Senior Cloud DevSecOps Engineer
About YellowIpe
Our mission is to inspire the connection between technology and people; we foster the best in our professionals through our expertise in finding and attracting the best talent for the best projects. Focus on People, Collaboration, and Commitment are the pillars that guide us on this journey.
Join the yellow team as our new Senior Cloud DevSecOps Engineer!
Project: Involvement in a security project (linked to the Anycloud initiative) or in the expansion of our capacity in the DevOps as a service project, focusing on robust security practices in multi-cloud environments.
Responsibilities: Act as a senior/intermediate DevSecOps engineer in the analysis, design, and improvement of Identity and Access Management (IAM) policies to ensure the application of the 'Least Privilege' principle in each cloud environment (AWS, Azure, GCP).
Collaborate closely with security, software engineering, and other DevOps teams to strengthen the global security posture regarding IAM policies, ensuring compliance and risk mitigation.
Work with development teams (service owners) in executing comprehensive QA validations to confirm that IAM policies work as expected, both from a functional and performance standpoint, including automated testing.
Stay updated on security trends, emerging vulnerabilities, compliance regulations, and innovative tools, pushing for continuous improvements in security and operational efficiency.
Actively participate in the review and implementation of security practices throughout the software development life cycle (SDLC) and promote the DevSecOps culture within the organization.
Requirements: Minimum of 3 years of proven experience in cloud platforms (Azure, AWS, or GCP), with deep knowledge in identity management, access, container security (Kubernetes), cloud networking, and IAM policies.
Proficiency in the English language, both verbally and in writing.
Solid understanding of secure SDLC practices, DevSecOps, Infrastructure as Code (IaC) (Terraform or equivalent), and security integration in CI/CD pipelines.
Hands-on skill in scripting/automation (Python, PowerShell, or similar) for security-related tasks, with the ability to implement automated solutions.
Excellent communication skills to explain technical security risks and solutions to development, DevOps, and product teams, promoting common understanding and collaboration.
Problem-solving mindset and a collaborative approach to resolving security concerns, including the ability to provide viable technical recommendations.
Differentials: Hands-on experience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud or Wiz, bringing additional value to security in cloud environments.
Knowledge in Application Security and Code Security Analysis solutions (SCA/SAST/DAST), particularly Snyk, to ensure full security integration in applications.
Solid experience with container technologies such as Docker and advanced knowledge in Kubernetes cluster management and optimization, contributing to a resilient and secure architecture.
Application: View the job and apply at YellowIpe