DevSecOps Senior Engineer
Indexed description
Our journey, which began in 1979, has grown into a strong logistics network that delivers more than 1 million shipments daily across Türkiye, with 13 Regional Directorates, 28 Transfer Centers, nearly 1,000 branches, a fleet of 3,000 vehicles, and a team of 14,000 employees. As a subsidiary of Austrian Post Group, we continue our operations with international strength while investing in technology and innovation through Aras Digital, expanding beyond borders through Aras Global, and supporting the unifying power of sports through our Aras Kargo Women's Volleyball Team.
With our renewed identity, experience, and energy, we are setting our course toward the future. If you would like to grow, develop, and take a strong step forward in your career on this journey with us, we would be delighted to welcome you to our team.
We are looking for a Senior DevSecOps Engineer with at least 5 years of experience specializing in security automation, Azure Cloud, and hybrid (On-Premise) environments. This role is a critical intersection of technical execution and strategic governance, encompassing tasks such as integrating SAST/DAST/SCA into CI/CD pipelines, securing Kubernetes ecosystems, and leading ISO 27001 / NIS2 compliance programs.
Job Description:
- Defining and implementing security controls and processes within the Secure Software Development Lifecycle (SDLC) in collaboration with development, operations, and DevOps teams.
- Managing security tools integrated into CI/CD processes, including SAST (Static Application Security Testing), SCA (Software Composition Analysis), DAST (Dynamic Application Security Testing), and CS (Container Security), as well as planning for tools not yet integrated, in coordination with DevOps teams.
- Designing and maintaining processes for the automatic detection, validation, and reporting of application security vulnerabilities within the company's infrastructure.
- Ensuring the management of application security orchestration platforms in cooperation with relevant teams.
- Securing the deployment of applications developed in container, Kubernetes, and cloud environments.
- Closely monitoring global security incidents and implementing necessary measures to prevent similar incidents within the company.
- Collaborating with Security Assurance and Information Security teams to improve missing security controls.
- Planning and implementing activities to raise security awareness in partnership with external resources, universities, NGOs, and industry associations.
- Evaluating tools for automating, reporting, and monitoring security tests, ensuring their adoption and use within the company.
- Lead and maintain ISO 27001 and NIS2 compliance programs.
- Develop, implement, and maintain information security policies, procedures, and guidelines.
- Coordinate internal and external security audits and assessments.
- Support risk management, vendor assessments, and security awareness training.
- Ensure business continuity, perform disaster recovery tests in collaboration with stakeholders.
Required Qualifications:
- Over 5 years of experience in security automation, software development processes, and DevSecOps.
- Expertise in application security tools and technologies (SAST, DAST, SCA, CS, etc.).
- Experience in integrating security into CI/CD tools (Jenkins, Github etc.).
- Knowledge of Kubernetes, container technologies, and cloud security.
- Experience in designing, managing, and automating infrastructure on cloud platforms (Azure Cloud, On-Premise).
- Proficiency in IaC tools (Terraform, Ansible etc.).
- Expertise in managing and optimizing Linux-based systems.
- Strong analytical thinking and problem-solving skills.
- Relevant certifications are preferred (CISSP, CISM, OSCP, CEH, etc.).
- Comprehensive knowledge and experience with the Azure Cloud platform.
- Proficiency in English (written and spoken)
- Proven experience in network security, information security, audit, and compliance.
- Strong working knowledge of ISO 27k Certifications and NIS2 directive.
- Apply and maintain security benchmarking standards (e.g., CIS Benchmarks, NIST CSF, ISO 27002, OWASP ASVS) across systems and infrastructure.
- Experience with SIEM, XDR and SOAR or related security tools.
- Understanding identity access management monitoring.
- Experience participating in security testing and resilience exercises.
- Ability to balance technical problem-solving with governance and process work.
- Ability to take ownership of security initiatives and deliver measurable results.
- Strong collaboration skills, with the ability to work effectively across multiple teams and stakeholders.
What Awaits You at Aras?
With our values of “We Are Aras: Purpose, Performance, and Joy,” we focus on people, society, and creating together. We offer an inclusive culture that supports the well-being, development, and work-life balance of our employees in every aspect. In this work experience, where you will feel valued and ready for the future:
• You become part of a flexible and balanced working experience (benefits such as a hybrid working model for office employees, flexible working hours, early finish on Fridays, and taxi transportation for Headquarters employees).
• You can create time for the special moments in your life (practices such as birthday leave and 30 days of paternity leave).
• You benefit from comprehensive fringe benefits that support your well-being and safety (the Meditopia app, meal card, supplementary health insurance, life insurance, and personal accident insurance).
• You can strengthen your competencies through continuous learning and development opportunities (technical and behavioral online training through Aras AkademiGO, leadership and talent programs, English language training, and postgraduate education support).
• You become part of a strong team culture that focuses on collaboration, recognition, and inclusiveness, while taking ownership and responsibility.
Aras Digital is an equal opportunity employer. We value diversity and are committed to creating an inclusive working environment for all employees. All qualified applicants are encouraged to apply regardless of gender, age, disability, or background.
You may visit the link to reach our data privacy policy:
https://www.arasdx.com/kvkk/İşe%20Alım%20Süreçlerine%20Yönelik%20Aydınlatma%20Metni.pdf
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search