DevSecOps & Infrastructure Security Engineer

NewMind AI

Şişli

On-site

TRY 180,000 - 300,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

New Mind AI is seeking an experienced DevSecOps & Infrastructure Security Engineer to reinforce security across SaaS platforms, on-prem deployments, and Kubernetes/OpenShift environments. You will own security initiatives end-to-end, assess architectures, and guide engineering teams on mitigations.

The role requires 5+ years in security-focused roles, strong Linux/network security knowledge, hands-on Kubernetes/OpenShift, and expertise in CI/CD security, SAST, SCA, and secret management.

Qualifications

  • 5+ years of professional experience in DevSecOps, Infrastructure Security, Platform Security, Cloud Security, or related fields.
  • Strong Linux and network-security knowledge, with production experience in Kubernetes/OpenShift and CI/CD security.
  • Practical experience with SAST, SCA, secret scanning, vulnerability-management processes, IAM, PAM, RBAC, TLS/mTLS, PKI, and CIS CIS Benchmarks.
  • Familiarity with Policy & Supply Chain tooling (Kyverno, OPA Gatekeeper, Cosign) and runtime security (Falco, Tetragon).
  • Experience with automation (Ansible, Terraform) and monitoring (Splunk/SIEM).

Responsibilities

  • DevSecOps & Secure SDLC: Improve security controls across CI/CD, SAST, SCA, secret scanning, container/IaC scanning, SBOM; build automated security gates.
  • Kubernetes/OpenShift Security: Assess environments, improve RBAC, PSP, NetworkPolicy and namespace isolation; policy-as-code with Kyverno/OPA Gatekeeper.
  • Infrastructure & Network Security: Harden Linux production systems, assess segmentation, manage TLS/mTLS, PKI, certificate lifecycle, contribute to Zero Trust.
  • IAM, PAM & Secrets: Review auth mechanisms, manage secrets (CyberArk, Vault), secure secret distribution and rotation.
  • SaaS & On-Premises Security: Evaluate tenant isolation, data-access risks, blast radius, and lateral movement.
  • Vulnerability Management & Incident Response: Prioritize vulnerabilities, investigate incidents, perform root-cause analysis.
  • Security Architecture: Review services, model attack surfaces, perform threat modeling, validate controls.

Skills

Linux security
Kubernetes/OpenShift
CI/CD security
Threat modeling
OWASP Top 10

Tools

Kubernetes
OpenShift
Helm
Trivy
SonarQube
Semgrep
Kyverno
OPA Gatekeeper
Cosign
Falco
Tetragon
CyberArk
Vault
Ansible
Terraform
Splunk

Job description

I - Who We Are?

New Mind AI is an innovative and pioneering company specializing in leveraging big data through a comprehensive and holistic approach. From data digitization and classification to deriving meaningful insights and extracting actionable outputs, we employ advanced taxonomies and ontologies to organize data in a structured and insightful manner, creating a semantic layer to better understand corporate data. Our mission extends beyond mere data structuring; we empower companies to transform their data into actionable insights, facilitating dynamic corporate governance. With over 300 task-oriented and domain-specific AI models, built using an orchestration of experts framework, we provide robust solutions for dynamic corporate governance. By implementing dynamic knowledge network structures, we develop advanced AI models that ensure effective management of corporate data in the business world. Our expertise spans AI-driven business solutions, including AI legal tech products, excelling in natural language processing, deep learning, machine learning, data analysis, and data visualization. Headquartered in YTÜ Teknopark, Maslak, Istanbul, and operating four specialized laboratories—Data Visualization Lab in India, Data Taxonomy Lab in Bomonti, and Big Data and Legal Tech Labs in Maslak—we are leaders in big data analysis in Türkiye and beyond. Our flagship dynamic knowledge management platforms, Mecellem, Malumat, and Mahfuz, empower professionals across various industries by streamlining complex tasks, optimizing decision-making, and managing business risks with precision. Through our cutting-edge AI tools, including Generative AI, LLMs, text-to-speech and speech-to-text, image recognition, voice recognition, function call, graphRAG, OCR, blockchain and RAG, we set new standards in business technology. We deliver smarter, more dynamic solutions for the business world, both in Türkiye and internationally.

II - Who We Are Looking For?

We are looking for an experienced DevSecOps & Infrastructure Security Engineer to strengthen the security of our SaaS platforms, enterprise customer on-premises deployments, Kubernetes/OpenShift environments, CI/CD pipelines, and production infrastructure. The ideal candidate will have 5+ years of experience and go beyond operating security tools or merely forwarding vulnerability reports. We expect someone who can assess systems from a security perspective, proactively identify risks, propose practical solutions, and take end-to-end ownership of security initiatives. You must be comfortable challenging existing architectures when necessary, evaluating potential attack scenarios, and providing technically sound security guidance to engineering teams.

