DevSecOps Engineer - Job DescriptionJob TitleDevSecOps EngineerJob SummaryWe are looking for an experienced
DevSecOps Engineer to integrate security practices throughout the software development and deployment lifecycle. The role involves building secure CI/CD pipelines, automating infrastructure and security testing, managing cloud environments, and identifying and remediating vulnerabilities.
Key Responsibilities- Design, implement, and maintain CI/CD pipelines with security controls.
- Integrate DevSecOps practices into development, testing, deployment, and operations.
- Automate security scanning such as:
- SAST - Static Application Security Testing
- DAST - Dynamic Application Security Testing
- SCA - Software Composition Analysis
- Container security scanning
- Infrastructure-as-Code security scanning
- Implement and manage DevOps tools such as Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, or similar.
- Manage cloud infrastructure across AWS, Azure, or GCP.
- Implement Infrastructure as Code using Terraform, CloudFormation, or Ansible.
- Secure containerized applications using Docker and Kubernetes.
- Monitor applications and infrastructure for security threats and vulnerabilities.
- Perform vulnerability assessment, remediation, and security compliance activities.
- Implement secrets management using tools such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault.
- Configure IAM, RBAC, authentication, authorization, and least-privilege access.
- Integrate security gates into CI/CD pipelines to prevent vulnerable code from reaching production.
- Collaborate with developers, QA, DevOps, cloud, and security teams.
- Automate security and compliance checks wherever possible.
- Investigate security incidents and support root-cause analysis.
- Maintain security documentation, standards, and operational procedures.