
DevSecOps Engineer
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in Europe.
• Take ownership of Drata, manage controls, collect evidence, and liaise with auditors.
• Assist with SOC 2 and ISO 27001 compliance efforts, with plans to address GDPR, HIPAA, and HITRUST next.
• Create and uphold practical security policies and procedures, covering areas such as Vulnerability Management, Access Control, Incident Response, and Data Protection.
• Develop and automate processes for onboarding, offboarding, and access reviews utilizing SSO and centralized IAM.
• Streamline provisioning and deprovisioning tasks across GCP, AWS, GitHub, and various SaaS tools.
• Promote security within the SDLC, including the use of Dependabot, CodeQL/SAST, SCA, dependency update policies, and secrets management.
• Manage vulnerability processes, including scanning, CVE triage, patching, annual penetration testing, vendor selection, coordination, and follow-up.
• Engage in responses to critical vulnerabilities and security incidents.
• Enhance security observability through audit logging, change tracking, and reporting across production platforms.
• Allocate approximately 60% of your time to infrastructure tasks: Kubernetes, deployments, monitoring, automation, and on-call duties.
• Over 5 years of hands-on experience in security/DevSecOps for production infrastructure.
• Direct experience in implementing SOC 2, including controls, evidence collection, audit preparation, and communication with auditors.
• Familiarity with Drata, Vanta, or similar compliance automation platforms.
• Capability to compose and implement practical security policies and procedures.
• Strong hands-on experience with Docker, Kubernetes, and GCP and/or AWS cloud environments.
• Background in IAM, network policies, secrets management, hardening, and production operations.
• Solid understanding of IAM/SSO, centralized access management, provisioning/deprovisioning, and periodic access reviews.
• Experience in constructing onboarding and offboarding processes from a security and compliance viewpoint.
• Ability to automate routine tasks using Python and/or Bash.
• Strong communication skills with developers.
• Willingness and capability to mentor, teach, and share knowledge.
• Analytical mindset with a focus on root-cause analysis.
• Proactive, detail-oriented, and reliable.
• Nice to have: Experience with GDPR, HIPAA, and HITRUST.
• Nice to have: Experience in regulated sectors such as banking, fintech, or healthcare, including customer/vendor security audits.
• Nice to have: Experience with both on-prem and SaaS environments.
• Nice to have: Familiarity with Kubernetes security tools such as Falco, OPA/Gatekeeper, Pod Security Standards, and Trivy.
• Nice to have: Experience using AI agents to automate routine tasks.
• Nice to have: Skills in Terraform/Ansible and GitOps.
• Nice to have: Involvement in bug bounty or responsible disclosure programs.
• Access to award-winning AI products designed for technology corporations.
• Utilize a cutting-edge tech stack, including Speech Technologies, NLP, Generative AI (LLMs, diffusion models), voice-first agentic architecture, and privacy-first/on-premises deployment.
• Work in an environment with a high engineering standard and genuine ownership.
• Experience rapid career advancement.
• Enjoy a startup pace with the stability of an enterprise.
• Fully remote work opportunity across Europe.
• 21 vacation days plus public holidays and 5 sick days.
• Private English lessons available through Preply.
Social Discovery Group
Commit
Megaport
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.