Senior DevSecOps Engineer
Campminder
| Company | Campminder |
| Category | Engineering |
| Location | Boulder |
| Remote | Remote |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 10 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Ideal start timeline: August 2026
Role status: Exempt
Compensation: Our target hiring range is $165,000-$196,000 plus participation in our Annual Bonus Program with eligibility for $12,000 bonus. Actual compensation will be commensurate with experience and skills.
Campminder’s Flexible Working Location: Our employees have the option to work 100% remotely within the United States or their choice of days at home and at our office in Boulder, Colorado. We host a variety of all-company hybrid meetings and social events. We require anybody working remotely to have a very reliable, high-speed internet connection.
We know the best people can choose to work anywhere.
Here’s a few reasons why 100+ of them choose Campminder:
With 20+ years experience of serving the industry through its digital transformation, we’re stable, profitable, and have developed a loyal customer base (that continues to grow).
We build software for summer camps, an industry that enables meaningful experiences for kids.
We work on interesting, ambitious projects that create real value for our clients.
We know our team members feel their work has an impact on the organization’s purpose.
At the same time, we are genuinely committed to work/life balance. Our team members feel they have the flexibility to take time off when needed and feel supported in making use of flexible working arrangements.
We invest in emerging technology and cutting-edge leadership and are proud to take an "AI-Enabled" approach in our solutions.
We’ve been listed on Outside Magazine’s 50 Best Places to Work for 8 consecutive years for our values-led culture and employee experience.
This role’s mission & overview: Camps trust Campminder to keep their data safe, and that trust is what lets them focus on running a great summer. You'll own how we protect that data end to end: architecting and hardening our security infrastructure, carrying our PCI and SOC2 programs through every audit, and setting the roadmap that keeps us ahead of real threats. You'll be the person the engineering org comes to on security and the one who defines what good looks like at Campminder.
As a Senior DevSecOps Engineer on our Engineering team, you will:
Partner with the DevOps team to Integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and drive remediation before code reaches production
Configure, tune, and harden WAF rules across our web applications
Partner with platform and IT to implement and maintain EDR, DLP, vulnerability scanning and remediation, and SIEM/XDR tooling across servers and endpoints
Manage secrets and credentials in build pipelines, including vault-based storage, rotation, and least-privilege service accounts
Execute PCI, SOC2, and ISO technical controls: SAQ completion, quarterly ASV scans, and disaster recovery implementation
Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration
Coordinate pen testing engagements and drive remediation against SLA timelines
Run security awareness training programs (KnowBe4, Security Journey) and maintain AI usage oversight, including approved tooling, code-gen governance, and supply-chain monitoring
We think a successful candidate will bring:
Experienced in security engineering or DevSecOps, with hands-on ownership of both pipeline-level and infrastructure-level security
Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud-native identity controls like Azure conditional access
Comfort embedding security directly into CI/CD workflows through security and dependency scanning tooling, secrets management, and policy-as-code
A track record of hardening containerized and cloud-native environments, including Kubernetes and image scanning
Experience executing PCI, SOC2 or similar compliance technical controls (scans, SAQs, evidence prep); program ownership isn't required, but you
991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →