N2SWe are seeking a skilled DevSecOps Engineer to integrate security across the entire software development lifecycle. The ideal candidate will have strong experience in CI/CD, cloud security, automation, and modern DevOps toolchains, with the ability to collaborate closely with development, operations, and security teams.
Automate security checks within CI/CD pipelines using tools such as SAST, SCA, DAST, and Secrets Scanning.
Implement automated compliance validation and policy enforcement.
Integrate security testing tools into build pipelines (e.g., SonarQube, Checkmarx, Snyk, OWASP ZAP, Trivy).
Apply infrastructure‑as‑code (IaC) security checks (Terraform/CloudFormation security scanning).
Implement Kubernetes security best practices—RBAC, network policies, pod security, runtime scanning.
Detect vulnerabilities, misconfigurations, and anomalies in production environments.
Conduct root cause analysis and define preventative measures.
Drive security governance, compliance automation, and risk reporting.
Provide security guidance, documentation, and training to engineering teams.
Participate in architecture reviews and security design discussions.
Required Skills & Qualifications
Strong experience with DevOps & CI/CD pipelines.
Hands‑on experience in SAST, DAST, SCA, Container scanning.
Proficiency with Linux, scripting (Python, Bash, Shell).
Knowledge of Docker & Kubernetes security.
Expertise in securing cloud platforms (AWS/GCP/Azure).
Infrastructure-as-Code (Terraform, Helm, CloudFormation).
OWASP Top 10, CIS Benchmarks, NIST, ISO 27001.
Strong problem-solving capabilities.
Excellent communication and cross-team collaboration.
Ability to advocate for security without blocking delivery.
3–10+ years of experience in DevOps/DevSecOps/Security engineering.
Certifications (preferred but not mandatory):
CISSP, CEH, CCSP
Mid-Senior level
Full-time
¿Te interesa este puesto?