DevSecOps Engineer

stepstone.fr

Dublin

On-site

EUR 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

StepStone is seeking a DevSecOps Engineer to embed security into the SDLC and CI/CD pipelines, focusing on application security guardrails and developer tooling. You will provide hands-on cloud security across AWS, with Azure proficiency, collaborating with infrastructure and DevOps teams to harden posture and enable delivery speed.

You will implement guardrails, threat model services, and manage CSPM/CNAPP tooling, ensuring secure SDLC practices and audit readiness.

Qualifications

  • Strong experience embedding security into CI/CD pipelines and SDLC (SAST/DAST/SCA) with policy gates.
  • Threat modeling and secure coding guidance; collaborate with developers to land fixes without blocking delivery.
  • Hands-on AWS security (IAM, VPC, KMS, encryption); Azure/GCP security proficiency.
  • IaC expertise (Terraform, CloudFormation; Bicep or Deployment Manager a plus) and scripting in Python.
  • Knowledge of vulnerability mgmt, logging, secrets mgmt, and incident response.
  • Experience operating CNAPP/CSPM platforms (Wiz preferred) and remediating findings.
  • Familiarity with container/Kubernetes security (EKS/AKS/GKE) and AI/ML security desirable.

Responsibilities

  • Own and mature the DevSecOps program with guardrails across CI/CD pipelines.
  • Threat-model new services and translate findings into actionable guardrails for developers.
  • Create reusable IaC patterns and templates adopted by engineering teams.
  • Triage and remediate findings across cloud and app layers; reduce backlog.
  • Establish cloud security guardrails on AWS; extend to Azure with Defender and Policy.
  • Harden IAM, network exposure, and encryption; enforce least privilege.
  • Extend posture mgmt to Azure and/or GCP controls.
  • Reduce internet-facing exposure and support SOC 2, audit, and compliance.

Skills

CI/CD security
SAST
DAST
SCA
infrastructure-as-code
Python
AWS security
Azure security
GCP security
Threat modeling
Kubernetes security
CNAPP/CSPM Wiz

Education

Bachelor's degree in CS/InfoSec
4+ years DevSecOps / cloud security
DevSecOps or App Sec cert
SOC 2 / ISO27001 / SOX exposure

Tools

Terraform
CloudFormation
Bicep
GCP Deployment Manager
Python
Wiz

Job description

We are global private markets specialistsdelivering tailored investment solutions,advisory services, and impactful, data driveninsights to the world’s investors.Leveraging the power of our platform andour peerless intelligence across sectors,strategies, and geographies, we helpidentify the advantages and the answersour clients need to succeed.

The DevSecOps Engineer is responsible for embedding security into the software development lifecycle and the firm's CI/CD pipelines, with primary focus on application security guardrails, developer-facing tooling, and secure engineering practices. The role also maintains hands-on cloud security expertise, primarily on AWS with working proficiency across Azure, to harden posture and reduce exposure. Sitting within Infrastructure Engineering, the role partners closely with application development, platform, and DevOps teams to build guardrails that get adopted rather than imposed, protecting systems and data while supporting delivery speed.

