20 часов назад
DevSecOps Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DevSecOps Engineer (Terraform/Kubernetes): Building secure cloud delivery pipelines and platform foundations with an accent on IAM, infrastructure as code, CI/CD, Kubernetes operations, and software supply chain security. Focus on automating policy enforcement, observability, incident response, compliance evidence, and reliable production operations.
Location: Houston, Texas, United States; onsite work involving regular movement around the office and corporate campus
Company
is an automotive company within The Friedkin Group.
What you will do
- Design and automate least-privilege IAM across cloud and Kubernetes environments.
- Build and maintain Terraform modules and production/non-production environments with drift detection and policy-as-code.
- Own GitHub Actions pipelines, reusable workflows, environment protections, security scans, signing, and deployment gates.
- Operate production Kubernetes clusters, including lifecycle management, Helm/Kustomize, GitOps, networking, secrets, autoscaling, upgrades, and disaster recovery.
- Implement software supply chain security, secret management, observability, incident response automation, and on-call support.
- Partner with AppSec and product teams on threat modeling, secure design reviews, compliance initiatives, cost controls, reliability, and platform documentation.
Requirements
- 8+ years of experience in DevOps, platform engineering, or SRE with a security-first mindset.
- Strong cloud and Kubernetes IAM experience, including RBAC, OIDC/OAuth2, SSO, and identity providers.
- Production experience with Terraform, GitHub Actions, Kubernetes, Helm, networking, ingress, autoscaling, upgrades, backups, and disaster recovery.
- Practical experience with security scanners, policy-as-code, containers, Linux, and AWS or another major cloud platform.
- Strong Python or Bash scripting, infrastructure troubleshooting, debugging, communication, ownership, and cross-team leadership skills.
- Must be legally authorized to work in the United States without sponsorship.
Nice to have
- Experience with HashiCorp Vault, Kyverno, Keeper, service mesh, Cilium, GitOps at scale, or progressive delivery.
- Experience with SIEM, detection engineering, security data pipelines, PII protection, tokenization, or regional compliance.
- Background in financial, insurance, or automotive domains and other regulated environments.
Culture & Benefits
- Regular full-time position.
- Up to 20% travel is required.
- Participation in compliance initiatives such as SOC 2 and ISO 27001.
- Inclusive workplace committed to diversity and reasonable accommodation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →