Senior DevSecOps Engineer

Jobtailor

Cape Town

On-site

ZAR 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an Application Security professional to own security in the SDLC and CI/CD pipelines. You will integrate security controls (SAST/DAST/SCA), support threat modeling, and collaborate with architecture teams to ensure secure design and compliance.

You will assist developers with vulnerability triage and remediation, tune tools to minimize false positives, and contribute to audits and evidence generation. Container security and cloud-native practices are central to the role.

Qualifications

  • Strong grounding in application security concepts and secure coding practices.
  • Experience with SAST, DAST, SCA and software supply-chain security.
  • Ability to influence engineering teams through collaboration and credibility.
  • Hands-on expertise with containers and orchestration platforms like Docker and Kubernetes.

Responsibilities

  • Own security controls within CI/CD pipelines and secure SDLC practices.
  • Support threat modeling and secure design reviews with architecture teams.
  • Assist with vulnerability triage, remediation, and evidence generation for audits.
  • Configure and maintain security tooling integrations in CI/CD environments.

Skills

Application Security Concepts
CI/CD Security
SAST
DAST
SCA
Container Security

Tools

GitHub Actions
GitLab CI
Jenkins
Azure DevOps
Docker
Kubernetes
Terraform
Bicep
CloudFormation

Job description

You’ll take ownership of work that gives us our competitive edge, including: Development and Application Security-by-Design
Integrate and operate application security controls within CI/CD pipelines, including: Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Secrets detection and dependency risk scanning
Support secure SDLC practices such as: Branch protection and quality gates, Secure build and release controls, Artifact integrity and validation checks
Assist with threat modelling and secure design reviews in collaboration with architecture teams.
Support developers in vulnerability triage and remediation.
Tune security tools to reduce false positives and developer friction.
Support audit, compliance, and evidence generation activities.
Participate in security incident investigation related to application flaws.
Ensure secure, compliant approaches are the default and easiest options for development teams to adopt.
Configure and maintain security tooling integrations within CI/CD systems (e.g. GitHub Actions, GitLab CI, Jenkins, Azure DevOps) under agreed architectural standards
Ensure security controls operate consistently across teams and repositories.
Define and document DevSec security standards, patterns, and decisions.
Provide evidence and control mappings to support audits, risk assessments, and regulatory reviews.
Identify and track DevSec-related risks and technical debt, driving remediation through process improvements rather than manual controls.
Influence security outcomes through collaboration and technical leadership rather than enforcement.
Contribute to security enablement, awareness, and uplift initiatives focused on cloud-native and container security practices.

Requirements
  • Clear, confident communication (written and verbal), and the ability to breakdown complex ideas
  • A collaborative mindset, working smoothly with cross-functional teams to hit shared goals
  • Strong organisational skills and the ability to manage multiple projects without dropping the ball
  • Exceptional attention to detail and a commitment to high-quality work
  • Adaptability - you stay sharp, productive and positive in fast-moving environments
  • Strong grounding in application security concepts. Secure coding knowledge (OWASP Top 10, API security, dependency risk).
  • Strong knowledge of SAST, DAST, SCA, and software supply-chain security concepts.
  • Strong advocate for enablement-first security.
  • Ability to influence engineering teams through collaboration and technical credibility.
  • Hands-on expertise with containers and orchestration platforms (e.g. Docker, Kubernetes).
  • Demonstrated experience implementing container security across build, registry, and runtime.
  • Proven experience securing CI/CD pipelines and developer toolchains.
  • Knowledge of: Infrastructure as Code (Terraform, Bicep, CloudFormation, etc.)
  • Secrets and key management
  • Cloud identity and access management
  • Solid understanding of information security frameworks (e.g. ISO 27001).
  • Experience operating in regulated or audited environments.
  • Able to design controls that are auditable without slowing delivery.
Core Competencies

Demonstrates expertise in Application Security, including Secure SDLC practices and CI/CD pipeline security. Proficient in threat modeling, vulnerability management, and security tooling integration, with a strong focus on collaboration and enablement within cross-functional teams.

Highest-signal resume keywords
  • Application Security Concepts
  • CI/CD Pipeline Security
  • SAST, DAST, SCA
  • Container Security
  • Infrastructure as Code
ATS Optimization Keywords
Hard Skills
  • Secure Coding Knowledge
  • Threat Modeling
  • Vulnerability Triage
  • Security Tooling Integration
  • Secrets Management
  • Cloud Identity and Access Management
  • Information Security Frameworks
  • Container Orchestration
  • DevSec Standards Documentation
  • Audit and Compliance Support
Soft Skills
  • Clear Communication
  • Collaborative Mindset
  • Organizational Skills
  • Attention to Detail
  • Adaptability
Industry Keywords
  • Application Security
  • Secure SDLC
  • DevSecOps
  • Regulated Environments
  • ISO 27001
Tools & Technologies
  • GitHub Actions
  • GitLab CI
  • Jenkins
  • Azure DevOps
  • Docker
  • Kubernetes
  • Terraform
  • Bicep
  • CloudFormation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

Jobtailor • Randburg

On-site
ZAR 900,000 - 1,200,000
DevSecOps Engineer
DevSecOps Engineer

Boardroom Appointments • Cape Town

On-site
ZAR 500,000 - 700,000
Senior DevSecOps Engineer - Secure CI/CD & Cloud-native
Senior DevSecOps Engineer - Secure CI/CD & Cloud-native

Jobtailor • Cape Town

On-site
ZAR 600,000 - 900,000
DevOps Engineer
DevOps Engineer

PwC South Africa • City of Johannesburg Metropolitan Municipality

On-site
ZAR 900,000 - 1,200,000
Lead DevSecOps / Azure Architect
Lead DevSecOps / Azure Architect

Blue Pearl HQ • Johannesburg

On-site
ZAR 900,000 - 1,350,000
Senior Cybersecurity Engineer - Compliance & Technology
Senior Cybersecurity Engineer - Compliance & Technology

ATS Client • Sandton

On-site
ZAR 900,000 - 1,600,000
Senior DevOps Engineer
Senior DevOps Engineer

Blue Pearl HQ • Johannesburg

On-site
ZAR 600,000 - 850,000
Senior DevSecOps Engineer: Secure SDLC Innovator
Senior DevSecOps Engineer: Secure SDLC Innovator

Betway Group • Cape Town

On-site
ZAR 900,000 - 1,200,000
Group Life Cover
Funeral Fund Benefit
Income Continuation Benefit
+2
IT Security Specialist Talent Pool
IT Security Specialist Talent Pool

Mr Price Group • Durban

On-site
ZAR 600,000 - 800,000
Senior DevOps Engineer
Senior DevOps Engineer

ATS Client • Johannesburg

On-site
ZAR 900,000 - 1,300,000