A
Apprecode
DevopsSenior
Senior Cloud DevSecOps Engineer
AWSAzureTerraformCheckovTfsecOpa/RegoGitHub ActionsAzure DevOpsGitLab CIVaultAzure Key VaultKubernetesAWS EKSAksDockerPythonBashPowerShellSonarqubePrisma CloudWizSnykCrowdstrikeMicrosoft SentinelJiraSiemIAMRbacAws Security HubAzure DefenderSoc2Iso 27001Cis BenchmarksHelm
About the Position
We are looking for a seasoned Cloud DevSecOps Engineer to embed security into every stage of the development lifecycle. The role involves architecting infrastructure, automating security checks, and bridging Security with Engineering.
Responsibilities
- Architect and maintain fault-tolerant infrastructure across AWS and Azure using Terraform, with a focus on modular design and immutable infrastructure principles
- Implement automated IaC policy checks (Checkov, Tfsec, OPA/Rego) to surface misconfigurations as early as the code review stage
- Build and harden end-to-end CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI) with integrated SAST/DAST, container scanning, secret detection, and software composition analysis
- Apply zero-trust principles through a well-structured IAM strategy, RBAC, and centralized secrets management (HashiCorp Vault, Azure Key Vault)
- Deploy and secure containerized workloads on Kubernetes clusters (EKS / AKS)
- Automate the baking of EDR agents, vulnerability scanners, and observability tooling into golden base images (AMIs, Azure Golden Images)
- Continuously audit cloud posture via AWS Security Hub and Azure Defender, maintaining alignment with SOC2, ISO 27001, and CIS Benchmarks
- Build automated workflows that collect security findings, score them by risk, and route them into engineering backlogs (Jira)
- Centralize application, container, and infrastructure log delivery into SIEM systems to enable real-time threat detection
- Act as a bridge between Security and Engineering — delivering developer-friendly remediation guidance and maintaining reusable secure-by-default templates (Terraform modules, Helm charts)
Requirements
- 3+ years in Cloud Operations, DevOps, or DevSecOps with hands-on production experience across both AWS and Azure
- Proven track record of building and securing CI/CD pipelines at scale
- Strong proficiency with Terraform (modular architecture), and familiarity with Bicep or CloudFormation
- Scripting skills in Python, Bash, or PowerShell
- Solid understanding of Docker and Kubernetes (EKS/AKS): security hardening, service mesh, and container runtime defense
- Hands-on experience with security tooling such as SonarQube, Prisma Cloud, Wiz, Snyk, CrowdStrike, Microsoft Sentinel, or equivalents
- Practical knowledge of cloud network security, encryption, and end-to-end vulnerability management
- Nice-to-Have Certifications: Certified DevSecOps Professional (CDP) or Practical DevSecOps
- AWS Certified Security – Specialty / Azure Security Engineer Associate
- CKA or CKS (Kubernetes)
Senior Cloud DevSecOps Engineer
View Original