Tech Stack
AnsibleAWSAzureCloudDockerGoGoogle Cloud PlatformGrafanaJenkinsKubernetesPrometheusPythonSplunkTerraform
About the role
- Design and implement security automation in CI/CD pipelines for applications and infrastructure.
- Integrate static (SAST), dynamic (DAST), and dependency (SCA) security scanning tools.
- Collaborate with DevOps and engineering teams to embed security best practices from design to deployment.
- Manage secrets, IAM, and encryption policies across cloud environments (AWS, Azure, GCP).
- Define and enforce compliance standards (ISO, SOC2, GDPR, HIPAA).
- Build monitoring and alerting systems for threat detection and vulnerability management.
- Implement container and Kubernetes security (runtime protection, image scanning, RBAC).
- Support penetration testing and incident response processes.
- Conduct security training and awareness for developers and operations teams.
Requirements
- 5+ years of experience in DevOps or Security Engineering, with at least 2+ years in DevSecOps.
- Fluent English.
- Strong knowledge of CI/CD tools (Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps).
- Hands-on expertise with security tools (SonarQube, Snyk, Checkmarx, Aqua, Prisma, Twistlock).
- Solid understanding of cloud platforms (AWS, Azure, GCP) and their security services.
- Experience with infrastructure-as-code (Terraform, CloudFormation, Ansible) and policy-as-code (OPA, Sentinel).
- Knowledge of containerization and orchestration security (Docker, Kubernetes).
- Familiarity with monitoring and logging tools (ELK, Prometheus, Grafana).
- Strong scripting/programming skills (Python, Bash, Go).
- Experience defining/enforcing compliance standards (ISO, SOC2, GDPR, HIPAA).
- Experience with secrets management, IAM, and encryption policies.
- Experience supporting penetration testing and incident response processes.
- Nice to have: Security certifications (CISSP, CISM, OSCP, CCSP, AWS/Azure/GCP Security).
- Nice to have: Experience with zero-trust architectures, microsegmentation, and service mesh security (Istio, Linkerd).
- Nice to have: Familiarity with SIEM/SOAR platforms (Splunk, QRadar, Sentinel).
- Nice to have: Background in regulated industries (finance, healthcare, telecom).
- Nice to have: Contributions to security open-source projects or DevSecOps communities.
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
security automationCI/CDSASTDASTSCAcloud securityinfrastructure-as-codepolicy-as-codecontainer securityscripting
Soft skills
collaborationcommunicationtrainingawareness
Certifications
CISSPCISMOSCPCCSPAWS SecurityAzure SecurityGCP Security