DevSecOps Engineer (Cloud Security and Compliance)
Come Back Agency supports US software and technology companies by running their hiring process. We work with delivery and leadership teams to define roles, screen candidates, and manage interviews. Successful candidates are hired directly by the company and become part of its team.
This position is with a US-based software company providing custom development and AI implementation for North American clients. The team builds and maintains production software, including AI-enabled systems, and works in long-term client engagements. Team members operate as part of an internal, distributed team and collaborate directly with client stakeholders.
About the role
We are looking for an experienced DevSecOps / Security & Compliance Consultant for a 3–4 month contract.
The company already has two DevOps engineers responsible for the existing infrastructure. Your role will be to independently assess the company’s current security and compliance posture, create a practical SOC 2 and/or ISO 27001 readiness roadmap, coordinate the implementation of required controls, and prepare the company for an external audit.
What you will do:
Conduct a security and compliance gap assessment
Define a realistic SOC 2 and/or ISO 27001 readiness roadmap
Map requirements to technical and organizational controls
Configure and manage Vanta, Drata, Secureframe, or a similar compliance platform
Define the required evidence and coordinate its collection
Work with the existing DevOps engineers to implement AWS, IAM, logging, monitoring, backup, vulnerability management, and secure SDLC controls
Prepare or improve security policies, risk registers, incident response procedures, access reviews, and business continuity documentation
Support client security questionnaires and auditor requests
Conduct a readiness review or mock audit
Document remaining gaps and provide a clear handover plan
Requirements:
Proven hands-on ownership of at least one SOC 2 or ISO 27001 readiness and audit cycle
Experience implementing controls, collecting evidence, and working directly with auditors or external assessors
Strong understanding of AWS infrastructure, IAM, logging, security, CI/CD, and vulnerability management
Experience with Vanta, Drata, Secureframe, or similar compliance automation tools
Ability to independently manage the compliance workstream and coordinate technical implementation with the internal DevOps team
Strong documentation and stakeholder communication skills
English at B2 level or higher
Apply with your resume and a short note outlining your relevant experience. You can also submit it through our website at comeback.ua. Selected candidates will be contacted by Come Back Agency.