Cloudinary is looking for a Senior DevSecOps Engineer to be our eyes and ears on security end to end. You'll be embedded in the DevOps team and partner with our existing DevSecOps engineer to secure massively scalable, global production systems that power tens of thousands of websites and apps, while also tackling organizational security across identity, endpoints, SaaS, and risk. This is a hands-on role with broad ownership and real impact across R&D, Production, and the business.
Detect, protect, and respond (hands-on)
Secure our delivery pipelines & runtime
Raise the bar across the organization (beyond prod)
Influence, automate, and measure
5+ years in Security Operations/Cloud Security/Blue Team roles, with deep, hands-on experience in AWS (IAM/GuardDuty/CloudTrail/CloudWatch) and Kubernetes/containers.
Strong incident response skills across detection, investigation, containment, and recovery especially in complex cloud-native environments.
Proficiency building security automations and tools in Python or Go; experience with SOAR and API-driven workflows.
Practical expertise with SIEM/log analytics (e.g., ELK/OpenSearch, Splunk), EDR, CSPM/CNAPP, and secrets management (e.g., Vault).
Solid grasp of CI/CD security, supply-chain risks (SAST/DAST/IAST, dependency scanning, artifact signing), and IaC (Terraform) security reviews.
Networking & Linux fundamentals; proven ability to partner with DevOps/SRE/R&D and to communicate risk clearly to non-security stakeholders.
Willingness to participate in a shared on-call rotation for security incidents.