Member of Technical Staff, Security/DevSecOps
San Francisco, California, United States
Full Time Senior-level / Expert USD 190K - 205K
Envoyâs workplace platform has redefined how companies welcome visitors, improve the onsite experience, book desks and meeting rooms, manage deliveries, and access accurate and unified workplace data in 16,000 locations around the globe by designing products that solve common workplace problems.
Envoy provides a simple way to manage your complex safety, security, and compliance needs across all your workplace locationsâwherever you need to bring people together.
Rely on smart, automated solutions to common workplace problems, like freeing up unused space and eliminating repetitive tasks. Not only does this allow you to make the most efficient use of your space and resources, it frees up your teamâs time to focus on the work that matters.
With Envoyâs intuitive technology that employees actually enjoy using, you can create a great workplace experience that fosters community and togetherness by making it easy for teams to coordinate working onsite.
Unlike companies that offer disconnected workplace solutions and disparate (and often imprecise) data sources, Envoyâs platform provides accurate, comprehensive, and unified workplace data so you can make informed business decisions. Envoyâs integrated solutions pull data from multiple sources to ensure that you always have the most accurate data available.
For more information, visit Envoy.com.
Â
 This is an L3 opportunity. Successful candidates often come from senior engineering roles and are experienced in leading complex projects, mentoring peers, and making architectural contributions across teams.
About the roleEnvoyâs engineering organization is scaling rapidly in the cloud. We are looking for an experienced Cloud Security / DevSecOps Engineer to harden our AWS environments, embed security into our CI/CD pipelines, and champion secure-by-default infrastructure practices.Â
We are looking for exceptional engineers to join our growing team at Envoy. We love to drive innovation in the workplace through hack projects. If youâre looking to challenge the status quo and build the Office OS. Come join us.
This onsite position requires 4 days a week (Monday-Thursday) in our San Francisco HQ office.
You Will- Design, implement, and continuously improve security controls in AWS, including IAM policies, VPC network segmentation, Security Groups, and secure service configuration (e.g., S3, RDS, Lambda).
- Own WAF management (Cloudflare WAF) â authoring rules, tuning managed rulesets, and monitoring attacks.
- Integrate automated security guardrails into CI/CD pipelines (GitHub Actions) for IaC, container images, and serverless deployments.
- Implement and enforce InfrastructureâasâCode (IaC) security scanning using tools such as tfsec, Trivy, Checkov, or Terrascan, with gating for critical findings.
- Lead container and orchestration security for Docker and Kubernetes/EKS, including image scanning, admission controls, runtime monitoring (Falco), and benchmark enforcement (kubeâbench).
- Establish and operate secretsâmanagement best practices using tools like HashiCorp Vault, AWS Secrets Manager, or SOPS, ensuring leastâprivilege access.
- Deploy, tune, and maintain AWS security services â GuardDuty, Security Hub, Config, CloudTrail, IAM Access Analyzer â for continuous detection and compliance.
- Conduct cloud threat modeling and risk assessments (STRIDE, AWS WellâArchitected Framework) to identify gaps and prioritize mitigations.
- Automate security compliance reporting against frameworks such as CIS Benchmarks and NIST 800â53 using IaC and policyâasâcode (e.g., Open Policy Agent).
- Collaborate with infrastructure and product engineering teams to embed security early and unblock delivery velocity.
- Autonomous and highly organized, thriving in a fastâmoving environment.
- Passionate about enabling secure cloud engineering without blocking developer velocity.
- Intellectually curious, always experimenting with new cloud security tooling and best practices.
- A clear, concise communicator who can translate complex security topics for diverse stakeholders.
- Handsâon expertise securing AWS workloads, multiâaccount architectures, and VPC design.
- Deep knowledge of IAM policy design, roleâbased access control, and leastâprivilege enforcement.
- Proficiency with Terraform or CloudFormation and experience implementing IaC security scans in CI/CD.
- Demonstrated experience managing WAF solutions and mitigating webâlayer attacks (OWASP Top 10, bot mitigation).
- Experience hardening container images and Kubernetes/EKS clusters, plus familiarity with container runtime security.
- Strong scripting skills in Python, Go, or similar for automation and tooling integration.
- Experience performing cloud security risk assessments and threat modeling for new services.
- Familiarity with AWS security tooling (GuardDuty, Config, Security Hub, Macie, Access Analyzer).
- Excellent written and verbal communication skills and the ability to educate engineers on secure practices.
- Preferred certifications: AWS Certified Security â Specialty, CISSP, GIAC Cloud Security Automation (GCSA).
- A high degree of trust in your ideas and execution
- An opportunity to partner and collaborate with other talented people
- An inclusive community where you feel welcomed and cared for as a person
- The ability to make an immediate impact helping customers create a great workplace experience
- Support for your personal and professional growth
This application will only be open for two weeks! Donât miss your chanceâapply now before the deadline closes!
Compensation descriptionÂ
Envoy's compensation package includes a market-competitive salary, equity for all full-time roles, and great benefits. If you are located in the San Francisco/ Bay Area, our expected cash compensation for this role is $190K- $205K (Annually). Final offers may vary within the range provided based on experience, expertise, and other factors.Â
If you have any questions related to compensation, please contact Recruiting after you apply.
#LI-Hybrid
By applying for this position, you acknowledge that you have fully read and understand the job requirements and received the Envoy Privacy Notice for applicants, which is linked here. Completing this application requires you to provide personal data, such as your name and contact information, which is mandatory for Envoy to process your application. Envoy is an EEO Employer and does not discriminate on the basis of any characteristic protected by local, state or federal law.
Â
Tags: Automation AWS CI/CD CISSP Cloud Cloudflare Compliance DevSecOps Docker GIAC GitHub IAM Kubernetes Lambda Monitoring NIST OWASP Privacy Python Risk assessment S3 Scripting Terraform
Perks/benefits: Career development Competitive pay Equity / stock options
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.