DevSecOps Engineer
Responsible for embedding security into the SDLC by building secure CI/CD pipelines, implementing shift-left security tooling (SAST, DAST, SCA), securing AWS/GCP cloud infrastructure with IaC, and building SIEM/log aggregation platforms. Supports incident response and monitoring.
Responsibilities
- Build and maintain secure CI/CD pipelines with integrated security controls.
- Implement and automate shift-left security tooling across the SSDLC (SAST, DAST, SCA, secrets detection).
- Secure cloud infrastructure (AWS, GCP) and codify security/compliance controls using IaC and policy-as-code.
- Design and build SIEM or centralized log aggregation platforms, including log pipelines and detection rules.
- Support incident response and continuous monitoring of cloud and application security posture.
Requirements
- 4+ years in DevOps, security, or SRE with 2+ in DevSecOps/cloud security.
- Experience securing AWS/GCP (IAM, networking, encryption, CIS Benchmarks).
- Proven CI/CD pipeline building (GitHub Actions, GitLab CI, Jenkins).
- Knowledge of shift-left tools (SAST, DAST, SCA, secrets detection, container scanning).
- Proficiency in IaC (Terraform) and IaC scanning (Checkov).
- Scripting in Python, Go, or Bash.
- Container security (Docker, Kubernetes, runtime protection).
- Experience building SIEM/log aggregation (Splunk, ELK, Datadog).
- Familiarity with OWASP, NIST, CIS, GDPR, PCI DSS.
Nice to have
- Experience implementing security/compliance controls for GDPR, HIPAA, PCI DSS in cloud.
- Experience with CSPM/CNAPP tools (Wiz, Prisma Cloud, Orca, AWS Security Hub, GCP SCC).
- Experience with policy-as-code (OPA/Rego, Sentinel).
- Knowledge of secrets management platforms (HashiCorp Vault, AWS Secrets Manager).
- Certifications: AWS/GCP Security Specialty, CKS, OSCP.