DevSecOps Engineer

Posted Sep 4

This is a fully remote position, open to applicants in Egypt, +1 more country.

📋 Description

• Take ownership of cloud security posture management across GCP and AWS, focusing on ongoing assessment, misconfiguration detection, and tracking remediation efforts.

• Design and enforce IAM policies, ensure proper service account hygiene, implement least-privilege access controls, and manage workload identity in multi-cloud environments.

• Implement VPC security measures, including firewall rules, network policies, ingress/egress restrictions, and Private Google Access.

• Secure and internalize service endpoints through the use of internal load balancers, private endpoints, and VPN/interconnect; consistently work to minimize the public attack surface.

• Oversee secrets management utilizing GCP Secret Manager and AWS Secrets Manager, remove hardcoded credentials, and programmatically rotate secrets.

• Lead incident response for cloud and Kubernetes security: triage, contain, investigate, and remediate incidents.

• Manage compliance reporting for SOC 2, HIPAA, and ISO 27001, including evidence collection, gap analysis, and implementation of controls.

• Conduct threat modeling, security reviews, and risk assessments for architecture.

• Strengthen GKE clusters by applying CIS benchmarks, pod security standards, and admission control policies.

• Implement Kubernetes network policies, RBAC, runtime security tools, and controls for the container supply chain.

• Apply Istio security controls, such as mTLS, authorization policies, and observability for east-west traffic.

• Secure GitLab CI/CD pipelines through runner protection, permission restrictions, branch protection, MR approvals, integrated security scanning, and policy-as-code.

• Establish mandatory Terraform IaC security gates with tfsec and Checkov.

• Manage GitLab token hygiene, including expiry policies, project token rotation, and audits of personal access tokens.

• Audit public endpoints and maintain controls for WAF, Cloud Armor, TLS, bastion hosts, DNSSEC, private DNS, and split-horizon DNS.

• Develop security automation pipelines for policy enforcement, compliance checks, and vulnerability remediation as code.

• Instrument security observability in Datadog, including threat detection dashboards and alert tuning.

• Create runbooks for incidents, vulnerability responses, and access reviews.

• Promote security training and awareness; lead secure code reviews and threat modeling workshops.


⛳️ Requirements

• 7+ years of experience in DevSecOps, cloud security, or infrastructure security engineering.

• Extensive hands-on experience in securing Kubernetes clusters in production environments, focusing on RBAC, network policies, pod security, and runtime protection.

• Proven expertise with GCP and/or AWS security services, as well as IAM design.

• Strong knowledge of CI/CD security, encompassing pipeline hardening, secrets management, and integrated scanning.

• Experience in internalizing service endpoints and minimizing the cloud attack surface.

• Familiarity with compliance standards such as HIPAA, SOC 2, or ISO 27001 in regulated settings.

• Excellent communication skills, capable of articulating critical vulnerabilities to a CTO and producing runbooks for engineers.

• Required hands-on experience with GCP security services: Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, and Binary Authorization.

• Required hands-on experience with AWS security services: GuardDuty, Security Hub, IAM, KMS, Macie, and AWS Config.

• Required knowledge of Kubernetes: GKE hardening, pod security standards, network policies, RBAC, and admission controllers.

• Required knowledge of GitLab: CI/CD security, SAST/DAST, dependency scanning, and pipeline policy management.

• Required knowledge of Terraform: IaC security scanning with tfsec and Checkov, along with secure module design.

• Required knowledge of Datadog: security monitoring, threat detection, and alert management.

• Required knowledge of Istio: mTLS, authorization policies, and service mesh security.

• CKS, Google Professional Cloud Security Engineer, or AWS Security Specialty certifications are desirable but not mandatory.

• Additional experience with tools such as Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, Splunk/Chronicle, Python or Go, eBPF security tools, penetration testing, red teaming, STRIDE or PASTA threat modeling, and service mesh security beyond Istio is a plus.


🏝️ Benefits

• Employees have the flexibility to work remotely.

People also viewed

VALCE Talent Solutions11 hours ago

AWS DevOps

MX flagMexico OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
4Pharma Ltd13 hours ago

Senior Dev Ops Engineer

IN flagIndia OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
MTP Brasil13 hours ago

DevOps Engineer

BR flagBrazil OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
BlackSky13 hours ago

Principal DevSecOps Architect

US flagVirginia, +1 more stateFull-timeDevOps & Site Reliability Engineer (SRE)$190k – $215k/year
ApplyView job
BPCS, Comprehensive marketing solutions, ltd.13 hours ago

DevSecOps Engineer

US flagWashington OnlyFull-timeDevOps & Site Reliability Engineer (SRE)$95k – $105k/year
ApplyView job
FTI - Frontier Technology Inc.16 hours ago

Senior DevOps Engineer

US flagAlabama, +3 more statesFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers