Lead DevSecOps Engineer
We are now building a Platform & Cloud Security function and are looking for the first hire to launch and lead it. This is a rare opportunity to set the standards from scratch and shape how security is embedded into a modern, high-load, cloud-native environment.
Main Responsibilities
โ Establish the DevSecOps function, defining best practices and security standards across the Platform Tribe
โ Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning, container scanning)
โ Harden infrastructure and runtime environments (Linux, Docker, Kubernetes/EKS, RBAC)
โ Design and enforce cloud security controls in AWS (IAM least-privilege, GuardDuty, Security Hub, encryption at rest/in transit)
โ Define and maintain IaC security policies (Terraform/Terragrunt, drift detection, policy-as-code)
โ Implement and manage secrets management solutions (Vault, AWS Secrets Manager)
โ Build centralized security monitoring & alerting (Datadog, ELK, CloudWatch, SIEM/SOAR)
โ Lead vulnerability management and threat modeling practices
โ Automate workflows through scripting (Python, Bash)
โ Partner with backend, infrastructure, and platform engineers to embed security in design & delivery
โ Contribute to compliance readiness (ISO 27001, GDPR, PCI-DSS)
โ Act as a security subject-matter expert, mentoring engineers and raising awareness
โ Continuously evaluate and implement new security tools and approaches
Mandatory Requirements
โ 5+ years in Security Engineering / DevSecOps roles , with proven success delivering secure infrastructure and applications
โ Strong skills in Python and Bash for building and automating security workflows
โ Cloud Security (AWS focus) โ Deep knowledge of IAM least-privilege design, encryption at rest/in transit, GuardDuty, Security Hub, and best practices for securing multi-account environments
โ Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code)
โ Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies
โ Terraform/Terragrunt, including policy-as-code, drift detection, and compliance enforcement
โ Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent
โ Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows
โ In-depth understanding of secure network design, segmentation, and monitoring
โ Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.)
โ Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access)
โ Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks
โ Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines
Nice to have
โ Exposure to Kafka or ClickHouse in security-sensitive environments
โ Familiarity with GitOps tooling (FluxCD/ArgoCD)
โ Broader knowledge of SOC 2, HIPAA, or other regulatory frameworks
We offer
โ Compensation at top industry standards + quarterly bonuses based on transparent evaluation
โ Remote-first flexibility and adaptable working hours
โ Unlimited paid vacation & sick leave
โ Comprehensive medical insurance (for you and your partner)
โ Financial support for major life events
โ Professional growth budget for courses, training, and certifications
Required skills experience
| Linux | 1 year |
| Docker | 1 year |
| Kubernetes | 1 year |
| RBAC | 1 year |
| Terraform | 1 year |
| AWS | 1 year |
Required languages
| English | B2 - Upper Intermediate |
| Ukrainian | Native |