
DevSecOps
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants anywhere in the world.
• Establish and lead the DevSecOps function from inception within the security team, outlining strategy, roadmap, priorities, and success metrics;
• Evaluate the existing security posture of applications, infrastructure, cloud environments, and development methodologies;
• Create and implement security controls throughout the software development lifecycle;
• Set up and uphold secure CI/CD practices, including security gates and automated validation protocols;
• Embed security checks into engineering workflows, emphasizing automation and enhancing developer experience;
• Develop and manage vulnerability management processes, which encompass triage, prioritization, remediation tracking, and reporting;
• Define and execute cloud security standards, guardrails, and best practices across AWS, Azure, or GCP environments;
• Design and enforce security controls for Kubernetes and containers, covering RBAC, secrets management, network segmentation, and runtime protection;
• Formulate Infrastructure-as-Code security standards and policy-as-code controls;
• Integrate security logs and events into SIEM for monitoring, threat detection, and incident response;
• Develop security standards, technical guidelines, and operational procedures for Engineering and Platform teams;
• Assist in security incident investigations related to cloud, infrastructure, CI/CD, application vulnerabilities, exposed credentials, and supply-chain threats.
• A minimum of 2 years of practical experience in DevSecOps, Cloud Security, or Security Engineering;
• Experience in leading security initiatives, projects, or programs with substantial ownership and autonomy;
• Demonstrated ability to create security processes, tools, or programs from the ground up;
• Hands-on experience in integrating security controls into CI/CD pipelines without hindering engineering productivity;
• Familiarity with containerized environments and Kubernetes security;
• Experience with cloud platforms, particularly AWS;
• Practical knowledge of Infrastructure as Code tools such as Terraform, Helm, or Ansible;
• Experience in integrating security logs and events with SIEM platforms to support detection, monitoring, and incident response scenarios;
• Capacity to balance security needs with business goals and engineering speed;
• Experience with Python is an advantage;
• Proficiency in English at an Intermediate level or above.
• Focus on Health & Wellness
• Global Medical Coverage
• Opportunities for Growth
• Benefits Programs (compensation for gym/stomatology/psychological services, etc.)
• Performance-Driven Rewards
• Dynamic Work Environment
Cribl
Flock Safety
Pear Tree.
GFT Technologies
Get handpicked remote jobs straight to your inbox weekly.