Senior DevSecOps Engineer
Panopto·6 months ago
Company Overview:
At Panopto, we are the most customer-centric learning technology company in the world. As the leader in visual and audio-based learning, we empower organizations to share knowledge effortlessly in a capture and post-capture world. We don’t just build software; we obsess over our users’ goals to deliver solutions that truly matter. Our mission is simple: to attract the brightest talent, people like you, to Elevate the Craft and do the most impactful work of your career.
To enhance our team we are seeking an experienced Senior DevSecOps Engineer who thrives at the intersection of engineering and security. In this role, you’ll own the security posture of a platform used by millions, partnering closely with developers to build secure systems from the ground up.
Position Summary:
In this role, you will have the opportunity to do meaningful work in your career, elevating your craft while contributing to a team that values lifelong learning.
As a Senior DevSecOps Engineer, you are a critical guardian of the platform that powers video knowledge management for global universities and businesses. You will not operate in an isolated silo or an "ivory tower." Instead, you will elevate the craft of security by embedding automated security controls directly into the development lifecycle and CI/CD pipelines. You will bridge the gap between compliance standards (ISO 27001, SOC 2, TX-RAMP) and high-velocity software engineering, ensuring our security posture is pragmatic, scalable, and built on Clarity over Complexity. Driving an AI-first mindset, you will leverage modern automation tools and AI workflows to eliminate manual security tasks, accelerate threat modeling, and simplify system architectures.
You'll also have opportunities to contribute to other initiatives that directly advance our core values and support you in elevating your craft.
How You’ll Contribute:
In this role, you will have the opportunity to…
-
Design Secure Systems: Lead hands-on threat modeling assessments on new features across many different AWS services, ensuring security is baked into application design from the first line of code.
-
Drive Proactive Defense & CI/CD Security: Build, maintain, and enforce automated static (SAST), dynamic (DAST), and dependency (SCA) security testing frameworks within our AWS delivery pipelines to catch vulnerabilities before code reaches production.
-
Secure Cloud & Container Infrastructure: Design and manage security guardrails across AWS environments, Kubernetes clusters, Docker containers, and CloudFormation/CDK/Terraform Infrastructure-as-Code (IaC) deployments.
-
Own Policy & Automated Governance: Lead the technical implementation of policy-as-code and compliance guardrails (ISO 27001, SOC 2, TX-RAMP), translating complex regulatory requirements into simple, actionable engineering standards.
-
Leverage AI Security Tools: Evaluate and integrate AI-assisted tools to accelerate code reviews, log analysis, and vulnerability triage, while establishing secure usage guidelines for developer AI tools.
-
Lead Incident Response: Act with ownership during security events by conducting investigations and root-cause analysis, using collective wisdom to prevent future incidents.
-
Mentor Engineering Teams: Coach developers on secure coding practices, threat identification, and vulnerability remediation through practical mentorship and reusable design patterns.
What Success Looks Like:
-
Within 6 Months: Execute threat modeling assessments for active feature releases. Complete an audit of our current CI/CD pipelines, assume technical ownership of cloud security standards, and establish working relationships with lead developers.
-
Within 1 Year: Automate at least one major vulnerability triage workflow in the build pipeline.
-
Your Legacy: Establish fully automated policy-as-code guardrails across AWS and Kubernetes environments, demonstrating a measurable reduction in security debt during architectural reviews.
Values in Action
-
Customer First, Always: You proactively surface friction points in the customer experience before they are escalated — and propose solutions, not just reports.
-
Thrive Together: You share work-in-progress for early feedback, knowing that challenge improves the outcome. You separate critiques of ideas from critiques of people.
-
Elevate the Craft: You hold the bar high on your own work and invest in developing those around you. You treat every project as an opportunity to learn something new.
-
Act with Ownership: You define success by outcomes, not activity. You flag problems early and bring a proposed path forward, not just the problem.
-
Clarity Over Complexity: You default to the simpler solution. Your written communication — internal or external — is direct, specific, and free of filler.
How We Thrive:
You’ll work with a team of talented engineers with a variety of areas of expertise, from devops to design, architecture to accessibility. The team’s experience level ranges from seasoned developers with well over a decade in industry to junior developers and contractors who are growing their roles and impact.
The Foundation for Success:
-
Cloud & Container Security Mastery: Proven track record securing Multi-Account AWS environments and Infrastructure-as-Code deployments (IAM/Identity Center, Network Security, Encryption, Docker/ECS/Fargate, Terraform, CloudFormation/CDK, Security Hub, GuardDuty).
-
Pipeline Automation & Code Proficiency: Strong hands-on experience integrating security tools into CI/CD pipelines and writing automation scripts using Python or Bash.
-
Practical AI Application: Demonstrated experience using AI tools (such as automated code reviewers, LLM tools, or AI-driven security scanners). In addition, experience securing AI systems, AI supply chinese, and AI-assisted workflows.
-
Threat Modeling Execution: Proven ability to evaluate application architectures for security flaws and guide teams on mitigating OWASP Top 10 vulnerabilities.
-
Pragmatic Compliance: Understanding that security must support business velocity, with experience turning compliance requirements into automated checks without slowing down software releases.
