Job Description:
We are looking for a seasoned DevSecOps Engineer to lead the design and implementation of cloud security processes and automation in a government environment. This role will collaborate closely with development and operations teams to deliver secure, efficient, and scalable cloud infrastructure
Key Responsibilities:
- Cloud & Infrastructure Management: Design, deploy, and maintain cloud environments on AWS using Terraform for Infrastructure-as-Code.
- Containerization & Orchestration: Build and manage containerized applications with Docker, Kubernetes, Kustomize, Helm, and ArgoCD for CI/CD automation.
- Monitoring & Logging: Implement observability solutions with Elasticsearch, Kibana, and Prometheus to ensure system health and performance.
- Development & Automation: Contribute to tooling and automation using Go, Python, and modern frontend frameworks (TypeScript, React, NextJS).
- Version Control & CI/CD: Manage pipelines and repositories with GitLab, ensuring secure and efficient delivery.
- Database Management: Administer and optimize PostgreSQL databases for high availability and performance.
- Production Support: Provide hands‑on support for production systems, ensuring uptime, resilience, and rapid incident response.
- Cybersecurity: Implement DevSecOps best practices, embedding security into every stage of the development lifecycle.
- Perform routine reviews and updates of security policies to stay ahead of emerging threats.
Required Skills & Qualifications:
- Proven expertise in DevSecOps and cloud security, with a track record of delivering secure solutions.
- Hands‑on experience in establishing and implementing cloud DevSecOps processes, policies, and automation frameworks.
- Strong proficiency in AWS, including command-line interface (CLI) usage and a wide range of cloud services.
- Skilled in Infrastructure-as-Code (IaC), with the ability to write and maintain Terraform scripts for resource provisioning and automation.
- Practical experience in cloud operations automation, such as updating IP addresses, managing API Gateway WAF rules, and configuring Route 53.
- Deep knowledge of security best practices, cloud compliance standards, and risk management methodologies.
- Excellent troubleshooting and problem‑solving skills, with the ability to resolve complex issues under pressure.