TL;DR
DevSecOps Engineer: Integrating security practices into CI/CD pipelines and cloud infrastructure with an accent on automated security checks, vulnerability scanning, and compliance validation. Focus on managing secrets, monitoring security configurations, and developing automation tools to enhance security processes.
What you will do
- Integrate security practices into CI/CD pipelines and development workflows.
- Implement automated security checks, vulnerability scanning, and compliance validation.
- Manage secrets, credentials, and access policies.
- Monitor cloud and infrastructure security configurations, identify risks, and implement improvements.
- Collaborate with development and security teams to ensure secure application delivery.
- Support incident response activities and contribute to root cause analysis.
- Develop automation scripts and tools to enhance security processes.
- Maintain documentation for security controls, processes, and best practices.
Requirements
- Experience as a DevSecOps Engineer for 2.5+ years.
- Strong understanding of CI/CD pipelines and experience integrating security tools (SAST, DAST, SCA, IaC scanning, and compliance control).
- Hands-on experience with cloud platforms (AWS, Azure, or GCP).
- Knowledge of container security, Docker, and Kubernetes security best practices.
- Familiarity with secrets management solutions (Hashicorp Vault, AWS Secrets Manager, etc.).
- Scripting skills (Python, Bash, or similar) for automation.
- Experience with monitoring and logging tools (ELK, Prometheus, Grafana).
- Understanding of threat modeling, vulnerability management, and secure coding principles.
- English: from Upper-Intermediate and above required.
Culture & Benefits
- Work with leaders in FinTech, Healthcare, Retail, Telecom, and other domains.
- Flexible work conditions: fully remote, office, or hybrid options.
- Professional, financial, and career growth with mentoring and adaptation systems.
- Annual bonus opportunity up to an additional 1,000 USD based on expertise.
- Access to corporate training portal and certification compensation.
- Bright corporate life with events, snacks, and social activities.
- Referral program, English courses, private health insurance, and sports compensation.
Будьте осторожны: если вас просят войти в iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →