
DevSecOps Engineer
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Mexico.
• Identify, evaluate, prioritize, and address security vulnerabilities, including CVEs in containers, application dependencies, and infrastructure components.
• Work collaboratively with engineering and DevOps teams to remediate vulnerabilities throughout CI/CD pipelines, container images, Kubernetes workloads, and cloud infrastructure.
• Provide support and security for Kubernetes environments, with a preference for Azure Kubernetes Service (AKS).
• Implement and uphold security controls across cloud-native platforms, encompassing container security, image scanning, runtime security, and Kubernetes hardening.
• Utilize Static Code Analysis / SAST tools to pinpoint code-level security risks and assist development teams in addressing findings.
• Employ CSPM tools to identify and rectify cloud security misconfigurations.
• Automate security, compliance, and operational tasks using Bash and other scripting languages.
• Support secure software delivery processes, which include CI/CD security gates, vulnerability scans, policy enforcement, and compliance checks.
• Collaborate with global teams across various time zones on security initiatives, incident response, and platform enhancements.
• Advocate for DevSecOps best practices and integrate security into the software development lifecycle.
• Demonstrated experience as a DevSecOps Engineer, DevOps Engineer with a security emphasis, or Cloud Security Engineer.
• Practical experience in managing CVEs, vulnerability remediation, patching, and dependency upgrades.
• Direct experience in risk prioritization for security vulnerabilities.
• Extensive experience with Kubernetes, particularly AKS (Azure Kubernetes Service).
• Strong hands-on experience with Linux systems, including troubleshooting, hardening, and package management.
• Proficient in Linux permissions, services, networking, and logs.
• Solid experience in writing and maintaining Bash scripts.
• Familiarity with static code analysis tools such as SonarQube, Checkmarx, Veracode, Snyk Code, or Semgrep.
• Experience with CSPM tools like Prisma Cloud, Wiz, Microsoft Defender for Cloud, Orca, or Lacework.
• Knowledge of container security practices, including image scanning, base image management, secrets handling, and Kubernetes security policies.
• Proficient in English (both written and verbal).
• AI-driven tools and automation to facilitate smarter collaboration, accelerate processes, and promote continuous improvement.
• Opportunity to engage in AI-driven financial crime detection technology.
• Collaboration with global teams across various time zones.
• Professional experience in cloud-native security, DevSecOps, and financial technology.
Tether.to
CoorsTek, Inc.
Sigma Software Group
Tether.to
Get handpicked remote jobs straight to your inbox weekly.