DevSecOps Engineer
We are looking for an experienced DevSecOps Engineer who will help us integrate and automate security processes in CI/CD, increase infrastructure protection and ensure compliance with best security practices. Our products are used by thousands of users, and the security of our services is one of our priorities.
What you will be doing:
• Implementation and automation of security tools in the CI/CD process (SAST, DAST, SCA, IAST).
• Analysis of vulnerabilities in code, infrastructure and containers, working with False Positive.
• Development and configuration of security monitoring systems, incident response.
• Monitoring and improving the security level of on-prem infrastructures (Kubernetes).
• Interaction with developers, DevOps and security teams to implement secure practices.
• Active participation in the processes of IAM configuration, management of certificates, secrets and access policies.
• Conducting internal security audits, participation in external (e.g. penetration) tests.
What skills and experience are important to us:
• Experience as a DevSecOps Engineer, Security Engineer or DevOps Engineer with a focus on security for 3+ years.
• Excellent understanding of CI/CD processes and tools (GitLab CI/CD, Jenkins, GitHub Actions, etc.).
• Skills in working with security tools (SonarQube, OWASP ZAP, Aqua Security, Trivy, Snyk, Checkmarx, etc.).
• Experience with baremetal solutions in infrastructure and knowledge of their security specifics.
• Deep understanding of Kubernetes and containerization from a security perspective.
• Knowledge of the basics of cryptography, certificate management, authentication and authorization mechanisms (OAuth2, OpenID, JWT).
• Programming skills (Python, Bash, Go) for task automation.
• Experience with SIEM, IDS/IPS and logging tools (ELK, Splunk, Wazuh, etc.) will be a plus.
• Knowledge of security standards (OWASP, NIST, ISO 27001, CIS Benchmarks).
Soft Skills:
• Strong analytical and troubleshooting skills to investigate and resolve security incidents.
• Excellent written and verbal communication skills for technical reporting and collaboration.
• Ability to work effectively both independently and within cross-functional teams.
We Offer:
- Possibility of a remote work from anywhere in the world
- Generous days-off policy (vacation, sick leave, days off, holidays)
- Guaranteed performance reviews & career plan development
- Low bureaucracy level, with decisions made quickly
- Open-minded and easy-going management
- Friendly atmosphere among people who love their work.