Overflow is a Series C, growth-stage technology company on a bold mission to inspire the world to give. As the first DevSecOps Engineer, you will focus on Site Reliability Engineering and DevOps, ensuring systems are highly available and secure while maintaining compliance with SOC 2 and PCI Level 1 requirements.
Responsibilities:
- Secure, manage, and scale Overflow’s cloud environment, implementing least-privilege IAM policies, network security (VPCs, WAFs, Security Groups), and robust secret management
- Refine existing infrastructure provisioning using Infrastructure as Code (IaC) tools, ensuring security best practices
- Deploy and manage comprehensive observability, logging, and alerting frameworks to detect performance bottlenecks, anomalous behavior, or potential security incidents
- Own and optimize our continuous integration and deployment (CI/CD) pipelines
- "Shift Left" by integrating automated security testing (SAST, DAST, dependency scanning, container scanning) directly into the developer workflow
- Act as a security champion, partnering with software engineers to perform threat modeling, architectural reviews, and secure coding training
- Action on compliance requirements (SOC 2, PCI-DSS, and data privacy regulations)
- Partner with our legal and operations teams to streamline security audits, penetration testing, and vendor risk assessments
- Ensure that PII and sensitive financial data are properly encrypted at rest and in transit across all databases and caching layers
Requirements:
- Core Experience: 5+ years in DevOps, Site Reliability, or Cloud Platform roles
- Cloud Expertise: Deep, hands-on experience with Docker and AWS ECS Fargate
- CI/CD Automation: Extensive experience building and maintaining robust deployment pipelines using GitHub Actions
- Security & Compliance: Practical experience maintaining SOC 2 technical controls and a strong understanding of the architectural requirements for PCI-DSS (ideally Level 1) compliance
- Startup DNA / Founding Experience: Previous experience as the first DevOps or SRE hire at a high-growth startup, comfortable taking ownership of the 0-to-1 platform build
- Fintech & Web3 Context: While not a day-one requirement, experience securing financial ledger systems, payment gateways, or blockchain/crypto infrastructure will be increasingly valuable as our platform evolves
- Offensive Security Knowledge: Experience participating in bug bounties, conducting internal threat modeling, or a strong understanding of the OWASP Top 10