Tech Stack
CloudDockerJavaScriptKubernetesPythonTypeScript
About the role
- Deel is the all-in-one payroll and HR platform for global teams, supporting 150+ countries and a workforce of ~6,000
- We are seeking a DevSecOps Engineer to lead development, security, and infrastructure efforts as the product and customer base expand
- Security Automation: develop and maintain automated security tools and integrate scanners, static analysis, and vulnerability assessment into CI/CD
- Secure Infrastructure: design and implement secure cloud infrastructure, network architecture, access controls, encryption, and monitoring
- Continuous Monitoring: implement security monitoring, log analysis, intrusion detection, and system monitoring
- Secure Coding Practices: promote secure coding, conduct code reviews, and advise on security testing methodologies
- Collaboration and Communication: liaise between development, operations, and security teams to integrate security requirements
- Compliance and Auditing: assist in compliance assessments and audits, and provide documentation and evidence of security controls
Requirements
- 3+ years of relevant DevOps, SecOps, DevSec work experience in Production environments
- Software Development: basic programming skills and experience; familiarity with JavaScript, TypeScript, Python, version control (Git), CI/CD pipelines
- Security Knowledge: familiarity with security principles, OWASP Top 10, secure coding practices, encryption, authentication, access control, and security testing methodologies
- DevOps Practices: proficiency with CI/CD pipelines, infrastructure automation (Docker, Kubernetes), configuration management, and monitoring/observability
- Risk Assessment and Mitigation: threat modeling, risk assessment techniques, vulnerability management, and incident response planning
- Collaboration and Communication: ability to work closely with developers, security professionals, and operations personnel
- Automation and Tooling: experience with security scanners (SAST, DAST), vulnerability management systems, log analysis tools, and security-focused frameworks
- Security Certifications (desirable): CSSLP, CEH, CISSP