At Ytech, we live and breathe technology.
Our mission is to turn challenges into solutions and continuously find new ways to innovate.
Founded in 2020, we are a technology start-up operating in the IT and Telecommunications sectors, with a clear ambition: to challenge the market, break conventions, and create real value through innovation.
What challenge do we have for you?
Work model: Hybrid — 3 days onsite per week, with flexibility
Experience level: +2 years
We are looking for a Cloud DevSecOps Engineer to join a team focused on strengthening cloud security across AWS, Azure, and GCP environments.
You will work on the continuous improvement of cloud security policies, access controls, infrastructure security, and secure software delivery practices. The role combines hands-on Cloud Security, DevSecOps, automation, and collaboration with Security, Software Engineering, and DevOps teams.
You will also have the opportunity to support more junior team members and contribute to the continuous evolution of the organisation's security posture.
What we value in you:
- 2 to 4 years of professional experience working with cloud platforms such as AWS, Azure, or GCP.
- Strong knowledge of Identity and Access Management (IAM), least-privilege principles, cloud networking, and container security.
- Good understanding of Kubernetes security and cloud-native environments.
- Solid knowledge of Secure Software Development Lifecycle (SDLC) and DevSecOps principles.
- Experience with Infrastructure as Code, using Terraform or similar technologies.
- Experience integrating security controls into CI/CD pipelines.
- Practical scripting and automation skills using Python, PowerShell, or similar technologies.
- Experience analysing and improving cloud configuration and security policies.
- Strong problem-solving skills and a collaborative approach to security challenges.
- Excellent communication skills, with the ability to explain security risks and solutions to both technical and non-technical stakeholders.
- Fluent English, both written and spoken.
Nice to have:
- Experience with Cloud Security Posture Management (CSPM) platforms such as Prisma Cloud, Wiz, BitSight, SecurityScorecard, or similar tools.
- Knowledge of Application Security methodologies and tools, including SCA, SAST, and DAST, particularly Snyk.
- Strong hands-on experience with Docker and managing Kubernetes clusters.
- Experience using AI tools to accelerate or improve security-related workflows.
- Familiarity with Crossplane for infrastructure management.
- Previous experience mentoring or supporting junior DevSecOps or Security Engineers.
What will you be doing?
- Continuously analyse and refine cloud configuration policies to enforce least-privilege access across AWS, Azure, and GCP environments.
- Collaborate closely with Security, Software Engineering, and DevOps teams to strengthen the organisation's overall security posture.
- Support and mentor more junior members of the DevSecOps team.
- Work directly with development teams and service owners to perform comprehensive QA validation, covering both functional and performance requirements.
- Integrate and improve security controls throughout CI/CD and software delivery processes.
- Automate security-related tasks and workflows through scripting and infrastructure automation.
- Identify security risks, configuration issues, and opportunities for continuous improvement.
- Stay up to date with security trends, vulnerabilities, compliance requirements, and emerging technologies.
- Advocate for secure engineering practices and contribute to the continuous improvement of Cloud Security and DevSecOps processes.
Benefits of joining our team:
- Challenging projects with a strong technological focus.
- Training and certification programme.
- Health insurance.
- Structured career progression.
- Continuous support from the Ytech team.