We are looking for a proactive and skilled DevSecOps Engineer to incorporate security practices into our software development and operations processes. You have hands‑on experience with CI/CDI, covering pipelines, cloud platforms, container security, vulnerability management, etc., and security automation. You will collaborate closely with Development, DevOps, and Security teams to build secure, scalable, and compliant applications and infrastructure.
Key Responsibilities:
- CI/CD pipelines design, build, and maintenance with security aspects.
- Embed security tools and controls in the SDLC process.
- Perform SAST, DAST Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Conduct vulnerability scans and help track impact across applications, containers, and infrastructure.
- Design, develop, and harden the Infrastructure as Code (IaC) security practices.
- Secure cloud environments (AWS, Azure, or GCP) and ensure compliance with security best practices.
- SIEM and Security Monitoring: track security incidents, logs, and events monitoring tools.
- Promote container and Kubernetes security, including image scanning and runtime protection.
- Work with developers to find and fix security issues.
- Draft new and revise existing security policies, standards, and best practices.
- Automate Security and Compliance Checks in DevOps Workflows.
- Basic incident response support, performing initial threat identification and root‑cause analysis activities.
Required Skills & Qualifications:
The desired candidate should have a bachelor’s degree in Computer Science, Information Security Engineering, or a related field.
- 3+ years’ experience in DevOps, Cloud Security, Cybersecurity, and DevSecOps roles.
- Strong knowledge of DevSecOps concepts and secure software delivery life cycle.
- Experience with CI/CD tools like Jenkins, GitHub Actions, GitLab CI/CD, or Azure DevOps.
- Experience with cloud platforms (e.g., AWS, Azure, or GCP).
- Familiarity with Docker and Kubernetes.
- Knowledge of Infrastructure as Code Tools, Terraform, and CloudFormation.
- Experience in vulnerability management techniques and tools, security scanning; strong scripting skills (Python, Bash, PowerShell).
- Very good knowledge of networking, Linux administration, and basic‑level security.
- Familiarity with OWASP Top 10, security frameworks, and compliance standards.