-
Experience: 7+ years in security engineering, DevSecOps, software development, or cloud infrastructure security.
What Sets You Apart:
-
Security or cloud certifications such as CISSP, AWS Certified Security - Specialty, or Certified Kubernetes Security Specialist (CKS).
-
Experience securing video streaming architectures or high-scale backend services.
-
Experience implementing policy-as-code frameworks in regulated SaaS environments.
Join Us
Join Panopto and play a key role in shaping the security foundation of a platform used by millions. If you love threat modeling, automating defenses, guiding engineering teams, and turning compliance standards into practical, scalable security practices, you’ll feel right at home here.
Beyond the Requirements: At this point, we hope you're feeling excited about the job description you’re reading. Even if you don't feel that you meet every single requirement, we still encourage you to apply. We're eager to meet people that believe in our mission and can contribute to our team in a variety of ways - not just candidates who check all the boxes. We want people to feel comfortable expressing their true selves and to come, stay, and do their best work here.
Recruiting Tips: From crafting an impressive resume to presenting your best self during our interviews, we're dedicated to ensuring you feel well-prepared and self-assured as you embark on opportunities at Panopto. Discover some valuable Recruiting Tipsfrom our team.
The standard interview process at Panopto involves several steps, outlined below, to ensure we approach the process thoughtfully and consistently:
Application Review -> Recruiter Call -> Video Interview & Assessment -> Hiring Manager Call -> Interview Loop -> Debrief -> Offer
Our people and culture
Panopto’s mission is to be the leader in visual and audio-based learning in a capture and post-capture world. Our user base is as diverse as the world’s universities and businesses. Panopto’s commitment to fostering a fair, equitable, and inclusive culture empowers each member of our team to express their authentic selves, contribute their distinct perspectives and make a meaningful impact both individually and collectively. This inclusive environment not only encourages creativity and the free exchange of ideas but also harnesses the power of varied viewpoints. As a result, we are better equipped to tackle our most intricate challenges, leveraging the wealth of different experiences and backgrounds within our team. This collaborative spirit empowers us to challenge ideas (not people) recognizing that our shared success relies on collective wisdom. It drives us to continuously improve and innovate, ultimately elevating the quality of our products and services. It’s what sets Panopto apart as a unique and rewarding place to work.
Our purpose
We believe that video can have a transformative effect on learning. So we built a video knowledge management platform that helps businesses and universities improve the way that they train, teach, and share knowledge. Since 2007, we have been a pioneer in video capture software, video management, and inside-video-search technology. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users. Today, Panopto’s knowledge management platform is the largest repository of expert learning videos in the world. A proud remote-first company, Panopto is headquartered in Pittsburgh, with offices in London, Hong Kong, Singapore, and Sydney, and has received industry recognition for its innovation, rapid growth, and company culture.
Panopto is an Equal Opportunity Employer.
We value and encourage diversity and solicit applications from all qualified individuals which will receive consideration for employment without regard to race, color, religion, sex, marital status, sexual orientation, gender identity or expression, national origin, age, disability or protected veteran status, or any other legally protected criteria, in accordance with applicable law. Panopto is committed to providing reasonable accommodation to applicants with disabilities. If you require accommodation for interviewing or otherwise participating in the employee selection process, please provide more detail on how we can further support you by reaching out to the Employee Experience department.
Remote, US: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely.
Remote, International: Candidates looking for flexible or remote-friendly positions are encouraged to apply. Panopto is proud to be a remote-first company. Employees in this position are eligible to work remotely. Still, they may make regular trips to the local international office from time to time, where applicable.
Use of Artificial Intelligence (AI):
Panopto may utilize artificial intelligence (AI) tools to assist in our recruitment and evaluation process. This may include analyzing resumes, assessing skills, and generating insights to help identify qualified candidates.
Please be assured that AI tools are used to support our team, and all final hiring decisions are made by human reviewers. Panopto hiring teams will thoroughly review your application and assessment results. AI is not used to make final decisions regarding your candidacy.
By submitting your application and participating in the recruitment process, you acknowledge and consent to Panopto's use of AI tools as described above.
We are committed to full compliance with all applicable labor laws, including Equal Employment (EEOC) laws, across all our company entities.
To ensure fairness and transparency: We have human oversight in all hiring decisions. If you have concerns regarding the use of AI in your assessment, please contact Panopto Talent Attraction to request a manual review of your application. Please be aware that while we offer this option, the manual review process may take longer than the standard AI-assisted process.
Any data collected during this process, including video recordings if applicable, will be retained only for the duration necessary to fulfill the hiring purpose and will be deleted shortly thereafter once the role is filled.
We may utilize vendor tools to assist with the AI process. Vendor functions are ‘skill assessments' or 'resume analysis'.
Panopto is dedicated to a fair and equitable hiring process for all candidates.
Market context
Measured from remote postings we have tracked ourselves — not self-reported survey data.
What Senior Engineering roles in US Only pay
- 25th
- $137k
- Median
- $155k
- 75th
- $186k
Based on 973 comparable postings with disclosed salaries, last 12 months.
How Panopto is hiring
- Last 90 days
- 9 roles
- Total tracked
- 35
- Hiring across
- 7 job families
Tracked since February 2025.