π Job Title: DevSecOps Engineer
π Location: [Remote / On-site]
π Employment Type: [Full-Time / Contract / Freelance]
π Experience Level: [Mid-Level / Senior-Level]
π Job Summary:
We are looking for an experienced DevSecOps Engineer to integrate security into every stage of our software development lifecycle. The ideal candidate will have a strong background in DevOps, cloud security, and automation, with a passion for building secure and scalable systems. You will work closely with development, operations, and security teams to ensure robust security practices across our CI/CD pipelines, infrastructure, and applications.
π― Key Responsibilities:
-
Integrate security controls into CI/CD pipelines using tools like Snyk, Checkmarx, SonarQube, or similar.
-
Automate security testing for code, containers, and cloud infrastructure.
-
Perform threat modeling, vulnerability assessments, and implement mitigation strategies.
-
Collaborate with developers to ensure secure coding practices.
-
Monitor and respond to security incidents using SIEM and log management tools.
-
Implement and manage secrets management solutions (e.g., HashiCorp Vault, AWS Secrets Manager).
-
Ensure compliance with industry standards (SOC 2, ISO 27001, GDPR, etc.).
-
Maintain cloud infrastructure security (AWS, Azure, GCP).
-
Contribute to and maintain Infrastructure as Code (Terraform, CloudFormation).
-
Advocate for security best practices across teams.
π§ Required Skills & Qualifications:
-
3+ years of experience in DevOps, Security Engineering, or similar roles.
-
Strong understanding of CI/CD tools (Jenkins, GitLab CI, GitHub Actions, etc.).
-
Expertise in cloud platforms (AWS, Azure, or GCP).
-
Proficiency in scripting languages (Python, Bash, PowerShell).
-
Familiarity with containerization and orchestration (Docker, Kubernetes).
-
Experience with security tools: SAST, DAST, SCA, EDR, SIEM, and vulnerability scanners.
-
Understanding of common vulnerabilities (OWASP Top 10, CVEs) and how to remediate them.
π‘ Preferred Qualifications:
-
Certifications such as AWS Certified Security Specialty, Certified DevSecOps Engineer, OSCP, or CISSP.
-
Experience working with SOAR tools and automation frameworks.
-
Exposure to zero trust architectures and identity/access management.
-
Familiarity with security in microservices and serverless architectures.
π What We Offer:
-
Competitive salary and performance-based bonuses.
-
Flexible work environment (remote/hybrid options).
-
Access to ongoing training, certifications, and professional development.
-
A culture that values security, collaboration, and continuous improvement.