Jobgether
Jobgether

Senior DevSecOps Engineer

TLDR

Strengthen security posture of large-scale platforms by embedding security into SDLC, building scalable security frameworks, and driving compliance maturity across multiple teams.

Accountabilities
  • Design and implement an end-to-end Application & Infrastructure Security operating model, including ownership structures, SLAs, escalation paths, risk acceptance processes, and reporting frameworks.
  • Build and maintain a robust vulnerability management program covering detection, triage, prioritization, remediation tracking, exception handling, and security metrics.
  • Integrate security controls into SDLC and CI/CD pipelines, including SAST, SCA, secret scanning, container and image scanning, SBOM generation, and security quality gates.
  • Strengthen software supply chain security through dependency management, artifact signing, CI/CD hardening, protected branches, and secure release practices.
  • Define and implement cloud security baselines using Infrastructure as Code, including IAM policies, KMS, logging, threat detection, and cloud security monitoring tools.
  • Establish Kubernetes security standards such as Pod Security Policies/Standards, network policies, RBAC reviews, admission control, and runtime security practices.
  • Collaborate with engineering and platform teams to remediate vulnerabilities, reduce false positives, improve secure coding practices, and embed security-by-design principles.
  • Support compliance and audit readiness efforts (including PCI DSS and similar frameworks) by preparing documentation, controls, and security evidence.
  • Automate security workflows and reporting using scripting and engineering tools (Python, Bash, or Go) to improve efficiency and scalability.
  • Continuously improve security tooling, policies, and processes across cloud, application, and infrastructure environments.
  • Requirements

    • 5+ years of hands-on experience in DevSecOps, Application Security, or Security Engineering roles in production environments.
    • Strong practical experience integrating security tools into CI/CD pipelines (GitLab CI, GitHub Actions, or similar).
    • Expertise with security scanning tools such as SAST, SCA, secret scanning, container/image scanning (e.g., Semgrep, SonarQube, Trivy, Snyk, Grype, Gitleaks or equivalents).
    • Strong understanding of CI/CD security concepts including least privilege access, protected branches/environments, secrets management, CODEOWNERS, and secure runner configurations.
    • Proven experience building vulnerability management processes including triage, prioritization, SLA definition, remediation tracking, and risk acceptance workflows.
    • Deep knowledge of software supply chain security including SBOMs, dependency pinning, artifact signing, provenance, and dependency risk management.
    • Strong cloud security experience, ideally in AWS, including IAM, Security Groups, KMS, CloudTrail, GuardDuty, Security Hub, and network architecture.
    • Hands-on experience with Kubernetes security including RBAC, network policies, admission controllers, audit logging, and runtime security concepts.
    • Experience with Infrastructure as Code security (Terraform preferred) using tools like tfsec, Checkov, or policy-as-code frameworks.
    • Strong automation skills in Python, Bash, or Go for building security tools, pipeline integrations, or reporting systems.
    • Solid understanding of OWASP Top 10, web application vulnerabilities, and secure development practices.
    • Ability to work independently, prioritize effectively, and collaborate closely with engineering, platform, and business stakeholders in a fast-paced environment.
    • Experience in regulated industries such as fintech or gaming is a plus.
    • Benefits

      • Fully remote work with flexibility to work from anywhere within compatible regions.
      • Competitive compensation package aligned with experience and market standards.
      • 20 paid vacation days plus public holidays and sick leave.
      • Private health insurance and psychological support coverage.
      • Flexible benefits budget for personal use, hobbies, sports, and lifestyle needs.
      • Learning and development budget, including courses, training, workshops, and language programs.
      • Corporate events, team-building activities, and professional development workshops.
      • Flexible working culture focused on autonomy, trust, and work-life balance.
      • Access to modern engineering practices, automation-first workflows, and cutting-edge security tooling.
      • Opportunity to work on high-scale, high-impact systems in a fast-growing product environment.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1

Benefits

Flexible Work Hours

Flexible working culture focused on autonomy, trust, and work-life balance.

Health Insurance

Private health insurance and psychological support coverage.

Learning Budget

Learning and development budget, including courses, training, workshops, and language programs.

High-impact systems opportunity

Opportunity to work on high-scale, high-impact systems in a fast-growing product environment.

Paid Time Off

20 paid vacation days plus public holidays and sick leave.

Remote-Friendly

Fully remote work with flexibility to work from anywhere within compatible regions.

Wellness Stipend

Flexible benefits budget for personal use, hobbies, sports, and lifestyle needs.

Jobgether runs the largest remote job platform, effectively linking job seekers with over 200,000 flexible and remote opportunities that match their unique skills and preferences. Our focus is on enhancing the hiring process, ensuring efficiency while prioritizing the candidate experience, particularly in the growing health and wellness sector.

Founded
Founded 2020
Employees
11-50 employees
Industry
Professional Services
View company profile
Apply for this job