DevSecOps Engineer
Indexed description
Key Responsibilities
- Integrate automated security testing (SAST, DAST, SCA, secrets scanning, container security scanning) into CI/CD pipelines and enforce policy-as-code gates.
- Design, build, and maintain secure infrastructure using Infrastructure as Code (Terraform, CloudFormation, or similar), following least-privilege and defense-in-depth principles.
- Harden containerized and serverless workloads (Docker, Kubernetes) and implement runtime security monitoring.
- Manage secrets, keys, and certificates using tools such as HashiCorp Vault, AWS Secrets Manager.
- Triage, prioritize, and remediate vulnerabilities in partnership with development teams; track findings to closure and reduce mean-time-to-remediate.
- Build security automation and tooling to reduce manual toil and provide self-service guardrails for engineers.
- Monitor cloud environments for misconfigurations and threats using CSPM/CNAPP tooling and centralized logging (SIEM).
- Contribute to incident response: detection, investigation, containment, and post-incident reviews.
- Support compliance and audit efforts (SOC 2, ISO 27001, PCI-DSS, HIPAA, or similar) by codifying and evidencing controls.
Required Qualifications
- 4+ years of experience in DevSecOps, SRE, security engineering, or a related field, with demonstrable security responsibilities.
- Hands-on experience with at least one major cloud provider (AWS, Azure, or GCP) and its native security services.
- Proficiency with CI/CD platforms (GitHub Actions, GitLab CI, Jenkins,.
- Strong scripting/automation skills in Python, Bash, Go, or comparable languages.
- Working knowledge of Infrastructure as Code and configuration management.
- Familiarity with container orchestration (Kubernetes) and container security practices.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure software development practices.
- Experience integrating and interpreting output from security scanning tools.
- Strong understanding of Security secOps tools, SonarQube, twist lock, hashi corp vault
Preferred Qualifications
- Relevant certifications (CKA,AWS Security Specialty, CKS, Any relevant secOps certification..
- Experience with policy-as-code frameworks (OPA/Rego, Sentinel).
- Exposure to compliance frameworks and audit processes.
- Threat modeling and application security experience.
- Familiarity with observability and SIEM platforms.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search