DevSecOps Engineer

Jobtailor

Deutschland

Vor Ort

EUR 90.000 - 140.000

Vollzeit

Vor 9 Tagen

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Jobtailor is seeking a senior Security Engineer to secure cloud infrastructure, applications, and AI-enabled systems. You will design and implement security controls across CI/CD pipelines and production environments, drive vulnerability remediation, and collaborate with engineering teams to improve secure development practices.

Ideal candidates have 5+ years in security engineering with strong AWS expertise and experience with SOC 2, PCI DSS, FinTech security standards.

Qualifikationen

  • 5+ years hands-on experience in security engineering, infrastructure security, or DevSecOps.
  • Experience with AWS security in production environments.
  • Familiarity with SOC 2, PCI DSS, FinTech security best practices.

Aufgaben

  • Secure and harden cloud infrastructure, applications, and APIs.
  • Implement and maintain security controls across production environments.
  • Lead vulnerability remediation and secure development practices with engineering teams.
  • Coordinate remediation efforts and validate fixes.
  • Design guardrails for AI-generated actions and threat modeling.

Kenntnisse

Security Engineering
Vulnerability Management
AWS Ecosystem
Incident Response
DevSecOps

Ausbildung

CISSP
CISM
AWS Security Specialty

Tools

Cloud Security Tooling
SIEM
Observability Platforms
Endpoint Security
IaC Security

Jobbeschreibung

  • Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows
  • Implement and maintain security controls across production environments, CI/CD pipelines, cloud infrastructure, and internal tooling
  • Remediate vulnerabilities and improve secure development practices with engineering teams
  • Maintain encryption, secrets management, logging, monitoring, and access controls
  • Design and improve security architecture across cloud-native and distributed systems
  • Identify, assess, prioritize, and remediate vulnerabilities across infrastructure, applications, APIs, and operational systems
  • Conduct vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews
  • Coordinate remediation efforts, validate fixes, and implement long‑term mitigation strategies
  • Improve detection and prevention capabilities for emerging threats
  • Secure AI‑driven systems and automated agents against prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage
  • Design guardrails and validation layers for AI‑generated actions
  • Monitor AI behavior for anomalies, abuse attempts, and unsafe decision‑making
  • Ensure AI systems are observable, auditable, bounded, and fail safely
  • Improve security monitoring, alerting, logging, and incident response capabilities
  • Investigate suspicious activity, anomalies, and potential security incidents
  • Lead or support incident response, root cause analysis, and remediation planning
  • Recommend preventative measures following incidents or security discoveries
  • Collaborate with Compliance and Operations to meet SOC 2, PCI DSS, and financial and consumer data security requirements
  • Assist with audit preparation, evidence collection, security documentation, and control validation
  • Participate in risk assessments, control reviews, and remediation planning
  • Participate in customer and partner due diligence processes
  • Answer technical security questions from customers, financial institutions, prospects, partners, auditors, and assessors
  • Complete security questionnaires, RFPs, and vendor risk assessments
  • Communicate security architecture, operational controls, monitoring capabilities, and security practices
  • Collaborate with Engineering, Product, Compliance, Operations, and Leadership
  • Contribute to architecture reviews, security planning, engineering roadmaps, and operational processes
  • Embed security‑first practices into engineering and operational culture
  • Balance security, reliability, scalability, and business velocity
Requirements
  • 5+ years of hands‑on experience in security engineering, infrastructure security, application security, DevSecOps, vulnerability management, or offensive security
  • Exceptional knowledge of the AWS ecosystem
  • Experience identifying and remediating vulnerabilities in production systems
  • Working knowledge of SOC 2, PCI, and FinTech security best practices
  • Ability to drive projects, make decisions, and prioritize in a fast‑moving environment
  • Excellent communication skills for explaining complex systems to engineering and business stakeholders
  • Experience securing AI/LLM‑powered systems or automated agents preferred
  • Familiarity with prompt injection attacks, adversarial AI techniques, AI guardrails, validation systems, and behavioral anomaly detection preferred
  • Experience with cloud security tooling, SIEM, observability platforms, penetration testing tools, endpoint security platforms, and infrastructure‑as‑code security preferred
  • Prior experience in high‑growth startups, FinTech, banking, or payments preferred
  • CISSP, CISM, AWS Security Specialty, or similar certifications preferred
Core Competencies

Demonstrates expertise in securing cloud infrastructure and applications, with a strong focus on vulnerability management, incident response, and compliance with SOC 2 and PCI standards. Proficient in implementing security controls and improving security architecture for AI-driven systems and operational workflows.

Highest‑signal resume keywords
  • Security Engineering
  • Vulnerability Management
  • AWS Ecosystem
  • Incident Response
  • DevSecOps
ATS Optimization Keywords
Hard Skills
  • Vulnerability Scanning
  • Penetration Testing
  • Threat Modeling
  • Security Architecture Design
  • Encryption Management
  • Access Control Implementation
  • CI/CD Security
  • Behavioral Anomaly Detection
  • Remediation Planning
  • Security Documentation
Soft Skills
  • Excellent Communication
  • Project Management
  • Decision Making
  • Collaboration
Certifications & Qualifications
  • CISSP
  • CISM
  • AWS Security Specialty
Industry Keywords
  • SOC 2
  • PCI DSS
  • FinTech
  • Adversarial AI Techniques
  • AI Guardrails
Tools & Technologies
  • Cloud Security Tooling
  • SIEM
  • Observability Platforms
  • Endpoint Security Platforms
  • Infrastructure‑as‑Code Security
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Cloud Security Architect – Terraform
Senior Cloud Security Architect – Terraform

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Cloud Security Engineer
Cloud Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security training
Security Engineer
Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 80.000 - 110.000
AWS DevSecOps Engineer
AWS DevSecOps Engineer

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Senior Manager, Information Security Architecture – Engineering
Senior Manager, Information Security Architecture – Engineering

Jobtailor • Deutschland

Remote
EUR 120.000 - 150.000
IS Principal Security Architect
IS Principal Security Architect

Jobtailor • Deutschland

Hybrid
EUR 130.000 - 190.000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Riederich

Vor Ort
EUR 75.000 - 110.000
IT Security Analyst – Level 1
IT Security Analyst – Level 1

Jobtailor • Deutschland

Hybrid
EUR 45.000 - 65.000
Global Product Cyber Security Expert – R&D Digital Portfolio
Global Product Cyber Security Expert – R&D Digital Portfolio

Jobtailor • Mannheim

Vor Ort
EUR 110.000 - 150.000
Senior Analyst, Platform Engineer
Senior Analyst, Platform Engineer

Jobtailor • Deutschland

Hybrid
EUR 65.000 - 90.000