Lead DevSecOps Engineer

RecruitGarden Top Employer

We are now building a Platform & Cloud Security function and are looking for the first hire to launch and lead it. This is a rare opportunity to set the standards from scratch and shape how security is embedded into a modern, high-load, cloud-native environment.

 

Main Responsibilities

โ€“ Establish the DevSecOps function, defining best practices and security standards across the Platform Tribe

โ€“ Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning, container scanning)

โ€“ Harden infrastructure and runtime environments (Linux, Docker, Kubernetes/EKS, RBAC)

โ€“ Design and enforce cloud security controls in AWS (IAM least-privilege, GuardDuty, Security Hub, encryption at rest/in transit)

โ€“ Define and maintain IaC security policies (Terraform/Terragrunt, drift detection, policy-as-code)

โ€“ Implement and manage secrets management solutions (Vault, AWS Secrets Manager)

โ€“ Build centralized security monitoring & alerting (Datadog, ELK, CloudWatch, SIEM/SOAR)

โ€“ Lead vulnerability management and threat modeling practices

โ€“ Automate workflows through scripting (Python, Bash)

โ€“ Partner with backend, infrastructure, and platform engineers to embed security in design & delivery

โ€“ Contribute to compliance readiness (ISO 27001, GDPR, PCI-DSS)

โ€“ Act as a security subject-matter expert, mentoring engineers and raising awareness

โ€“ Continuously evaluate and implement new security tools and approaches

 

Mandatory Requirements

โ€“ 5+ years in Security Engineering / DevSecOps roles , with proven success delivering secure infrastructure and applications

โ€“ Strong skills in Python and Bash for building and automating security workflows

โ€“ Cloud Security (AWS focus) โ€” Deep knowledge of IAM least-privilege design, encryption at rest/in transit, GuardDuty, Security Hub, and best practices for securing multi-account environments

โ€“ Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code)

โ€“ Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies

โ€“ Terraform/Terragrunt, including policy-as-code, drift detection, and compliance enforcement

โ€“ Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent

โ€“ Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows

โ€“ In-depth understanding of secure network design, segmentation, and monitoring

โ€“ Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.)

โ€“ Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access)

โ€“ Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks

โ€“ Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines

 

Nice to have

โ€“ Exposure to Kafka or ClickHouse in security-sensitive environments

โ€“ Familiarity with GitOps tooling (FluxCD/ArgoCD)

โ€“ Broader knowledge of SOC 2, HIPAA, or other regulatory frameworks

 

We offer

โ€“ Compensation at top industry standards + quarterly bonuses based on transparent evaluation

โ€“ Remote-first flexibility and adaptable working hours

โ€“ Unlimited paid vacation & sick leave

โ€“ Comprehensive medical insurance (for you and your partner)

โ€“ Financial support for major life events

โ€“ Professional growth budget for courses, training, and certifications

Required skills experience

Linux 1 year
Docker 1 year
Kubernetes 1 year
RBAC 1 year
Terraform 1 year
AWS 1 year

Required languages

English B2 - Upper Intermediate
Ukrainian Native
Published 24 March
5 views
ยท
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...