Senior DevSecOps & Product Security Engineer

Doxis

Porto

Híbrido

EUR 70 000 - 110 000

Tempo integral

Há 12 dias

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Private healthcare
Udemy memberships
Udemy Business access
Flexible hours & hybrid/remote

Resumo da oferta

Doxis is seeking an experienced Senior DevSecOps & Product Security Engineer to design, automate and operate security across our cloud platform and SDLC. You will integrate automated controls into CI/CD pipelines and support regulatory compliance.

You will work closely with engineering and cloud operations to mature security posture, implement guardrails, and drive secure software delivery with hands-on tooling and scripting.

Qualificações

  • 5+ years in Security Engineering or DevSecOps.
  • Experience securing cloud-native SaaS products and production cloud platforms.
  • Hands-on with CI/CD tools like GitHub Actions, Azure DevOps, GitLab CI or Jenkins.
  • Knowledge of IAM, encryption, secrets management, and vulnerability management.

Responsabilidades

  • Design and implement security controls across CI/CD pipelines.
  • Automate SAST, SCA, secret detection, container scanning, IaC and DAST.
  • Build policy-as-code, guardrails and automated compliance reporting.
  • Secure cloud infrastructure, Kubernetes environments and deployment processes.
  • Own vulnerability management, including scanning, remediation tracking and reporting.
  • Support secure coding practices, threat modelling and design reviews.
  • Assist with penetration testing, security assessments and audits.
  • Improve detection, logging and incident response capabilities.
  • Develop automation for evidence collection, reporting and dashboards.

Conhecimentos

Security Engineering
DevSecOps
Cloud Security
CI/CD
Threat Modelling

Ferramentas

Checkmarx
SonarQube
GitHub Advanced Security
Trivy
Snyk
Semgrep
OWASP ZAP

Descrição da oferta de emprego

We are looking for an experienced Senior DevSecOps & Product Security Engineer to help build, automate and operate security capabilities across our cloud platform, SDLC and CI/CD pipelines.

This is a hands-on role working closely with engineering, cloud operations and architecture teams to improve security posture, embed automated controls and support compliance with customer, contractual and regulatory requirements.

Key Responsibilities
  • Design and implement security controls across CI/CD pipelines
  • Automate SAST, SCA, secret detection, container scanning, IaC scanning and DAST where appropriate
  • Build policy-as-code, security guardrails and automated compliance reporting
  • Secure cloud infrastructure, Kubernetes environments and deployment processes
  • Improve IAM, privileged access management, MFA, networking and encryption standards
  • Own vulnerability management, including scanning, risk assessment, remediation tracking, patch coordination and reporting
  • Partner with development teams on secure coding standards, threat modelling, design reviews and software supply chain security
  • Support penetration testing, customer security assessments and audit preparation
  • Investigate security events, support incident response and improve detection, logging and monitoring
  • Develop automation for evidence collection, reporting, dashboards and security workflows
What We're Looking For
  • 5+ years' experience in Security Engineering, DevSecOps or Cloud Security
  • Experience securing cloud-native SaaS products and production cloud platforms
  • Strong knowledge of at least one major cloud platform: AWS, Azure or Google Cloud
  • Hands-on experience with CI/CD tools such as GitHub Actions, Azure DevOps, GitLab CI or Jenkins
  • Experience with security tools such as Checkmarx, SonarQube, GitHub Advanced Security, Trivy, Snyk, Semgrep or OWASP ZAP
  • Strong container and Kubernetes security knowledge, including Docker and Helm
  • Experience with IaC tools such as Terraform, Bicep, CloudFormation or Pulumi
  • Familiarity with IaC scanning tools such as Checkov, tfsec or Terrascan
  • Strong scripting skills in Python, PowerShell or Bash
  • Solid understanding of OWASP Top 10, Secure SDLC, threat modelling, Zero Trust, IAM, encryption, PKI, secrets management, SIEM, incident response and vulnerability management
  • Experience with frameworks such as ISO 27001, ISO 27002, NIST CSF, CIS Controls, SSDF or SOC 2
Nice to Have
  • Go programming experience
  • Experience with UK Government Security Policy Framework or NCSC Cloud Security Principles
  • Experience in government or regulated industry environments
About You

You are hands-on, pragmatic and automation-focused. You can work closely with engineering teams, communicate clearly, influence technical decisions and continuously improve how security is embedded into software delivery.

What Success Looks Like

In your first 12 months, you will have helped embed automated security testing into CI/CD pipelines, improved cloud security posture, reduced manual security work, strengthened vulnerability management and increased confidence in secure software delivery.

What We Offer
  • Private healthcare for you and your dependents.
  • Urban Sports Club & Udemy Business memberships covered by Doxis.
  • Access to Udemy Business.
  • Flexible working hours and a hybrid or remote working environment.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Mid Cloud DevSecOps | Hybrid
Mid Cloud DevSecOps | Hybrid

A2IT Technology • Almada

Híbrido
EUR 38 000 - 60 000
DevSecOps (Lisbon / Porto - Hybrid)
DevSecOps (Lisbon / Porto - Hybrid)

Claranet limited • Lisboa, Porto

Híbrido
EUR 60 000 - 80 000
Integration into a dynamic and motivated team
Additional training
Salary package according to the role performed
Senior DevSecOps Engineer
Senior DevSecOps Engineer

LUZA Group • Oeiras

Presencial
EUR 60 000 - 90 000
Remote work whenever possible
Work equipment provided
Benefits plan
Application Security Engineer
Application Security Engineer

LUZA Group • Porto

Híbrido
EUR 50 000 - 70 000
Remote work when possible
Equipment provided
Benefits plan
Cloud Security Engineer
Cloud Security Engineer

Thought Machine Group Limited • Portugal

Presencial
EUR 45 000 - 70 000
Highly competitive salary
Voluntary Pension Plan (match up to 5%)
Private Healthcare Insurance
+10
Senior DevSecOps & Product Security Engineer - Remote
Senior DevSecOps & Product Security Engineer - Remote

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
Senior Devsecops Engineer
Senior Devsecops Engineer

Luza Group • Lisboa

Híbrido
EUR 60 000 - 90 000
Remote work flexibility
Equipment provided
Benefits plan
Senior Product Owner ID71659
Senior Product Owner ID71659

AgileEngine • Braga

Híbrido
EUR 78 000 - 130 000
Professional growth
Competitive USD-based pay
Exciting projects
+1
Senior Product Owner ID71659
Senior Product Owner ID71659

AgileEngine • Porto

Presencial
EUR 90 000 - 130 000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Product Owner ID71659
Senior Product Owner ID71659

AgileEngine • Coimbra

Híbrido
EUR 104 000 - 156 000
Professional growth
Competitive compensation
Exciting projects
+1