Назад
Company hidden
12 часов назад

DevSecOps Engineer (AWS)

Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Romania
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
DevSecOps Engineer (AWS): Designing and implementing cloud security controls, automated security testing, and enterprise DevSecOps architectures across AWS, CI/CD pipelines, containers, and Kubernetes with an accent on security automation, vulnerability management, and compliance. Focus on integrating SAST, DAST, SCA, container scanning, and infrastructure security checks, while establishing secure engineering standards and maintaining audit readiness.

Location: Bucharest, Romania; hybrid workplace

Company

hirify.global operates in software development and is hiring for a security-focused engineering role.

What you will do

  • Design and implement cloud security controls across AWS, covering identity, network, and infrastructure layers.
  • Develop Python and Bash automation to enforce security controls, compliance, and operational efficiency.
  • Integrate security into CI/CD pipelines and DevOps workflows across the software development lifecycle.
  • Build and maintain DevSecOps reference architectures, technical standards, engineering patterns, and best practices.
  • Implement automated SAST, DAST, SCA, container, image, secret, credential, and infrastructure security scanning.
  • Manage vulnerability scanning, prioritization, remediation tracking, reporting, governance, compliance reviews, and Kubernetes security.

Requirements

  • At least 3 years of experience in DevSecOps, security engineering, or security-focused DevOps.
  • Knowledge of AppSec, the OWASP Top 10, secure coding, Linux administration, TCP/IP networking, virtualization, and databases.
  • Hands-on experience with Git, CI/CD concepts, Python, and Bash.
  • Knowledge of vulnerability management tools such as Qualys and Nessus, plus SAST/DAST tools including SonarQube, OWASP ZAP, or Burp Suite.
  • Understanding of monitoring tools such as Grafana and Prometheus, Terraform security, Kubernetes security, and vulnerability scanners.
  • Strong technical documentation and writing skills are mandatory.

Nice to have

  • Experience with Terraform, Ansible, YAML, orchestration, and Agile/Scrum methodologies.
  • Experience supporting continuous Authority to Operate initiatives.
  • Exposure to multi-account AWS governance, SCPs, IAM boundaries, HashiCorp Vault, or AWS Secrets Manager.

Culture & Benefits

  • Hybrid work arrangement in Bucharest.
  • Cross-functional collaboration with infrastructure, development, and cybersecurity teams.
  • Work focused on practical security controls, continuous compliance, and audit readiness.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →