DevSecOps Engineer
Indexed description
DevSecOps Engineer / Senior DevSecOps Engineer
Requirements
* Experience in DevSecOps, Cloud Security, Application Security, or DevOps
* Hands-on experience working in AWS, Azure, Google Cloud, and on-prem environments
* Strong knowledge and hands-on experience in CI/CD pipelines and Secure SDLC processes
* Experience with security controls for source code, dependencies, Dockerfiles, container images, Helm charts, and Infrastructure as Code within the pipeline
* Knowledge of integrating and managing SAST, SCA, container security, IaC scanning, and similar controls into CI/CD processes
* Experience working with SonarQube, Fortify, or similar application security tools
* Evaluating, prioritizing, and managing remediation processes for findings resulting from security scans
* Command of security gate, quality gate, and pipeline policy approaches
* Strong technical knowledge in the Docker and Kubernetes ecosystem
* Command of IAM, secrets management, and privileged access management principles in multi-cloud / hybrid structures
* Experience with Git, Terraform, Helm, and similar DevOps / Infrastructure as Code technologies
* Technical competence in Linux systems, troubleshooting, and providing hands-on support to existing DevOps operations
* Ability to develop security controls not just by operating them, but with a mindset of automation, standardization, and continuous improvement
Preferred
* Experience in Prisma Cloud or similar CNAPP / CSPM / CWPP solutions
* Experience in CyberArk Conjur or similar PAM / secrets management solutions
* Experience in Kubernetes security, admission control, policy-as-code, and runtime security
* Ability to develop automation with Python, Bash, or PowerShell
* Experience in false-positive management, rule/policy tuning in DevSecOps tools, and optimizing security controls without disrupting developer experience
* Experience working with monitoring, logging, and observability tools
The profile we are looking for is a teammate who does not just use security tools; but can understand the existing DevSecOps pipeline structure, effectively manage SonarQube/Fortify and similar controls, integrate new security requirements into the pipeline, and directly contribute to DevOps operations when necessary.
"bgts INT"
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search