Source description
About the role
Job Description : We are looking for a passionate and skilled DevSecOps Engineer with 2+ years of experience in DevOps and cloud security practices. The ideal candidate should have hands-on experience in implementing security across CI/CD pipelines, cloud infrastructure, containerized environments, and application deployments. The role involves integrating security into every stage of the software development lifecycle (SDLC) while ensuring scalable, reliable, and secure deployments. Key Responsibilities : - Implement and maintain secure CI/CD pipelines. - Integrate security controls into DevOps processes and workflows. - Perform vulnerability assessments and security scans on applications, containers, and infrastructure. - Automate security testing within build and deployment pipelines. - Monitor cloud environments and ensure adherence to security best practices. - Collaborate with Development, QA, and Infrastructure teams to remediate security vulnerabilities. - Configure and manage IAM policies, access controls, and secrets management. - Support compliance initiatives and security audits. - Monitor, investigate, and respond to security incidents. - Implement Infrastructure as Code (IaC) security best practices. - Ensure secure containerization and Kubernetes deployments. Required Skills : 1. DevOps & Cloud : - AWS, Azure, or GCP - CI/CD Pipelines (Jenkins, GitHub Actions, GitLab CI/CD) - Docker - Kubernetes - Linux Administration - Shell Scripting 2. Security : - Application Security (AppSec) - Vulnerability Management - OWASP Top 10 - Security Testing - Container Security - Cloud Security - Identity & Access Management (IAM) - Secrets Management 3. Infrastructure as Code : - Terraform - CloudFormation (Good to Have) 4. Security Tools : Experience with one or more of the following : - SonarQube, Snyk, Trivy, OWASP ZAP, Checkmarx, Veracode, Aqua Security, Prisma Cloud 5. Monitoring & Logging : - ELK Stack, Grafana, Prometheus, CloudWatch Preferred Qualifications : - Bachelor's degree in Computer Science, Information Technology, or related field. - Experience working in Agile/Scrum environments. - Understanding of Secure SDLC principles. - Knowledge of security compliance standards such as ISO 27001, SOC 2, PCI-DSS, or GDPR. Good to Have : - Kubernetes Security - DevSecOps Automation - Incident Response - Threat Modeling - Security Compliance & Audits - Multi-cloud exposure (AWS/Azure/GCP) Preferred Certifications : - AWS Certified Security Specialty - AWS Certified Solutions Architect - Certified Kubernetes Security Specialist (CKS) - CEH (Certified Ethical Hacker) - CompTIA Security+ - DevSecOps Foundation Certification Job Description : We are looking for a passionate and skilled DevSecOps Engineer with 2+ years of experience in DevOps and cloud security practices. The ideal candidate should have hands-on experience in implementing security across CI/CD pipelines, cloud infrastructure, containerized environments, and application deployments. The role involves integrating security into every stage of the software development lifecycle (SDLC) while ensuring scalable, reliable, and secure deployments. Key Responsibilities : - Implement and maintain secure CI/CD pipelines. - Integrate security controls into DevOps processes and workflows. - Perform vulnerability assessments and security scans on applications, containers, and infrastructure. - Automate security testing within build and deployment pipelines. - Monitor cloud environments and ensure adherence to security best practices. - Collaborate with Development, QA, and Infrastructure teams to remediate security vulnerabilities. - Configure and manage IAM policies, access controls, and secrets management. - Support compliance initiatives and security audits. - Monitor, investigate, and respond to security incidents. - Implement Infrastructure as Code (IaC) security best practices. - Ensure secure containerization and Kubernetes deployments. Required Skills : 1. DevOps & Cloud : - AWS, Azure, or GCP - CI/CD Pipelines (Jenkins, GitHub Actions, GitLab CI/CD) - Docker - Kubernetes - Linux Administration - Shell Scripting 2. Security : - Application Security (AppSec) - Vulnerability Management - OWASP Top 10 - Security Testing - Container Security - Cloud Security - Identity & Access Management (IAM) - Secrets Management 3. Infrastructure as Code : - Terraform - CloudFormation (Good to Have) 4. Security Tools : Experience with one or more of the following : - SonarQube, Snyk, Trivy, OWASP ZAP, Checkmarx, Veracode, Aqua Security, Prisma Cloud 5. Monitoring & Logging : - ELK Stack, Grafana, Prometheus, CloudWatch Preferred Qualifications : - Bachelor's degree in Computer Science, Information Technology, or related field. - Experience working in Agile/Scrum environments. - Understanding of Secure SDLC principles. - Knowledge of security com
More at Antino