We help enterprises and service providers empower their data -driven competitive advantage at scale. As our Senior DevSecOps Engineer, you will be the foundational security expert within the DevOps team. Following a recent corporate transition, our infrastructure is moving into a highly regulated environment subject to strict, ongoing security compliance frameworks and external audits.
You will lead the charge in designing, securing, and continuously adapting our infrastructure to meet these evolving enterprise and regulatory standards. Your immediate priority will be securing the environments where protected data is stored across public cloud infrastructure, on-premise virtual environments, and containerized clusters. Beyond immediate compliance, you will architect our secure cloud posture from the ground up, embed automated security guards seamlessly into our deployment pipelines, and mentor the broader engineering team on modern security practices.
Compliance &
Infrastructure Hardening &
Secure Architecture &
Application Security Integration: Manage and optimize the integration of automated security scanning tools (SAST, SCA, and DAST) into CI/CD pipelines. Ensure reliable capture, aggregation, and reporting of scan results to satisfy product governance and audit requirements.
Threat Detection &
Security Incident Response: Serve as the primary technical escalation point for infrastructure security incidents, creating automated playbooks for rapid triage and mitigation.
Mentorship: Act as the security subject matter expert, identifying technical gaps and upskilling the DevOps and development teams in secure infrastructure concepts.Requirements:
Proven experience as a Senior DevSecOps, Cloud Security, or Security Infrastructure Engineer.
Deep, hands-on expertise securing public cloud environments (AWS preferred) and container orchestration platforms (Kubernetes).
Strong background with Infrastructure as Code (IaC) and modern GitOps/declarative continuous delivery workflows.
Demonstrated experience navigating strict compliance frameworks, government regulations, or protected data environments (e.g., NIST, FedRAMP, CIS, or equivalent federal/enterprise frameworks).
Experience configuring enterprise-scale logging, continuous monitoring, and automated configuration compliance tools.
מתעניינים במשרה הזו?