DevSecOps Engineer
Indexed description
Job Summary
We are seeking a DevSecOps Engineer to integrate security into our development and operations processes. The successful candidate will own secure CI/CD pipelines, implement automated security testing, and collaborate with cross-functional teams to embed security throughout the product lifecycle.
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines and infrastructure as code.
- Integrate automated security scanning, vulnerability management, and compliance checks into the software delivery lifecycle.
- Collaborate with development, security, and operations teams to define and enforce security standards and best practices.
- Monitor and respond to security incidents, perform root cause analysis, and drive remediation efforts.
- Ensure cloud environments are secure, compliant, and well-governed (IAM, network security, logging, and monitoring).
- automate configuration management, secrets handling, and incident response playbooks.
- 5-8 years of experience in [field]
- Strong experience with cloud platforms (e.g., AWS, Azure, GCP) and infrastructure as code (Terraform, CloudFormation).
- Proficient in securing CI/CD pipelines, container security, and orchestration (Kubernetes).
- Hands-on knowledge of security tooling (static/dynamic analysis, SAST/DAST, SCA) and vulnerability management.
- Familiarity with monitoring, logging, and incident response practices; ability to perform root cause analysis.
- Relevant security certifications (e.g., CISSP, CISM, CISA, CCSK, or cloud security certifications).
- Experience with DevSecOps in regulated industries and compliance frameworks (e.g., PCI DSS, SOC 2, ISO 27001).
- Scripting and automation skills (Python, Bash, PowerShell) and experience with security-focused governance tools.
- Security-minded engineering approach with a focus on automation and repeatability.
- Strong collaboration and communication skills; ability to translate security requirements to technical teams.
- Problem-solving mindset with the ability to prioritize and manage multiple initiatives.
- Proficiency in risk assessment, threat modeling, and vulnerability remediation strategies.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- Relevant certifications (e.g., AWS/Azure/GCP certifications, CISSP, CISM, CCSP) are a plus.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search