Senior DevSecOps & Product Security Engineer

Doxis

Porto

Híbrido

EUR 70 000 - 110 000

Tempo integral

14 dias+
Gerador de candidaturas

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Private healthcare
Udemy memberships
Udemy Business access
Flexible hours & hybrid/remote

Resumo da oferta

Doxis is seeking an experienced Senior DevSecOps & Product Security Engineer to design, automate and operate security across our cloud platform and SDLC. You will integrate automated controls into CI/CD pipelines and support regulatory compliance.

You will work closely with engineering and cloud operations to mature security posture, implement guardrails, and drive secure software delivery with hands-on tooling and scripting.

Qualificações

  • 5+ years in Security Engineering or DevSecOps.
  • Experience securing cloud-native SaaS products and production cloud platforms.
  • Hands-on with CI/CD tools like GitHub Actions, Azure DevOps, GitLab CI or Jenkins.
  • Knowledge of IAM, encryption, secrets management, and vulnerability management.

Responsabilidades

  • Design and implement security controls across CI/CD pipelines.
  • Automate SAST, SCA, secret detection, container scanning, IaC and DAST.
  • Build policy-as-code, guardrails and automated compliance reporting.
  • Secure cloud infrastructure, Kubernetes environments and deployment processes.
  • Own vulnerability management, including scanning, remediation tracking and reporting.
  • Support secure coding practices, threat modelling and design reviews.
  • Assist with penetration testing, security assessments and audits.
  • Improve detection, logging and incident response capabilities.
  • Develop automation for evidence collection, reporting and dashboards.

Conhecimentos

Security Engineering
DevSecOps
Cloud Security
CI/CD
Threat Modelling

Ferramentas

Checkmarx
SonarQube
GitHub Advanced Security
Trivy
Snyk
Semgrep
OWASP ZAP

Descrição da oferta de emprego

We are looking for an experienced Senior DevSecOps & Product Security Engineer to help build, automate and operate security capabilities across our cloud platform, SDLC and CI/CD pipelines.

This is a hands-on role working closely with engineering, cloud operations and architecture teams to improve security posture, embed automated controls and support compliance with customer, contractual and regulatory requirements.

Key Responsibilities
  • Design and implement security controls across CI/CD pipelines
  • Automate SAST, SCA, secret detection, container scanning, IaC scanning and DAST where appropriate
  • Build policy-as-code, security guardrails and automated compliance reporting
  • Secure cloud infrastructure, Kubernetes environments and deployment processes
  • Improve IAM, privileged access management, MFA, networking and encryption standards
  • Own vulnerability management, including scanning, risk assessment, remediation tracking, patch coordination and reporting
  • Partner with development teams on secure coding standards, threat modelling, design reviews and software supply chain security
  • Support penetration testing, customer security assessments and audit preparation
  • Investigate security events, support incident response and improve detection, logging and monitoring
  • Develop automation for evidence collection, reporting, dashboards and security workflows
What We're Looking For
  • 5+ years' experience in Security Engineering, DevSecOps or Cloud Security
  • Experience securing cloud-native SaaS products and production cloud platforms
  • Strong knowledge of at least one major cloud platform: AWS, Azure or Google Cloud
  • Hands-on experience with CI/CD tools such as GitHub Actions, Azure DevOps, GitLab CI or Jenkins
  • Experience with security tools such as Checkmarx, SonarQube, GitHub Advanced Security, Trivy, Snyk, Semgrep or OWASP ZAP
  • Strong container and Kubernetes security knowledge, including Docker and Helm
  • Experience with IaC tools such as Terraform, Bicep, CloudFormation or Pulumi
  • Familiarity with IaC scanning tools such as Checkov, tfsec or Terrascan
  • Strong scripting skills in Python, PowerShell or Bash
  • Solid understanding of OWASP Top 10, Secure SDLC, threat modelling, Zero Trust, IAM, encryption, PKI, secrets management, SIEM, incident response and vulnerability management
  • Experience with frameworks such as ISO 27001, ISO 27002, NIST CSF, CIS Controls, SSDF or SOC 2
Nice to Have
  • Go programming experience
  • Experience with UK Government Security Policy Framework or NCSC Cloud Security Principles
  • Experience in government or regulated industry environments
About You

You are hands-on, pragmatic and automation-focused. You can work closely with engineering teams, communicate clearly, influence technical decisions and continuously improve how security is embedded into software delivery.

What Success Looks Like

In your first 12 months, you will have helped embed automated security testing into CI/CD pipelines, improved cloud security posture, reduced manual security work, strengthened vulnerability management and increased confidence in secure software delivery.

What We Offer
  • Private healthcare for you and your dependents.
  • Urban Sports Club & Udemy Business memberships covered by Doxis.
  • Access to Udemy Business.
  • Flexible working hours and a hybrid or remote working environment.
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

DevSecOps (Lisbon / Porto - Hybrid)
DevSecOps (Lisbon / Porto - Hybrid)

Claranet limited • Lisboa, Porto

Presencial
EUR 60 000 - 80 000
Integration into a dynamic and motivated team
Additional training
Salary package according to the role performed
Senior Application Security Engineer
Senior Application Security Engineer

Signify Technology • Lisboa

Presencial
EUR 70 000 - 110 000
Senior DevSecOps & Product Security Engineer - Remote
Senior DevSecOps & Product Security Engineer - Remote

Doxis • Porto

Híbrido
EUR 70 000 - 110 000
Private healthcare
Udemy memberships
Udemy Business access
+1
DevSecOps Engineer
DevSecOps Engineer

Richemont Iberia SL • Moscavide

Presencial
EUR 55 000 - 75 000
Application Security Engineer ID71662
Application Security Engineer ID71662

AgileEngine, LLC. • Coimbra

Teletrabalho
EUR 44 000 - 58 000
Professional growth
Competitive USD-based pay
Exciting projects
+1
DevSecOps Engineer
DevSecOps Engineer

Riskified • Lisboa

Presencial
EUR 50 000 - 70 000
Healthcare benefits
Flexible schedule
Wellness program
+2
Senior Cloud Security & DevSecOps Engineer
Senior Cloud Security & DevSecOps Engineer

1GLOBAL • Lisboa

Híbrido
EUR 90 000 - 130 000
Application Security Engineer Id71662
Application Security Engineer Id71662

Agileengine • Viseu

Híbrido
EUR 79 000 - 114 000
Mentorship & TechTalks
USD-based pay with education, fitness,
Team activity budgets
+1
Cloud Platform Engineer
Cloud Platform Engineer

Genesis • Braga

Híbrido
EUR 90 000 - 110 000
Senior Technical Program Manager ID70121
Senior Technical Program Manager ID70121

AgileEngine • Braga

Presencial
EUR 70 000 - 90 000
Professional growth with mentorship and personalized growth roadmaps
Competitive compensation with budgets for education and fitness
Exciting projects with Fortune 500 and top product companies
+1