Auf einen Blick
- Aufgaben: Entwickle Sicherheitslösungen für unsere Software-Entwicklung und Cloud-Operationen.
- Unternehmen: Trase Systems, ein innovatives Unternehmen im Bereich KI mit einem dynamischen Team.
- Vorteile: Attraktives Gehalt, umfassende Gesundheitsversorgung, unbegrenzter Urlaub und Weiterbildungsmöglichkeiten.
- Weitere Informationen: Mentoring-Möglichkeiten und Karrierewachstum in einem spannenden Umfeld.
- Warum dieser Job: Gestalte die Zukunft der KI-Sicherheit in einem schnell wachsenden Startup.
- Qualifikationen: Mindestens 10 Jahre Erfahrung in Sicherheitsengineering und DevSecOps.
About Us
Co-founded in 2023 by Joe Laws and Grant Verstandig, Trase Systems is AI Uncomplicated.
Trase empowers enterprise leaders to harness the full potential of AI without the associated complexity and risks.
We are an end‑to‑end solution for deploying, managing, and optimizing AI in the enterprise.
Our platform specializes in bridging the “last mile” of AI adoption, unlocking AI’s full potential while driving efficiency and significant cost savings.
Trase is at the forefront of AI Agent innovation, topping the Hugging Face GAIA Leaderboard for Generalized AI Assistants, ahead of industry giants such as Google, Meta, Microsoft, and Open AI.
We are leveraging our cutting‑edge technologies to develop mission‑critical agentic applications in complex industries such as Healthcare, Oil & Gas, and National Security.
About the Role
As the Staff Dev Sec Ops Engineer, you will be the technical owner of how security is built into Trase’s software development lifecycle and cloud operations.
You will integrate automated security testing, continuous vulnerability management, and secure coding practices directly into our existing CI/CD pipelines, where the cost of catching misconfigurations and vulnerabilities is lowest and the blast radius is smallest.
You will own the implementation of Trase’s dedicated security architecture, delivering shift‑left tooling (SAST, DAST, SCA, secrets scanning, and Ia C scanning) alongside production cloud security services and resources, all deployed through infrastructure‑as‑code.
By standardizing and operating these secure pipelines, you will empower Trase’s software engineers to focus on high‑velocity delivery while ensuring that we maintain the controls and capabilities required by our customers and regulators.
Why This Role Exists
Trase ships mission‑critical agentic applications into Healthcare, Oil & Gas, and National Security at the pace of a startup, under the scrutiny of a defense contractor.
Our engineering velocity and the speed at which we deploy highly‑regulated workloads is one of our core advantages.
To preserve that velocity while maintaining customer trust and assurance, we must ensure that security is seamlessly and inextricably linked to delivery — and never bolted on after the fact.
This role exists to build upon our foundation and mature the ways in which we’ve embedded security throughout our pipelines and operations.
It is a continued investment in our CI/CD security tooling, production cloud security architecture, detection and response capabilities, and the Ia C patterns that make secure‑by‑default the path of least resistance for every Trase engineer.
Responsibilities
- Shift‑Left Security in CI/CD
- Design, implement, and operate the shift‑left security toolchain across Trase’s CI/CD pipelines, which include but are not limited to SAST, DAST, SCA, secrets scanning, container image scanning, and Ia C scanning.
- Define how findings are triaged, routed, and remediated; partner with engineering teams to keep developer experience high and friction low.
- Establish and enforce policy‑as‑code and pre‑merge security gates calibrated to risk.
- Cloud Security Architecture
- Design and deploy Trase’s production cloud security architecture, with a primary focus on Google Cloud Platform (GCP) and a clear path to multi‑cloud as the business requires.
- Implement foundational controls including network segmentation, workload identity, secrets management, encryption (in transit and at rest), and least‑privilege IAM using both cloud‑native services and third‑party applications or platforms.
- Stand up and operate cloud security posture management (CSPM) and cloud workload protection capabilities.
- Infrastructure‑as‑Code & Platform Security
- Build, codify, and maintain the secure‑by‑default infrastructure modules in Terraform, consumed by every Trase engineer.
- Embed security controls directly into platform abstractions so that the secure path is the default path.
- Drive secure baselines for Kubernetes, container runtimes, and serverless workloads.
- Detection, Monitoring & SIEM
- Operate and fine‑tune Trase’s SIEM and security telemetry pipeline, designing log sources, detections, and alerting workflows from the ground up.
- Define detection‑as‑code practices and tune detections to balance signal and noise.
- Build dashboards and reporting that give the security team and leadership real‑time visibility into the live posture of the environment.
- Incident Response
- Enhance and lead aspects of Trase’s technical security incident response capability, including runbooks, on‑call rotation design, tabletop exercises, and post‑incident reviews.
- Serve as a senior responder during security events, coordinating across stakeholder groups and the broader enterprise.
- Vulnerability & Threat Management
- Operate the end‑to‑end vulnerability management lifecycle across application, container, and cloud surface area.
- Facilitate remediation SLAs, partner with engineering to drive them, and report on progress to leadership.
- Cross‑Functional Partnership
- Partner closely with Engineering and the broader Security and Compliance team to translate framework requirements (e. g., SOC 2, HIPAA, ISO 27001, Fed RAMP, NIST 800‑53) into defensible, robust controls.
- Embed with Product and Engineering teams to ensure security is an integral part of how Trase builds, by design.
- Mentorship & Engineering Leadership
- Mentor junior Security and Compliance engineers and members of the Engineering team on secure coding, threat modeling, and cloud security best practices.
- Establish and propagate the patterns, runbooks, and reusable building blocks that allow Trase’s security capabilities to scale with the company.
Requirements
- 10+ years of experience in security engineering, Dev Sec Ops, cloud security, or platform security roles, including significant time as a senior individual contributor.
- Deep, hands‑on experience securing modern CI/CD pipelines, including production deployment of SAST, DAST, SCA, secrets, container, and Ia C scanning.
- Strong cloud security expertise, with primary depth in Google Cloud Platform—or proven multi‑cloud expertise and the ability to operate authoritatively in GCP.
- Expert‑level Terraform skills and a track record of building secure‑by‑default Ia C modules consumed by other engineers.
- Demonstrated experience standing up and operating a SIEM end‑to‑end—from log source design through detection engineering and alert tuning.
- Hands‑on incident response leadership, including runbook authorship, on‑call design, and serving as a senior responder during real incidents.
- Practical experience operating in environments governed by SOC 2, HIPAA, and ISO 27001, with a clear understanding of how engineering controls map to framework requirements.
- Strong programming or scripting skills (Python, Go, or similar) sufficient to build automation, integrations, and tooling—not just to configure off‑the‑shelf products.
- Excellent partnership skills and a developer‑empathetic mindset; track record of making security the path of least resistance rather than a bottleneck.
- Strong affinity and practical skill for working with LLMs and AI agents as part of your own workflow—clear judgment on when and how to deploy them to move quickly, orchestrate work, and ship with confidence.
- US Citizen and eligible for US security clearance
- Nice to Have
- Hands‑on experience implementing security architectures or controls for Fed RAMP (Moderate or High), Do D RMF, HITRUST, or other heavily regulated frameworks.
- Active US security clearance (Secret, TS, or TS/SCI).
- Deep Kubernetes and container security expertise (admission control, runtime security, software supply chain security).
- Experience securing AI/ML workloads, including model supply chain integrity, prompt injection defenses, and agent execution sandboxing.
- Industry certifications such as Google Professional Cloud Security Engineer, AWS Security Specialty, OSCP, GIAC (GCSA, GCIH, GCIA), or CKS.
- Open source contributions to security tooling, detection content, or Ia C modules.
- Salary Range
: $170,000-245,000. This represents the typical salary range for this position based on experience, skills, and other factors.
Our Trase Benefits
- For full‑time roles only
- Career track opportunity with potential for rapid advancement with strong performance as the firm grows
- 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.
- Paid maternity and paternity for 14 weeks at employees’ normal pay.
- Unlimited PTO, with management approval.
- Opportunities for professional development and continued learning.
- Optional 401K, FSA, and equity incentives available.
- Mental health benefits are available through Tara Mind.
- We’re an
- Equal
- Opportunity
Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
Applicant Data Disclosure
Bysubmitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third‑party service providers to facilitate its recruitment and hiring processes.
These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”).
Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:
- Managing and administering your application throughout the hiring process;
- Verifying the accuracy and authenticity of application materials, including by cross‑referencing information you provide against publicly available sources and proprietary databases;
- Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.
Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration.
If you have questions about the status of your application or the evaluation process, please contact talent@redcellpartners. com.
Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law.
Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.
For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.
#J-18808-Ljbffr
Staff DevSecOps Engineer Arbeitgeber: Trase
Trase Systems ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern die Möglichkeit bietet, in einem dynamischen und innovativen Umfeld zu arbeiten, das sich an der Spitze der KI-Technologie befindet. Mit umfassenden Gesundheitsleistungen, unbegrenztem Urlaub und klaren Karriereentwicklungsmöglichkeiten fördert Trase eine Kultur des kontinuierlichen Lernens und der Zusammenarbeit. Die Mitarbeiter profitieren von der schnellen Wachstumsdynamik eines Start-ups, während sie gleichzeitig an mission-kritischen Projekten in regulierten Branchen wie Gesundheitswesen und nationaler Sicherheit arbeiten.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Staff DevSecOps Engineer erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Trase kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Trase zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Trase.
Wir glauben, dass du diese Fähigkeiten brauchst, um Staff DevSecOps Engineer mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Trase vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Trase könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Trase sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Trase auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!