Cloud DevSecOps Engineer (AWS,Azure)
$$$$
We are looking for a security-first Cloud DevSecOps Engineer to design, automate, and protect our multi-cloud infrastructure across AWS and Azure. In this role, you won’t just build pipelines—you will bake security directly into them. You will work closely with our development and engineering teams to enforce a “Shift Left” culture, ensuring that automation, scalability, and airtight cloud compliance go hand-in-hand.
Requirements:
- 3+ years of hands-on experience in Cloud DevOps/DevSecOps, managing production environments across AWS and Azure.
- Strong experience designing and securing CI/CD pipelines (GitHub Actions, Azure DevOps, GitLab CI).
- Advanced knowledge of Infrastructure as Code using Terraform (CloudFormation or Bicep is a plus).
- Experience implementing Policy-as-Code and IaC security scanning using tools such as Checkov, Tfsec, OPA/Rego.
- Practical experience integrating security controls into the SDLC, including SAST, DAST, SCA, secret detection, and container image scanning.
- Hands-on experience with Kubernetes (EKS/AKS), Docker, container security, and workload hardening.
- Experience with cloud-native security services across AWS and Azure.
- Strong understanding of IAM, RBAC, Zero Trust, and enterprise secrets management (HashiCorp Vault, Azure Key Vault).
- Experience implementing and integrating security platforms such as SonarQube, Prisma Cloud, Wiz, Snyk, CrowdStrike, Microsoft Sentinel, or similar.
- Experience configuring centralized logging and telemetry pipelines for SIEM solutions.
- Practical knowledge of cloud security, vulnerability management, encryption, compliance frameworks (SOC2, ISO 27001, CIS), and secure software delivery.
- Proficiency in scripting (Python, Bash, or PowerShell).
Responsibilities
- Design, build, and maintain secure CI/CD pipelines, embedding security throughout the software delivery lifecycle.
- Automate cloud infrastructure provisioning across AWS and Azure using Terraform.
- Implement and maintain Policy-as-Code guardrails to prevent infrastructure misconfigurations before deployment.
- Integrate automated SAST, DAST, SCA, secret detection, vulnerability scanning, and container scanning into engineering workflows.
- Deploy and automate security tooling, including EDR agents, vulnerability scanners, monitoring agents, and security baselines across cloud workloads.
- Configure and automate application, infrastructure, and container log collection for centralized SIEM platforms.
- Build automated vulnerability remediation workflows, integrating findings into engineering backlogs (e.g., Jira).
- Implement and maintain Zero Trust access controls, IAM governance, RBAC, and enterprise secrets management.
- Secure Kubernetes platforms (EKS/AKS), container runtimes, and cloud-native workloads.
- Collaborate with Security, Engineering, and Platform teams to promote secure-by-default infrastructure and developer enablement.
- Develop reusable secure Terraform modules, Helm charts, and deployment templates.
- Continuously improve cloud compliance, security posture, and operational resilience across AWS and Azure environments.
Preferred certifications:
- AWS Certified Security — Specialty
- AWS Certified DevOps Engineer — Professional
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Certified DevSecOps Professional (CDP) or Practical DevSecOps
- Certified Kubernetes Administrator (CKA)
- Certified Kubernetes Security Specialist (CKS)
- HashiCorp Terraform Associate (nice to have)
Required languages
English
B2 - Upper Intermediate
Ukrainian
Native
Published 5 August
36 views
·
3 applications
Last responded 17 minutes ago
📊
Average salary range of similar jobs in
analytics →
Loading...