
DevSecOps
Gedanken - GCertifica
full-time
Posted on:
Location Type: Remote
Location: Brazil
Visit company websiteExplore more
About the role
- Work cross-functionally with teams, promoting a DevSecOps culture throughout the entire development lifecycle;
- Implement and monitor security controls for applications, APIs, infrastructure, and cloud environments;
- Support the evolution of security practices without compromising the teams' agility.
- Enhance pipelines and processes with a focus on automation, quality, and security;
- Support the implementation of secure CI/CD and versioning best practices;
- Contribute to the continuous improvement of the platform's infrastructure and architecture.
- Manage identity and access (IAM), including authentication and authorization;
- Work with tools such as Keycloak and integrations between systems;
- Ensure security best practices for APIs and integrations.
- Support incident troubleshooting and root cause analysis;
- Propose and implement preventive improvements;
- Document standards, processes, and best practices for the teams;
- Assist squads in adopting more secure and efficient practices.
Requirements
- Experience working as a DevSecOps engineer or in closely related roles;
- Hands-on experience with Google Cloud Platform (GCP);
- Practical knowledge of Kubernetes and administration of Linux environments;
- Experience with API and integration security;
- Experience with identity and access management (IAM);
- Knowledge of GitHub and versioning and automation best practices;
- Familiarity with applications developed in Python/Django and PostgreSQL databases;
- Mandatory knowledge of Keycloak.
- Preferred/Additional qualifications:
- Experience in startups or fast-growing environments;
- Experience with observability, system hardening, secrets management, and access policy enforcement;
- Experience with infrastructure-as-code and CI/CD;
- Knowledge of security practices in pipelines;
- Architectural mindset with a focus on scalability and resilience.
Benefits
- Allowance
- Profit-sharing (PLR) according to current policy
- Paid time off
- Birthday day off
- 3-year passport
- Maternity and paternity leave
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
DevSecOpssecurity controlsCI/CDKubernetesLinux administrationAPI securityidentity and access managementinfrastructure-as-codePythonPostgreSQL
Soft Skills
cross-functional collaborationagilitycontinuous improvementtroubleshootingroot cause analysisdocumentationprocess improvementefficiency