About the Role
Rumble Cloud is seeking a DevSecOps Engineer to embed security throughout the software development lifecycle for our cloud platform and customer-facing services. This hands-on role owns the Secure Software Development Lifecycle (SSDLC) end-to-end, partnering with engineering teams to remediate vulnerabilities and harden CI/CD pipelines.
Responsibilities
- Own the SSDLC end to end, including secure coding standards, threat modeling, security gates, policy-as-code, and audit documentation.
- Drive vulnerability identification, triage, and remediation across Python, Go, and TypeScript/React codebases.
- Design, harden, and optimize CI/CD pipelines using tools such as GitHub Actions, GitLab CI, or Jenkins.
- Integrate and operate security tooling including SAST, DAST, SCA, secret scanning, container scanning, and dependency analysis.
- Implement secure software supply chain practices such as signed artifacts, SBOM generation, and provenance controls.
- Manage secrets, credentials, and signing keys using least-privilege access and secure storage practices.
- Partner with engineering teams to review code, assess risk, and recommend practical remediation approaches.
- Support security incident response and post-incident follow-up to identify root causes.
- Contribute to audit readiness and evidence collection for frameworks such as ISO 27001, SOC 2, PCI DSS, or FedRAMP.
- Mentor engineers on secure development practices and foster a security-first culture.
Requirements
- Experience in a DevSecOps, application security, or product security role.
- Hands-on experience with CI/CD systems such as GitHub Actions, GitLab CI, or Jenkins.
- Strong knowledge of application security tooling including SAST, DAST, SCA, and container scanning.
- Practical understanding of the OWASP Top 10.
- Ability to read and review code in at least one of Python, Go, or TypeScript.
- Experience with Docker and Kubernetes.
- Experience with secrets management systems such as Vault.
- Experience with authentication patterns such as OAuth2 and OpenID Connect.
- Strong communication and collaboration skills.
Skills
- DevSecOps
- Application Security
- SSDLC
- CI/CD Pipeline Hardening
- SAST/DAST/SCA
- Python
- Go
- TypeScript
- Docker
- Kubernetes
- Vault
- OAuth2
- OpenID Connect
- Threat Modeling
- Software Supply Chain Security
Salary/Compensations
- $165,000 - $195,000 USD base + benefits + equity (United States)
- $122,000 - $158,000 CAD base + benefits + equity (Canada)
Benefits
- Competitive salaries
- Benefits
- Equity
About the Company
- Rumble is the Freedom-First technology platform.
- Offers a video platform, cloud services, advertising solutions, and a non-custodial cryptocurrency wallet.
Equal Opportunity
- Rumble is an equal opportunity employer.
- Promotes an equal playing field regardless of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability status, or any other applicable characteristics protected by law.
- Active participant in the e-verify program.
