DevSecOps Engineer

Overflow
Hybrid

About The Position

Overflow is seeking its first DevSecOps Engineer to establish the new Platform/DevOps team. This role will focus on Site Reliability Engineering (SRE) and DevOps, ensuring the company's systems are highly available, scalable, and efficient, with a strong emphasis on security. The engineer will manage the containerized AWS environment, automate deployments, build observability foundations, and play a key role in maintaining SOC 2 compliance and preparing for PCI Level 1 certification.

Requirements

  • 5+ years in DevOps, Site Reliability, or Cloud Platform roles
  • Deep, hands-on experience with Docker and AWS ECS Fargate
  • Extensive experience building and maintaining robust deployment pipelines using GitHub Actions
  • Practical experience maintaining SOC 2 technical controls
  • Strong understanding of the architectural requirements for PCI-DSS (ideally Level 1) compliance

Nice To Haves

  • Previous experience as the first DevOps or SRE hire at a high-growth startup, comfortable taking ownership of the 0-to-1 platform build.
  • Experience securing financial ledger systems, payment gateways, or blockchain/crypto infrastructure.
  • Experience participating in bug bounties, conducting internal threat modeling, or a strong understanding of the OWASP Top 10.

Responsibilities

  • Secure, manage, and scale Overflow’s cloud environment, implementing least-privilege IAM policies, network security (VPCs, WAFs, Security Groups), and robust secret management.
  • Refine existing infrastructure provisioning using Infrastructure as Code (IaC) tools, ensuring security best practices.
  • Deploy and manage comprehensive observability, logging, and alerting frameworks to detect performance bottlenecks, anomalous behavior, or potential security incidents.
  • Own and optimize continuous integration and deployment (CI/CD) pipelines.
  • Integrate automated security testing (SAST, DAST, dependency scanning, container scanning) into the developer workflow.
  • Act as a security champion, partnering with software engineers to perform threat modeling, architectural reviews, and secure coding training.
  • Action on compliance requirements (SOC 2, PCI-DSS, and data privacy regulations).
  • Partner with legal and operations teams to streamline security audits, penetration testing, and vendor risk assessments.
  • Ensure that PII and sensitive financial data are properly encrypted at rest and in transit across all databases and caching layers.

Benefits

  • Competitive base salary with equity eligibility
  • Medical, dental, and vision coverage for employees and dependents
  • Generous paid time off and company holidays
  • Paid parental leave
  • 401(k) retirement plan
  • Dedicated mental health and therapy stipend to support personal well-being
  • Team retreats and intentional in-person gatherings throughout the year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service