Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Senior DevSecOps Engineer

Campminder
CompanyCampminder
CategoryEngineering
LocationBoulder
RemoteRemote
EmploymentNot stated
LevelSenior
SalaryNot stated by the employer
Posted10 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Ideal start timeline: August 2026 Role status: Exempt Compensation: Our target hiring range is $165,000-$196,000 plus participation in our Annual Bonus Program with eligibility for $12,000 bonus. Actual compensation will be commensurate with experience and skills. Campminder’s Flexible Working Location: Our employees have the option to work 100% remotely within the United States or their choice of days at home and at our office in Boulder, Colorado. We host a variety of all-company hybrid meetings and social events. We require anybody working remotely to have a very reliable, high-speed internet connection. We know the best people can choose to work anywhere. Here’s a few reasons why 100+ of them choose Campminder: With 20+ years experience of serving the industry through its digital transformation, we’re stable, profitable, and have developed a loyal customer base (that continues to grow). We build software for summer camps, an industry that enables meaningful experiences for kids. We work on interesting, ambitious projects that create real value for our clients. We know our team members feel their work has an impact on the organization’s purpose. At the same time, we are genuinely committed to work/life balance. Our team members feel they have the flexibility to take time off when needed and feel supported in making use of flexible working arrangements. We invest in emerging technology and cutting-edge leadership and are proud to take an "AI-Enabled" approach in our solutions. We’ve been listed on Outside Magazine’s 50 Best Places to Work for 8 consecutive years for our values-led culture and employee experience. This role’s mission & overview: Camps trust Campminder to keep their data safe, and that trust is what lets them focus on running a great summer. You'll own how we protect that data end to end: architecting and hardening our security infrastructure, carrying our PCI and SOC2 programs through every audit, and setting the roadmap that keeps us ahead of real threats. You'll be the person the engineering org comes to on security and the one who defines what good looks like at Campminder. As a Senior DevSecOps Engineer on our Engineering team, you will: Partner with the DevOps team to Integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and drive remediation before code reaches production Configure, tune, and harden WAF rules across our web applications Partner with platform and IT to implement and maintain EDR, DLP, vulnerability scanning and remediation, and SIEM/XDR tooling across servers and endpoints Manage secrets and credentials in build pipelines, including vault-based storage, rotation, and least-privilege service accounts Execute PCI, SOC2, and ISO technical controls: SAQ completion, quarterly ASV scans, and disaster recovery implementation Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration Coordinate pen testing engagements and drive remediation against SLA timelines Run security awareness training programs (KnowBe4, Security Journey) and maintain AI usage oversight, including approved tooling, code-gen governance, and supply-chain monitoring We think a successful candidate will bring: Experienced in security engineering or DevSecOps, with hands-on ownership of both pipeline-level and infrastructure-level security Experience configuring IAM and SSO platforms (Okta, Auth0) alongside cloud-native identity controls like Azure conditional access Comfort embedding security directly into CI/CD workflows through security and dependency scanning tooling, secrets management, and policy-as-code A track record of hardening containerized and cloud-native environments, including Kubernetes and image scanning Experience executing PCI, SOC2 or similar compliance technical controls (scans, SAQs, evidence prep); program ownership isn't required, but you
HOUSE AD991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →