Senior DevSecOps Engineer
Pactfi
| Company | Pactfi |
| Category | Engineering |
| Location | New York |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Senior |
| Salary | USD 165k–225k |
| Posted | 14 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
About PactFi
Private asset markets (PE, Private Credit, VC, Real Estate) have 10x to 9.8T in AUM over the past decade and are projected to grow to $17T in the next five years. However, digital infrastructure has not kept pace, with most of the market operating predominantly in error-prone, internal-only software solutions.
PactFi provides secure, end-to-end, operational infrastructure for managing complex private credit transactions. Our web-based application brings together all parties involved in such a transaction to more efficiently allocate capital, complete KYC, share documents, manage funds flow, and more. The platform is secured to a bank-grade standard, and we have received our SOC 2 Type 2 attestation.
PactFi was developed in close partnership with two of the industry's largest players, both of whom represent the top 3 players in the private credit space by both size (AUM) and deal activity.
Overview
We're looking for a Senior DevSecOps Engineer to work closely with our Lead DevSecOps Engineer to improve the security, reliability, infrastructure, deployment, and operational maturity of our platform. This is a hands-on individual contributor role for someone who enjoys building, automating, securing, and improving production systems — not managing a team.
You'll strengthen our CI/CD workflows, AWS infrastructure, observability, SOC 2 readiness, business continuity, disaster recovery, and 24/7 on-call operations. The ideal candidate is experienced, practical, and collaborative — comfortable owning technical workstreams and helping engineering teams ship safely and efficiently.
What You'll Do
Infrastructure & Cloud Engineering
- Design, build, and improve secure, scalable AWS infrastructure using infrastructure-as-code (Terraform, Pulumi-Python).
- Improve cloud networking, IAM, secrets management, environment isolation, and secure configuration.
- Standardize provisioning, access control, auditability, and change management.
- Troubleshoot infrastructure issues and drive long-term fixes that reduce operational toil.
CI/CD & Developer Experience
- Build, maintain, and improve secure CI/CD pipelines for application, infrastructure, and platform deployments.
- Support container-based build and deployment workflows, including rolling updates and rollback strategies.
- Support Environment as a Service for the engineering and QA teams
- Reduce deployment friction while maintaining strong security and compliance controls.
Security, Compliance & SOC 2 Type 2
- Embed security controls into infrastructure, CI/CD pipelines, and cloud operations.
- Support SOC 2 Type 2 readiness through control implementation, evidence collection, access reviews, and audit support.
- Manage secrets, IAM, least-privilege access, and vulnerability management across containers, dependencies, and cloud services.
- Ensure sensitive data is protected across logs, pipelines, monitoring systems, backups, and AI-assisted workflows.
- Contribute to secure usage patterns for AI/ML tools and services, including data handling, vendor risk, access controls, and model boundary considerations.
Observability, Reliability & On-Call
- Build and improve observability across logs, metrics, dashboards, and alerts; maintain centralized logging pipelines.
- Define and maintain SLOs, SLIs, alerting standards, and escalation paths.
- Participate in a 24/7 production on-call rotation; support incident response, root-cause analysis, and postmortems.
- Create and maintain runbooks, playbooks, and operational documentation.
Business Continuity & Disaster Recovery
- Design, document, and improve BC/DR plans; support RTO/RPO planning for critical systems.
- Implement and test backup, restore, replication, failover, and recovery procedures.
- Identify single points of failure and drive remediation across infrastructure, data stores, and operational processes.
What We're Looking For
Experience & Technical Skills
-