
DevSecOps Engineer
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Poland.
• Collaborate with the team to operate and manage the platform, utilizing Azure, AKS, deployments, upgrades, incident response, and on-call support.
• Develop and maintain infrastructure for transitioning from a monolithic architecture to a microservices approach, which includes environments, Azure DevOps CI/CD pipelines, Infrastructure as Code, monitoring, and alerting.
• Oversee the external attack surface, catalog internet-facing assets, monitor for potential vulnerabilities, and ensure that identified issues are resolved.
• Embed security practices within Azure DevOps and Kubernetes delivery pipelines, focusing on code, dependencies, secrets, container, and Infrastructure as Code scanning.
• Create and uphold security baselines for Azure and Microsoft 365, including identity and access management, MFA, cloud security posture, Microsoft Defender, and access management protocols.
• Administer the complete vulnerability management process.
• Take ownership of technical security controls that support the ISO 27001 certification initiative.
• Offer technical insights for customer security questionnaires and audits.
• Assist with external penetration testing efforts and the remediation of identified findings.
• Automate operational and security processes while continuously enhancing platform reliability and security.
• A minimum of 5 years of professional experience in Platform Engineering, DevOps, or a comparable role.
• Robust hands-on expertise with Microsoft Azure and Kubernetes/AKS in production settings, including the construction of clusters, pipelines, and environments, along with performing upgrades and supporting production systems.
• Practical experience in security engineering and management of security-related processes.
• Familiarity with the technical aspects of ISO 27001 or an equivalent security framework, or comprehensive experience in end-to-end vulnerability management.
• In-depth knowledge of external attack surface monitoring, DAST, SAST, SCA, secrets scanning, container scanning, and cloud security posture management.
• Proficient in Azure DevOps and CI/CD pipelines.
• Experience in Infrastructure as Code and infrastructure automation.
• Scripting and automation capabilities using Bash, PowerShell, or Python.
• Competence in documenting technical processes and security controls, with the ability to convey technical concepts clearly to customers, security teams, and auditors.
• Capacity to independently prioritize tasks and assume ownership within a small, senior team setting.
• Proficiency in English.
• Private healthcare.
• Multisport card.
• Training opportunities.
FourEnergy GmbH
ICF
Mastercam
C&S Informática
Get handpicked remote jobs straight to your inbox weekly.