Senior DevSecOps Engineer
Join a core platform team to integrate security across the software development lifecycle and build secure, scalable infrastructure across cloud and on-premises environments.
Обязанности
- Integrate security practices across CI/CD pipelines and the software development lifecycle.
- Design and implement automated vulnerability scanning, compliance checks, and threat detection.
- Build and maintain secure, scalable Infrastructure as Code for cloud environments.
- Automate security controls and operational processes across cloud and Kubernetes environments.
- Design, implement, and optimize secure, reliable, high-performance CI/CD pipelines.
- Secure cloud and on-premises environments through IAM, network controls, and encryption practices.
- Manage and harden Kubernetes workloads, including configuration, access control, and image security.
- Conduct security assessments, penetration testing, and compliance audits.
- Monitor threats, respond to incidents, and improve incident response processes.
- Guide teams on secure coding, infrastructure, and deployment practices.
- Integrate monitoring, logging, and SIEM solutions to improve observability.
Требования
- 5–8 years of experience in DevOps or security, focused on secure infrastructure and application security.
- Expertise in AWS, GCP, or Azure security and Infrastructure as Code using Terraform or Ansible.
- Experience integrating security into CI/CD pipelines with tools such as Jenkins, GitHub Actions, or ArgoCD.
- Knowledge of container security, Kubernetes, and image scanning.
- Proficiency with SAST, DAST, SCA, secret scanning, and compliance frameworks such as CIS, NIST, ISO 27001, or SOC 2.
- Strong Python or Bash scripting skills for security automation.
- Experience with zero-trust models, IAM, and secrets management.
- Familiarity with AWS security tools, monitoring, alerting, and SIEM solutions.
- Strong troubleshooting skills in network security, encryption, and secure authentication.
- Excellent communication and collaboration skills.
Будет плюсом
- Experience securing endpoint products such as agents, sensors, or collectors.
- Background in AI security, including ML models, training pipelines, or inference serving.
- Experience with policy-as-code tools such as OPA or Kyverno.
- Familiarity with ISO 27001, SOC 2, HIPAA, PCI-DSS, or FedRAMP compliance frameworks.