DevSecOps Engineer

Uberall· Brazil· ashby· zverejnené 15. 07. 2026
Povinné:GitAWSKubernetesCloudDevOpsCI/CDMicroservicesSecurityLeadRemote
ABOUT THE ROLE We are looking for a proactive and skilled DevSecOps Engineer with 5+ years of hands-on experience to join our growing engineering team. You'll be working closely with a small team of five DevOps engineers to build, maintain, and scale secure cloud infrastructure, CI/CD pipelines, and observability stacks. We value a security-first engineering mindset where you will integrate security-as-code practices throughout the entire development lifecycle. If your background is in DevOps, that is a great fit, provided you have always focused on and enjoyed the security aspects of your work, and are now ready to fully commit to a dedicated security role. We value collaboration, strong communication, and a growth mindset: you'll be expected to contribute ideas, give and receive feedback, and work independently to ensure our platform is as secure as it is performant.     YOUR RESPONSIBILITIES - Integrate automated security scanning (SAST, DAST, container scanning) into CI/CD pipelines to ensure early detection of vulnerabilities. - Maintain and audit cloud infrastructure compliance (e.g., SOC2, HIPAA, GDPR) through automated policies. - Implement security best practices within Terraform/IaC to ensure "security-as-code" consistency. - Monitor and respond to cloud security incidents, collaborating closely with security and compliance teams. - Design, implement, and maintain cloud infrastructure primarily on AWS, with strong focus on EC2, RDS, OpenSearch, and EKS. - Help to manage the Kubernetes clusters running our microservices (we have over a hundred in production) as well as the legacy EC2-based platform. - Hardening Kubernetes clusters by implementing network policies, RBAC, and secure pod security standards to protect our microservices environment. - Collaborate on maintaining our Infrastructure as Code (IaC) maintenance using Terraform. - Identify opportunities for automation and optimization in deployment and infrastructure management. - Document processes, infrastructure, and decisions clearly and effectively. - Partner closely with our Information Security Lead on compliance audits, control evidence, and security roadmap prioritization, while reporting into the Head of DevOps for day-to-day work.     YOUR PROFILE Experience with our stack: - Proven experience in a DevSecOps or security-focused engineering role. - Familiarity with modern security tooling (vulnerability management, secrets management etc.). - Strong understanding of "shift-left" security principles. - 3+ years of experience in a DevOps or similar role. - Deep experience with AWS services, especially IAM, EC2, RDS, EKS, and OpenSearch. - Solid understanding and hands-on experience with Kubernetes and related tooling (we use Helm, Kustomize and FluxCD but we value knowing and adhering to the GitOps practices more than the specific tools). - Strong proficiency in Terraform for infrastructure automation. - Experience in CI/CD tools. - Bash or other shell scripting knowledge Soft Skills & Mindset: - Highly proactive and self-motivated; able to identify and address issues before they escalate. - Strong communication skills, both verbal and written. We are a remote and distributed team so we focus on effective and async communication. - Comfortable working collaboratively within a distributed team but also capable of driving tasks independently. - Open to giving and receiving feedback, and eager to grow with the team. - Analytical mindset with attention to detail and commitment to high-quality work.     NICE-TO-HAVE - Experience with GitLab CI and GitLab in general. - Familiarity with the JVM. - Experience in cost optimization on AWS. - Having worked with Istio or other service meshes. - Exposure to GRC/compliance automation tooling (Drata, Vanta, or similar) - Experience with Vulnerability/dependency scanning tools