Tech Stack
AWSAzureCloudGoogle Cloud PlatformGrafanaGroovyJenkinsKafkaKubernetesPrometheusPythonTerraform
About the role
- The objective of the DevSecOps Engineer role is to integrate robust security measures into the software development lifecycle, ensuring that our AWS cloud infrastructure and CI/CD pipelines are secure, compliant, and efficient.
- Enhance the security posture of systems through implementing infrastructure as code, automated security checks, and continuous monitoring.
- Foster a culture of security awareness and continuous improvement within development and operations teams.
- Build & Maintain CI/CD Pipelines Develop robust, scalable pipelines using Jenkins, ArgoCD, GitLab CI/CD, and GitHub Actions for applications and infrastructure components.
- Support GitOps Deployments Implement and manage GitOps workflows using ArgoCD for Kubernetes-based environments.
- Automation & Integration Integrate testing, vulnerability scanning (SAST/DAST), artifact promotion, and policy enforcement tools into the pipeline (e.g., Trivy, SonarQube, sigstore).
- Infrastructure-as-Code Alignment Work with Terraform, Helm, and YAML configurations to automate and manage infrastructure provisioning and deployment.
- Security & Compliance Automation Enforce DevSecOps best practices: manage secrets securely, implement image and code scanning, and support policy-as-code using OPA or similar tools.
- Metrics & Monitoring Track pipeline health, deployment frequency, rollback events, and MTTR using tools like Prometheus and Grafana.
- Collaborate Across Teams Partner with SRE, QA, platform, and application teams to align CI/CD workflows with operational and delivery goals.
Requirements
- +90% English written and oral (at least B2 level) with excellent communication skills
- 5+ years of experience in DevOps or Platform Engineering roles with direct CI/CD pipeline ownership.
- Proven hands-on experience with Terraform, AWS, Cloudify, Keycloak, Kafka, Patroni, Harbor, Shell Scripts and Python scripts.
- Proven hands-on experience with Jenkins, ArgoCD, and GitOps concepts.
- Experience deploying to Kubernetes environments and managing Helm/Terraform configurations.
- Familiarity with pipeline security practices (e.g., CVE scanning, artifact signing, least-privilege IAM).
- Strong skills ( Bash , Groovy , Python ).
- Experience working in cloud environments ( AWS , GCP , or Azure ).