DevSecOps Engineer

Richemont Iberia SL

Moscavide

Presencial

EUR 55 000 - 75 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Richemont Iberia SL in Lisboa is seeking a DevSecOps Engineer to join the Governance & Architecture team within Cloud & DevOps Services. You will strengthen security across the software delivery lifecycle by implementing secure code development and deployment practices.

You will automate security controls, support incident response, and collaborate with product, cybersecurity, and compliance teams to quantify risk and drive secure cloud workloads. Fluent English is required; French is a plus.

Qualificações

  • Experience integrating security controls into the SDLC (Secure SDLC).
  • Familiarity with preventive, detective and corrective controls and security frameworks (CIS, NIST).
  • Knowledge of security risk assessment using OWASP Top 10 (Web Apps, API).
  • Experience with automation tools and scripting to implement security controls.

Responsabilidades

  • Contribute to and enhance a complete stack of Cloud Security & DevSecOps solutions.
  • Automate the implementation and testing of security controls.
  • Monitor effectiveness and adjust controls as needed.
  • Investigate and resolve security incidents related to controls.
  • Provide guidance to engineering and project teams on security practices.

Conhecimentos

SSDLC experience
Security frameworks
OWASP Top10
CI/CD automation
Python/Go scripting
Cloud security
Kubernetes security
Problem solving
Communication
Continuous learning
English fluency
French a plus

Ferramentas

GitLab CI
Jenkins
AWX

Descrição da oferta de emprego

CONTEXT

As a DevSecOps Engineer, you will be part of the Governance & Architecture team within the Cloud & DevOps Services department.

You are instrumental in enabling and enhancing our security posture throughout our software delivery lifecycle, allowing streamlined and secure code development and deployment processes. You participate in designing, implementing, and continuously improving our security frameworks. Your proficiency in DevOps and secure application development practices will make you a crucial link between development and operations teams.

HOW WILL YOU MAKE AN IMPACT?
  • Contribute to and enhance a complete stack of solutions for Cloud Security & DevSecOps management from a people, process, and technology standpoint. This includes but is not limited to Secret Detection, SAST, SCA, and container security.
  • Develop and implement security controls that are aligned with the organization's security policies and procedures throughout our software delivery lifecycle.
  • Automate the implementation and testing of these controls.
  • Monitor their effectiveness and make necessary adjustments.
  • Investigate and resolve security incidents that are related to security controls.
  • Provide practical guidance to engineering and project teams to support the implementation of security controls, guidelines, and best practices.
  • Be a driving element and enable greater cooperation between product teams, cybersecurity teams, and compliance functions, helping quantify the risk and define relevant control objectives and activities to secure cloud workloads.
  • Contribute to the cloud and DevOps security governance (including participating in committees, building dedicated dashboards with associated KPIs, and evangelizing to other teams).
  • Be autonomous and proactive; Able to understand functional and technical requirements, identify gaps, and suggest improvements.
HOW WILL YOU EXPERIENCE SUCCESS WITH US?
  • Previous experience in an SSDLC context, with a proven track record in developing and implementing effective security solutions and managing security challenges.
  • Familiarity with security controls and frameworks. This includes understanding the different types of security controls, such as preventive, detective, and corrective controls, and the various security frameworks, such as the CIS Controls and the NIST Cybersecurity Framework.
  • Knowledge of the SDLC and how to integrate security controls into the SDLC. This includes understanding the different phases of the SDLC and how to apply security controls at each stage.
  • Knowledge of security risk assessment frameworks like OWASP top 10 (Web Applications, API). (APP SECURITY) (Knowledge of Secure Software Development Lifecycle)
  • Experience with automation tools , ci/cd (gitlab ci, Jenkins, awx…) and scripting languages (Python/Go mainly) will be key to understanding the context in which the controls must integrate and automating the implementation and testing of security controls themselves.
  • Knowledge of cloud (AWS, Ali Baba, and GCP, ideally) and Kubernetes security is essential, as these are the foundations of our technology stack.
  • Strong problem-solving skills. DevSecOps engineers need to be able to identify and solve security problems that arise while implementing security controls.
  • Effective communication skills. DevSecOps engineers must communicate effectively with developers, security engineers, and other stakeholders to implement security controls.
  • A passion for continuous learning and keeping up with the latest security trends and technologies. The security landscape is constantly evolving, so DevSecOps engineers must be willing to learn new things and keep up with the latest security trends and technologies.
  • Fluent in English, French is a plus
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Distributed Cloud | DevSecOps Engineer
Distributed Cloud | DevSecOps Engineer

Devoteam • Portugal

Presencial
EUR 45 000 - 75 000
Nearshore Sector | Security Operations Specialist (SecOps)
Nearshore Sector | Security Operations Specialist (SecOps)

Devoteam • Lisboa

Presencial
EUR 50 000 - 70 000
Diverse working environment
Opportunities for career advancement
Equal opportunities promotion
Distributed Cloud | DevSecOps Engineer
Distributed Cloud | DevSecOps Engineer

Devoteam • Porto

Presencial
EUR 40 000 - 60 000
Mid Cloud DevSecOps | Hybrid
Mid Cloud DevSecOps | Hybrid

A2IT Technology • Almada

Híbrido
EUR 38 000 - 60 000
Senior DevSecOps & Product Security Engineer
Senior DevSecOps & Product Security Engineer

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
DevSecOps (Lisbon / Porto - Hybrid)
DevSecOps (Lisbon / Porto - Hybrid)

Claranet limited • Lisboa, Porto

Híbrido
EUR 60 000 - 80 000
Integration into a dynamic and motivated team
Additional training
Salary package according to the role performed
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector
Devoteam Cyber Trust | Application Security Engineer | Mobility Sector

Devoteam | Cyber Trust • Lisboa

Presencial
EUR 45 000 - 65 000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Welvaart • Lisboa

Presencial
EUR 60 000 - 90 000
DevOps Engineer
DevOps Engineer

CodSec • Braga

Híbrido
EUR 42 000 - 64 000
Cloud DevSecOps Engineer
Cloud DevSecOps Engineer

Ytech • Portugal

Híbrido
EUR 42 000 - 66 000
Health insurance
Training and certification programme
Structured career progression
+1