Security Engineer (DevSecOps / AppSec)

Jobgether· Brussels (Firmensitz, recherchiert)· lever· veröffentlicht 28.07.2026
Muss:PythonAWSDockerCloudCI/CDAISecurityLeadRemote

Accountabilities Implement and maintain security tools within CI/CD pipelines, including SAST, DAST, SCA, and secret scanning solutions across development workflows.

Operate, maintain, and improve secrets management solutions such as Vault and cloud-based secret management platforms.

Continuously monitor repositories for exposed secrets and collaborate with development teams to remediate security findings.

Perform security-focused code reviews for critical features involving authentication, authorization, external integrations, and sensitive data handling.

Strengthen infrastructure security by reviewing Terraform configurations, IAM policies, AWS environments, security groups, and cloud security practices.

Support remediation efforts related to security assessments, penetration testing results, vulnerability scans, and internal findings.

Develop and lead Security Champions programs by identifying security advocates within engineering teams and supporting continuous security education.

Conduct threat modeling sessions for new features, integrations, and critical systems in partnership with product and engineering teams.

Define and document security requirements throughout the software development lifecycle, from design through deployment.

Evaluate the security of internal and external APIs, partner integrations, authentication flows, and application architectures.

Create scripts and automation solutions to improve security analysis, monitoring, and remediation processes.

Promote secure development practices and help engineering teams adopt security-first approaches.

Requirements

Hands-on experience with CI/CD pipelines and integrating security tools such as SAST, SCA, and secret scanning into development workflows.

Strong knowledge of AWS security services and concepts, including IAM, S3, Lambda, Security Groups, VPC, KMS, and cloud security best practices.

Experience with Infrastructure as Code (IaC), particularly Terraform, including identifying and fixing security issues in configurations.

Strong understanding of OWASP Top 10 and OWASP API Security Top 10, with the ability to apply security principles during code reviews and architecture discussions.

Ability to create scripts and automation workflows using languages such as Python or Bash.

Experience reading and understanding application code in at least one programming language used within software products.

Strong analytical thinking and risk assessment skills with the ability to identify and prioritize security concerns.

Proactive mindset with strong ownership, initiative, and ability to work independently.

Excellent communication skills and ability to collaborate effectively with software development teams.

Ability to explain security concepts clearly and support knowledge sharing across teams.

Experience with Bitbucket is considered an asset.

Practical experience with secrets management tools such as HashiCorp Vault or AWS Secrets Manager is preferred.

Familiarity with DAST tools such as OWASP ZAP or Burp Suite integrated into development pipelines is a plus.

Knowledge of Docker container security, image repositories, CIS Benchmarks, and cloud posture management tools such as Wiz, Prisma Cloud, AWS Security Hub, or GuardDuty is beneficial.

Experience securing serverless architectures, including Lambda and API Gateway, is an advantage.

Relevant certifications such as AWS Solutions Architect, AWS Security Specialty, Certified DevSecOps Professional, or HashiCorp Vault Associate are considered a plus.

Benefits

Fully remote work environment with flexibility and autonomy.

PJ contract model with 30 days of paid rest.

Health insurance with company-paid monthly fees after 6 months for PJ contractors.

Dental insurance after 6 months.

Life insurance coverage.

Complete equipment package provided for work.

Home office allowance of R$180 per month .

Birthday day off.

Gym membership discounts.

Flexible and inclusive workplace culture with no dress code.

Extended maternity and paternity leave.

Opportunity to work on impactful technology solutions within a rapidly growing environment.

Collaborative culture focused on innovation, autonomy, and professional growth.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1