III - What Will Be Your Responsibilities?
  • (i) DevSecOps & Secure SDLC: Integrate and continuously improve security controls across CI/CD pipelines, implement SAST, SCA, secret scanning, container/IaC scanning, and SBOM processes, and build automated security gates to prevent risks from reaching production.
  • (ii) Kubernetes & OpenShift Security: Perform security assessments of Kubernetes/OpenShift environments, improve RBAC, Pod Security Standards, NetworkPolicy, and namespace isolation controls, and implement Policy-as-Code using tools like Kyverno or OPA Gatekeeper.
  • (iii) Infrastructure & Network Security: Perform security hardening of Linux production systems, assess network segmentation, implement TLS/mTLS, PKI, and certificate lifecycle processes, and contribute to Zero Trust and Least Privilege architectures.
  • (iv) IAM, PAM & Secrets: Review authentication and authorization mechanisms, integrate and operate secrets-management solutions (e.g., CyberArk, HashiCorp Vault), and implement secure secret distribution and rotation processes to prevent credential exposure.
  • (v) SaaS & On-Premises Security: Assess SaaS environments for tenant isolation and data-access risks, evaluate blast radius and lateral-movement scenarios, and define security requirements for enterprise customer on-premises deployments.
  • (vi) Vulnerability Management & Incident Response: Prioritize vulnerabilities based on exploitability, business impact, and compensating controls rather than just CVSS scores, investigate suspicious events, and actively participate in technical incident analysis and root-cause analysis.
  • (vii) Security Architecture: Review new services and infrastructure designs, analyze attack surfaces and trust boundaries, participate in threat-modeling activities, and validate the actual effectiveness of implemented security controls.
IV - What Is Required from You?
  • (i) Experience: 5+ years of professional experience in DevSecOps, Infrastructure Security, Platform Security, Cloud Security, or related fields.
  • (ii) Technical Expertise: Strong Linux and network-security knowledge, accompanied by production experience with Kubernetes and/or OpenShift, as well as hands‑on experience with CI/CD security and Secure SDLC practices.
  • (iii) Security Knowledge: Practical experience with SAST, SCA, secret scanning, vulnerability‑management processes, IAM, PAM, RBAC, TLS/mTLS, PKI, and a strong understanding of OWASP Top 10, CIS Controls, and CIS Benchmarks.
  • (iv) Relevant Technologies: Proficiency with platforms (Kubernetes, OpenShift, Helm), DevSecOps tools (Trivy, SonarQube, Semgrep), Policy & Supply Chain (Kyverno, OPA Gatekeeper, Cosign), Runtime Security (Falco, Tetragon), IAM & Secrets (CyberArk, Vault), Automation (Ansible, Terraform), and Monitoring (Splunk/SIEM).
  • (v) Skills: Ability to assess systems from both defensive and attacker perspectives, strong troubleshooting skills, and the capability to independently identify security risks, explain their potential impact (e.g., attack paths, affected systems), and recommend practical technical mitigations.
  • (vi) Nice to Have: CISSP, CKS, CCSP, SSCP, Security+, or equivalent security certifications; experience with enterprise IAM/PAM, penetration‑test remediation, Service Mesh / mTLS, multi‑cluster Kubernetes security, or AI/ML and GPU infrastructure security.
V - Why Work at New Mind AI?

New Mind AI offers a unique opportunity for ambitious young professionals seeking to make a real impact in the rapidly growing field of AI. As a company at the forefront of AI innovation, we are driven by a strong mission to empower businesses with actionable insights derived from data. This translates to a dynamic and stimulating work environment where you will be challenged to think critically, develop your skills, and contribute to groundbreaking projects. Here are some key reasons why New Mind is an ideal place for young talent:

  • (i) be a part of something bigger: Our work goes beyond simply developing AI models. We are shaping the future of business and helping organizations navigate the complex world of data‑driven decision‑making;
  • (ii) work with leading experts: You will be surrounded by a team of passionate and knowledgeable individuals who are experts in their fields. This collaborative environment fosters continuous learning and growth;
  • (iii) gain valuable experience: You will have the opportunity to work on diverse projects, utilizing cutting‑edge AI tools and technologies, including Generative AI, LLMs, and more;
  • (iv) make a real difference: Your contributions will directly impact our company's growth and success, contributing to the advancement of AI technology and its positive impact on the world;
  • (v) global reach: As a company with a global presence, you will be exposed to a diverse range of perspectives and opportunities to work with clients and partners from around the world;
  • (vi) invest in your future: New Mind is committed to supporting its employees' professional development and offers opportunities for growth within the company.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps & Infrastructure Security Engineer
DevSecOps & Infrastructure Security Engineer

New Mind BYS • Şişli

On-site
TRY 240,000 - 420,000
Senior Machine Learning Engineer
Senior Machine Learning Engineer

NewMind AI • Şişli

On-site
TRY 350,000 - 700,000
Senior Full Stack Developer
Senior Full Stack Developer

New Mind BYS • Şişli

On-site
TRY 360,000 - 600,000
DevOps Engineer at NewMind AI
DevOps Engineer at NewMind AI

NewMind AI • Şişli

On-site
TRY 900,000 - 1,300,000
Legal Engineer
Legal Engineer

New Mind BYS • Şişli

Hybrid
TRY 180,000 - 300,000
Senior Machine Learning Engineer
Senior Machine Learning Engineer

New Mind BYS • Şişli

On-site
TRY 550,000 - 800,000
Global reach
Collaborative culture
Growth opportunities
+1
Senior DevSecOps & Cloud Security Engineer
Senior DevSecOps & Cloud Security Engineer

New Mind BYS • Şişli

On-site
TRY 240,000 - 420,000
Product Owner
Product Owner

New Mind BYS • Şişli

Hybrid
TRY 60,000 - 110,000
Senior DevSecOps & Infrastructure Security Engineer
Senior DevSecOps & Infrastructure Security Engineer

NewMind AI • Şişli

On-site
TRY 180,000 - 300,000
Forward Deployed AI Engineer
Forward Deployed AI Engineer

Digitopia Global Consulting Limited • Fatih

Hybrid
TRY 700,000 - 1,200,000
Stock options
Hybrid working
Flexible hours
+1