
DevSecOps Engineer
Posted Sep 4

Posted Sep 4
This is a fully remote position, open to applicants in Egypt, +1 more country.
• Take ownership of cloud security posture management across GCP and AWS, focusing on ongoing assessment, misconfiguration detection, and tracking remediation efforts.
• Design and enforce IAM policies, ensure proper service account hygiene, implement least-privilege access controls, and manage workload identity in multi-cloud environments.
• Implement VPC security measures, including firewall rules, network policies, ingress/egress restrictions, and Private Google Access.
• Secure and internalize service endpoints through the use of internal load balancers, private endpoints, and VPN/interconnect; consistently work to minimize the public attack surface.
• Oversee secrets management utilizing GCP Secret Manager and AWS Secrets Manager, remove hardcoded credentials, and programmatically rotate secrets.
• Lead incident response for cloud and Kubernetes security: triage, contain, investigate, and remediate incidents.
• Manage compliance reporting for SOC 2, HIPAA, and ISO 27001, including evidence collection, gap analysis, and implementation of controls.
• Conduct threat modeling, security reviews, and risk assessments for architecture.
• Strengthen GKE clusters by applying CIS benchmarks, pod security standards, and admission control policies.
• Implement Kubernetes network policies, RBAC, runtime security tools, and controls for the container supply chain.
• Apply Istio security controls, such as mTLS, authorization policies, and observability for east-west traffic.
• Secure GitLab CI/CD pipelines through runner protection, permission restrictions, branch protection, MR approvals, integrated security scanning, and policy-as-code.
• Establish mandatory Terraform IaC security gates with tfsec and Checkov.
• Manage GitLab token hygiene, including expiry policies, project token rotation, and audits of personal access tokens.
• Audit public endpoints and maintain controls for WAF, Cloud Armor, TLS, bastion hosts, DNSSEC, private DNS, and split-horizon DNS.
• Develop security automation pipelines for policy enforcement, compliance checks, and vulnerability remediation as code.
• Instrument security observability in Datadog, including threat detection dashboards and alert tuning.
• Create runbooks for incidents, vulnerability responses, and access reviews.
• Promote security training and awareness; lead secure code reviews and threat modeling workshops.
• 7+ years of experience in DevSecOps, cloud security, or infrastructure security engineering.
• Extensive hands-on experience in securing Kubernetes clusters in production environments, focusing on RBAC, network policies, pod security, and runtime protection.
• Proven expertise with GCP and/or AWS security services, as well as IAM design.
• Strong knowledge of CI/CD security, encompassing pipeline hardening, secrets management, and integrated scanning.
• Experience in internalizing service endpoints and minimizing the cloud attack surface.
• Familiarity with compliance standards such as HIPAA, SOC 2, or ISO 27001 in regulated settings.
• Excellent communication skills, capable of articulating critical vulnerabilities to a CTO and producing runbooks for engineers.
• Required hands-on experience with GCP security services: Security Command Center, IAM, VPC Service Controls, Cloud Armor, Secret Manager, and Binary Authorization.
• Required hands-on experience with AWS security services: GuardDuty, Security Hub, IAM, KMS, Macie, and AWS Config.
• Required knowledge of Kubernetes: GKE hardening, pod security standards, network policies, RBAC, and admission controllers.
• Required knowledge of GitLab: CI/CD security, SAST/DAST, dependency scanning, and pipeline policy management.
• Required knowledge of Terraform: IaC security scanning with tfsec and Checkov, along with secure module design.
• Required knowledge of Datadog: security monitoring, threat detection, and alert management.
• Required knowledge of Istio: mTLS, authorization policies, and service mesh security.
• CKS, Google Professional Cloud Security Engineer, or AWS Security Specialty certifications are desirable but not mandatory.
• Additional experience with tools such as Falco, OPA/Gatekeeper, HashiCorp Vault, Wiz/Orca/Prisma Cloud, Trivy/Snyk, Splunk/Chronicle, Python or Go, eBPF security tools, penetration testing, red teaming, STRIDE or PASTA threat modeling, and service mesh security beyond Istio is a plus.
• Employees have the flexibility to work remotely.
VALCE Talent Solutions
4Pharma Ltd
MTP Brasil
BlackSky
Get handpicked remote jobs straight to your inbox weekly.