Senior DevSecOps Engineer
Indexed description
What Will You Do
DevOps & Infrastructure Engineering
- Tune and configure servers, clusters, and containers appropriately to ensure high availability, performance, and scalability.
- Build tools and automation to reduce occurrences of errors, optimize system reliability, and improve customer experience.
- Perform root cause analysis (RCA) for production errors, investigate incidents, and resolve complex technical issues.
- Design, implement, and maintain procedures for system troubleshooting, monitoring, and automated visualization.
- Maintain comprehensive technical documentation for system architecture, operational procedures, and emergency response plans.
- DevSecOps Integration: Embed security tools, static/dynamic code analysis (SAST/DAST), and automated vulnerability scanning directly into CI/CD pipelines.
- Security Testing & Code Reviews: Perform ongoing security testing, penetration testing, and code reviews to identify and improve software security posturing.
- System & Cloud Hardening: Implement, test, and operate advanced security techniques, access controls, network segmentation, and encryption strategies in compliance with a technical reference architecture.
- Incident Response & Threat Mitigation: Provide engineering designs for new software solutions to help mitigate security vulnerabilities and act as a key responder to security incidents.
- Governance & Advisory: Consult team members on secure coding practices, zero-trust architecture, and stay updated with the latest tools, security frameworks, and threat vectors.
- Education & Experience: Bachelor's Degree in Computer Science, Computer Engineering, Cybersecurity, or a relevant field. Proven experience as a Senior DevOps, Infrastructure Engineer, DevSecOps Engineer, or Security Engineer.
- Security & Cryptography Expertise: Detailed technical knowledge of standards, frameworks, and capabilities for authentication and authorization (OAuth, SAML, IAM), applied cryptography, threat modeling, security vulnerabilities, and remediation (OWASP Top 10).
- Scripting & Development: Strong proficiency in Ruby, Python, Go, or .NET, alongside advanced Bash scripting for automation and security orchestration.
- Database & Systems: Working knowledge of databases and SQL, especially production-level tuning, access security, and data encryption at rest/in transit.
- Containerization & CI/CD: Hands-on mastery of Docker, Kubernetes, CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins), Infrastructure as Code (Terraform/Ansible), and cloud-native security tools.
- Network & Web Protocols: Adequate knowledge of web-related technologies (Web Applications, Web Services, SOA), network/web protocols (TLS/SSL, WAF, VPNs), and Load Balancing / Async Queue setups.
- Security & Observability Tools: Proficiency in monitoring/APM tools (e.g., Datadog, Prometheus, Grafana, ELK) combined with SIEM, vulnerability scanners (e.g., SonarQube, Trivy, Snyk), and log auditing tools.
- Mindset: Strong passion for security research, continuous learning, and driving a proactive security culture across engineering teams.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search