Start here! 2min video message from our Co-Founder & CEO, Cameron Brain:
https://www.loom.com/share/4149d7d188a84fab9d44694ec0c49a10
Hi! We’re EveryoneSocial, the #1 employee advocacy platform in the world. We’re used by Amazon, NVIDIA, Meta and others to activate their employees as marketers, to share company news and updates on social media. Word of mouth for the 21st century.
EveryoneSocial is a startup, we’re profitable, and shipping high-quality, innovative products is our #1 priority. If you’re interested in joining a small, experienced team working on software used by hundreds of thousands of people around the world we'd love to talk!
JOB DESCRIPTION
We’re looking for a pragmatic and hands-on DevSecOps Engineer to help strengthen, scale, and modernize our security and operational infrastructure.
This is a hybrid role that combines Security Operations/Engineering and DevOps responsibilities:
- You’ll work closely with engineering to manage cloud and application security risks, drive remediation efforts, and improve overall security hygiene across our stack
- You’ll also help maintain and evolve critical DevOps systems, such as CI/CD pipelines (Jenkins), infrastructure as code (Terraform), and cloud operations (AWS)
We run quarterly third-party red team testing and seek someone to triage results, manage security tooling, and proactively harden our systems between assessments. You’ll also help ensure our build and deployment processes are reliable, secure, and scalable.
This role also includes responsibility for internal corporate security tooling and endpoint security controls.
KEY RESPONSIBILITIES
Security Operations:
- Own and operate our core security tooling (e.g., Orca Security, AWS GuardDuty, Macie, Coralogix SIEM)
- Triage and coordinate remediation of findings from quarterly red team testing
- Collaborate with engineering to reproduce issues, prioritize fixes, and validate remediations
- Monitor for cloud and app vulnerabilities using internal and third-party tools
- Manage AWS security best practices (IAM, network config, access controls, audit logging)
- Define and implement secure-by-default patterns for infrastructure and product code
- Manage corporate security tooling and processes, including: identity & access management (Okta), MDM and endpoint protection (Jamf Pro, Jamf Protect), log management and security monitoring (Coralogix)
- Build lightweight security playbooks and processes (e.g., secret management, patching, internal alerting)
- Stay up to date with evolving threats, vulnerabilities, and security frameworks
DevOps:
- Maintain and improve CI/CD pipelines (Jenkins) to ensure fast, reliable, and secure deployments
- Support cloud infrastructure operations in AWS, including deployments, scaling, and configuration management
- Write and maintain infrastructure-as-code scripts (primarily Terraform)
- Monitor and manage system reliability, availability, and performance
- Build automation scripts to improve operational efficiency
QUALIFICATIONS
- ≥3 years of experience in security engineering, DevOps, and/or cloud infrastructure roles with a strong security focus
- Experience in a startup environment (< 50 employees) is a must
- Strong knowledge of AWS security fundamentals (IAM, least privilege, network boundaries, audit logging, etc.)
- Hands-on experience with security tooling such as Orca, Wiz, Snyk, or similar
- Hands-on experience managing and improving CI/CD pipelines (e.g., Jenkins, GitHub Actions).
- Comfortable with scripting/automation (e.g., Python, Bash, Terraform)
- Understanding of common application and cloud security risks (e.g., auth flaws, secrets exposure, insecure APIs)
- Strong collaboration and communication skills—you help others secure their work without slowing them down
Bonus points for:
- Experience reviewing pen test results or working with red team consultants
- Familiarity with security and compliance frameworks, including: AWS Foundational Security Best Practices, NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Critical Security Controls, SOC 2 and ISO 27001
- Exposure to vulnerability management programs or incident response
- Experience managing identity, device, and endpoint tooling in a Mac-first environment
- Exposure to serverless architectures (Lambda) and event-driven designs
WHAT WE OFFER
- Competitive salary
- Stock options
- Medical, dental, vision coverage contribution
- Flexible time off
- 401K with company matching