DevSecOps Security Engineer
Core
Embed security across the software development lifecycle (SDLC) for cloud and on-premise applications by integrating security tools into CI/CD pipelines and securing AWS environments.
Role type
Senior DevSecOps Security Engineer
Builds
Secure CI/CD pipelines, hardened containerized environments, and compliant AWS infrastructure
Domain
Cloud Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
AWS cloud services, CI/CD pipeline design, Infrastructure-as-Code (Terraform), container orchestration (Docker, Kubernetes), IAM/OIDC/secrets management, vulnerability management, scripting (Python, Bash, Go), security tooling (SAST, SCA, DAST, SIEM/SOAR)
Preferred skills
Offensive security practices, AI/ML security risks, financial sector experience
Technologies
GitHub Actions, AWS (EC2, S3, Lambda, IAM, GuardDuty, Inspector, CloudWatch), Terraform, CloudFormation, AWS CDK, Docker, Kubernetes, Mend, SonarQube, Prowler, Trivy, OWASP ZAP, Burp Suite
Responsibilities
Design and maintain security controls within CI/CD pipelines; Secure AWS environments and implement IAM, OIDC, and encryption controls; Develop automation scripts for secure deployments; Perform vulnerability management and incident response; Review code and infrastructure changes for security risks; Mentor team members and promote security culture
Seniority
Senior, hands-on IC