DevSecOps Engineer

TrueML · Lenexa, Kansas

remote mid tech
Apply through theHRkey →
awsazuregitiso

Why TrueML?

TrueML is a mission-driven financial software company that aims to create better customer experiences for distressed borrowers. Consumers today want personal, digital-first experiences that align with their lifestyles, especially when it comes to managing finances. TrueML’s approach uses machine learning to engage each customer digitally and adjust strategies in real time in response to their interactions. 

The TrueML team includes inspired data scientists, financial services industry experts and customer experience fanatics building technology to serve people in a way that recognizes their unique needs and preferences as human beings and endeavoring toward ensuring nobody gets locked out of the financial system.

\n


What you will do

Position Summary

We are seeking a Sr. Security Engineer to lead the integration of security across the software

development lifecycle (SDLC). This role sits at the intersection of engineering, cloud infrastructure, and

application security, driving automation, scalability, and secure-by-default development practices.

You will design and implement security-first CI/CD pipelines, embed automated security testing, and

partner with engineering teams to ensure applications are built, deployed, and operated securely—at

scale

Key Responsibilities

Security Automation & CI/CD Integration (Core Focus)

• Embed security controls and scanners (SAST, SCA, DAST, IaC, Container Security) into CI/CD

pipelines

(GitHub Actions, Jenkins, GitLab CI, Azure DevOps)

• Design and maintain automated security workflows across build, test, and deploy stages

• Implement security gates, policy enforcement, and compliance checks within pipelines

Cloud Security (AWS Focus)

• Secure cloud-native architectures across AWS (IAM, VPC, ECS/EKS, Lambda, S3, API Gateway)

• Integrate and operationalize CNAPP/CSPM tools (e.g., Wiz, Prisma Cloud)

• Enforce least privilege access, secrets management, and runtime protections

Own Cloud Security:  Define and maintain security policies for our AWS environment, specifically focusing on containerized workloads (EKS/ECS) and serverless architectures (Lambda).   Automate Compliance: Move beyond manual checks by building real-time monitoring and automated remediation for AWS resources, ensuring we stay "audit-ready" for frameworks like PCI and ISO 27001.   Lead Threat Modeling: Perform deep-dive threat modeling exercises on applications and designs, turning theoretical risks into actionable engineering plans.   Innovate with AI: Stay at the forefront of the industry by developing security standards for Generative AI. You’ll leverage AI-powered tools to explore our attack surface while defending against AI-driven threats.   Guard the Infrastructure: Secure our Infrastructure as Code (IaC) templates (Terraform/CloudFormation) and manage cloud primitives like IAM, KMS, and WAF to ensure a "least privilege" environment.    

 


What you bring


\n$122,090 - $160,000 a monthFor U.S.-based hires, the overall base salary framework for this role currently spans $122,090- $160,000. The applicable base salary range for any individual hire depends on the geographic labor market associated with the employee’s primary work location along with other factors such as relevant skills, experience, and qualifications.

Geographic labor markets are divided into "tiers" based upon a number of factors, including cost of living. Below, you'll find a few example cities representative of each tiers: We encourage you to speak to your recruiter to learn more about our compensation philosophy as well as discuss our benefits, total rewards, and opportunities for growth.\n

What We Offer (Perks & Benefits)

Remote Work, Travel Expectations & Physical Requirements:

This role supports a global, cross-functional business and operates primarily in a Remote-First environment. However, flexibility outside of standard business hours and occasional local or international travel may be necessary for global operations support, company meetings, training, offsites, and collaborative projects.

This position primarily involves computer-based work, requiring extended periods at a computer, participation in virtual meetings, and use of standard office technology. We will consider reasonable accommodations to enable individuals to perform the essential functions of the role.

Maintaining a reliable internet connection and a professional work environment is expected. The ability to protect confidential company, employee, customer, and business information while working outside of a company office is also required.

Personally Identifying Information

We collect personal information for employment purposes. We do not sell personal information. Most of the information we have is provided to us by you and/or collected as part of the employment process. For more details on how we use, share, and delete personal information see our Privacy Policy.

 

Dedication to Diversity & Inclusion

We are  an equal opportunity employer. We promote, value, and thrive with a diverse and inclusive team. Different perspectives contribute to better solutions and this makes us stronger every day. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, or other protected characteristics.



Please mention the word **HONOR** and tag RMTg1LjYxLjE1NS40Mg== when applying to show you read the job post completely (#RMTg1LjYxLjE1NS40Mg==). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.

Posted 16 Jun 2026 · ref 125995