Key Responsibilities
  • Own and continuously mature the firm's DevSecOps program, embedding SAST, DAST, SCA, infrastructure-as-code and secrets scanning, and policy gates directly into CI/CD pipelines to catch issues before deployment.
  • Partner with application development teams to threat-model new services and features at design time, translating findings into concrete guardrails and remediation guidance developers can act on.
  • Build and maintain secure-by-default patterns, reusable infrastructure-as-code modules, and golden pipeline templates that engineering teams adopt by default.
  • Operationalize the firm's cloud-native application protection platform (Wiz): triage, prioritize, and remediate findings across cloud and application layers, reducing backlog and mean time to remediate.
  • Establish and codify cloud security guardrails primarily on AWS, including Service Control Policies, Config rules, public-access blocking, default encryption, and tagging baselines.
  • Harden identity and access (IAM roles, policies, permission boundaries, and least privilege) and network exposure across cloud workloads.
  • Extend posture management and guardrails to Azure, using tools such as Microsoft Defender for Cloud, Azure Policy, Entra ID, and equivalent GCP controls.
  • Drive down internet-facing exposure, targeting zero critical and high-severity findings across public-facing workloads and applications.
  • Provide security evidence and controls in support of SOC 2, audit, and regulatory requirements, with emphasis on evidencing secure SDLC practices.
Required Skills
  • Strong, hands-on experience embedding security into CI/CD pipelines and the SDLC: SAST, DAST, SCA, infrastructure-as-code scanning, secrets management, and policy-as-code/gating.
  • Practical application security background, including threat modeling and secure coding guidance, with a track record of working directly with developers to land fixes without becoming a blocker to delivery.
  • Solid, hands-on AWS security expertise (IAM, VPC and network security, KMS and encryption, Service Control Policies, public-exposure controls), plus working proficiency in Azure and/or GCP security (Entra ID, Azure RBAC, Microsoft Defender for Cloud, Azure Policy, or equivalent GCP services).
  • Proficiency with infrastructure-as-code (Terraform and/or CloudFormation; Bicep or GCP Deployment Manager an advantage) and scripting and automation (Python preferred).
  • Solid understanding of core security processes, including vulnerability management, logging and detection, secrets management, and incident support.
  • Experience operating a CNAPP/CSPM platform (Wiz preferred), with a track record of remediating findings rather than only reporting them.
  • Familiarity with container and Kubernetes security (EKS/AKS/GKE) and AI/ML application security is desirable.
Educations and Or Work Experience Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Four (4)+ years of experience in DevSecOps, application security, or cloud security engineering.
  • Professional certifications such as a DevSecOps or application security credential (e.g., GWEB, Certified DevSecOps Professional), AWS Certified Security - Specialty, or equivalent.
  • Prior exposure to audit and compliance standards including SOC 2, ISO 27001, or SOX.

#LI-EO1

At StepStone, we believe that our people are our most important asset and crucial to our success. We are an Equal Opportunity Employer that strives to create an environment that empowers our employees and allows them to be heard, regardless of title or tenure. Our organizational community features multiple Employment Resource Groups as well as mentorship programs to enhance the employee experience for all.

As an Equal Opportunity Employer, StepStone does not discriminate on the basis of race, creed, color, religion, sex, national origin, citizenship status, age, disability, marital status, sexual orientation, gender identity, gender expression, genetic information or any other characteristic protected by law.

Candidates must be at least 18 years old to apply.

Developing People at StepStone

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

StepStone Group • Dublin

On-site
EUR 90,000 - 130,000
DevSecOps Engineer — Secure SDLC & Cloud Guardrails
DevSecOps Engineer — Secure SDLC & Cloud Guardrails

stepstone.fr • Dublin

On-site
EUR 90,000 - 130,000
DevSecOps Engineer: Secure CI/CD & Cloud Guardrails
DevSecOps Engineer: Secure CI/CD & Cloud Guardrails

StepStone Group • Dublin

On-site
EUR 90,000 - 130,000
Sr. Solutions Support Engineer
Sr. Solutions Support Engineer

Gem • Ireland

On-site
EUR 70,000 - 100,000
Sr. Solutions Support Engineer
Sr. Solutions Support Engineer

Wiz • Ireland

On-site
EUR 90,000 - 130,000
Security Engineer - Product
Security Engineer - Product

Wiz • Ireland

On-site
EUR 110,000 - 170,000
Solutions Support Engineer
Solutions Support Engineer

Gem • Ireland

On-site
EUR 85,000 - 115,000
Security Operations Engineer, AWS Security Cloud Response
Security Operations Engineer, AWS Security Cloud Response

Amazon • Dublin

On-site
EUR 90,000 - 130,000
Security Engineer
Security Engineer

Everseen • Cork

On-site
EUR 90,000 - 130,000
Software Engineer, Security Business Enablement
Software Engineer, Security Business Enablement

Stripe • Dublin

On-site
EUR 90,000 - 140,000