors who are growing their roles and impact. The Foundation for Success: Cloud & Container Security Mastery: Proven track record securing Multi-Account AWS environments and Infrastructure-as-Code deployments (IAM/Identity Center, Network Security, Encryption, Docker/ECS/Fargate, Terraform, CloudFormation/CDK, Security Hub, GuardDuty). Pipeline Automation & Code Proficiency: Strong hands-on experience integrating security tools into CI/CD pipelines and writing automation scripts using Python or Bash. Practical AI Application: Demonstrated experience using AI tools (such as automated code reviewers, LLM tools, or AI-driven security scanners). In addition, experience securing AI systems, AI supply chinese, and AI-assisted workflows. Threat Modeling Execution: Proven ability to evaluate application architectures for security flaws and guide teams on mitigating OWASP Top 10 vulnerabilities. Pragmatic Compliance: Understanding that security must support business velocity, with experience turning compliance requirements into automated checks without slowing down software releases. Experience: 7+ years in security engineering, DevSecOps, software development, or cloud infrastructure security. What Sets You Apart: Security or cloud certifications such as CISSP, AWS Certified Security - Specialty, or Certified Kubernetes Security Specialist (CKS). Experience securing video streaming architectures or high-scale backend services. Experience implementing policy-as-code frameworks in regulated SaaS environments. Join Us Join Panopto and play a key role in shaping the security foundation of a platform used by millions. If you love threat modeling, automating defenses, guiding engineering teams, and turning compliance standards into practical, scalable security practices, you’ll feel right at home here.
Posted 2026-03-12