DevSecOps Engineer
Core
Embed security into every layer of cloud infrastructure and software delivery pipelines for GCP and AWS environments, ensuring compliance and hardening without slowing engineering velocity.
Role type
Senior DevSecOps Engineer (Cloud & Kubernetes)
Builds
Hardened multi-cloud environments, secure Kubernetes clusters, and integrated CI/CD security pipelines
Domain
Cloud Security, Kubernetes Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Cloud security posture management (CSPM), IAM policy design, Kubernetes hardening, CI/CD pipeline security, IaC security scanning, threat modelling, compliance reporting, security automation
Preferred skills
Runtime security tooling, service mesh security, eBPF-based security, penetration testing, threat modelling frameworks
Technologies
GCP (Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager), AWS (GuardDuty, Security Hub, IAM, KMS, Macie), Kubernetes (GKE, RBAC, Network Policies), GitLab (CI/CD, SAST/DAST), Terraform (tfsec, Checkov), Datadog, Istio, Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk
Responsibilities
Own cloud security posture management and incident response across GCP/AWS/Kubernetes; Harden clusters and enforce network policies; Secure CI/CD pipelines with integrated scanning; Manage secrets hygiene and TLS; Conduct compliance reporting and threat modelling; Build security automation and observability pipelines
Seniority
Senior, hands-on IC