Skip to main content
Hanna Robulets Company
Scraped fromDjinniYesterday
DevopsSenior

Senior DevSecOps Engineer

AWSAzureTerraformKubernetesGitHub ActionsAzure DevOpsGitLab CICheckovTfsecOpa/RegoBicepCloudFormationSonarqubePrisma CloudWizSnykCrowdstrikeSentinel
Work Type
Remote
Job Type
-
Location
Worldwide
Salary
Not specified

About the Position

We are seeking a hands-on Senior DevSecOps Engineer with strong AWS and Azure experience to embed security directly into the engineering lifecycle. The role involves automating security tooling into CI/CD pipelines and building automated scaffolding for secure software delivery.

Responsibilities

  • CI/CD Security Automation: Design, build, and maintain secure deployment pipelines (e.g., GitHub Actions, Azure DevOps, GitLab CI). Integrate automated vulnerability scanning, secret detection, and software supply chain security (SCA) seamlessly into the developer workflow.
  • Policy-as-Code & Guardrails: Write, test, and deploy automated policy guardrails using Infrastructure as Code (IaC) linting and scanning tools (e.g., Checkov, Tfsec, OPA/Rego) to catch misconfigurations before they reach production.
  • Security Product Deployment: Automate the baking of EDR agents, vulnerability scanners, and monitoring tools into base machine images (AMIs, Azure Golden Images) and containerized base environments.
  • Vulnerability & Remediation Pipelines: Operationalize vulnerability management by building automated workflows that ingest findings from cloud security tools, prioritize them based on risk, and route them to engineering backlogs (e.g., Jira tracking).
  • Logging & SIEM Integration: Configure and automate the pipeline delivery of application, container, and infrastructure logs to central logging repositories and SIEM systems for real-time threat hunting.
  • Developer Enablement: Serve as a bridge between Security and Engineering, providing developer-friendly remediation guidance and creating reusable, secure-by-default code templates (Terraform modules, Helm charts).

Requirements

  • DevSecOps & CI/CD Pipelines: Deep, practical experience constructing and securing automated build/release pipelines at scale.
  • Multi-Cloud Platforms: Hands-on engineering experience configuring native security services and access controls in both AWS and Azure.
  • Infrastructure as Code (IaC): Advanced proficiency with Terraform or cloud-native tooling (Bicep, CloudFormation), focusing on modular design and immutable infrastructure.
  • Security Tooling Implementation: Direct experience implementing and maintaining security products across the lifecycle (e.g., SonarQube, Prisma Cloud, Wiz, Snyk, CrowdStrike, or Sentinel).
  • Container & Orchestration Security: Strong understanding of Kubernetes (EKS/AKS) security best practices, service meshes, and container runtime defense.
Senior DevSecOps Engineer
View Original