
DevSecOps Engineer
Posted Jul 21

Posted Jul 21
This is a fully remote position, open to applicants in Brazil.
• Integrate automated security scanning tools (SAST, DAST, container scanning) into CI/CD pipelines.
• Maintain and audit compliance of cloud infrastructure (e.g., SOC2, HIPAA, GDPR) using automated policies.
• Implement security best practices in Terraform and Infrastructure as Code (IaC).
• Monitor and address cloud security incidents proactively.
• Design, implement, and sustain cloud infrastructure primarily within AWS.
• Assist in managing Kubernetes clusters that run microservices.
• Strengthen Kubernetes clusters by applying network policies, RBAC, and secure pod security standards.
• Identify and explore opportunities for automation and optimization in deployment and infrastructure management.
• Clearly and effectively document processes, infrastructure, and decision-making.
• Collaborate closely with the Information Security Lead on compliance audits, control evidence, and prioritizing the security roadmap.
• A minimum of 5 years of practical experience in a DevSecOps or security-oriented engineering position.
• Demonstrated expertise with AWS services, particularly IAM, EC2, RDS, EKS, and OpenSearch.
• Extensive experience with Kubernetes and its associated tools.
• Strong command of Terraform for automating infrastructure.
• Familiarity with CI/CD tools.
• Knowledge of Bash or other shell scripting languages.
• Awareness of contemporary security tools (vulnerability management, secrets management).
• Solid understanding of "shift-left" security principles.
• An analytical mindset with a keen eye for detail and a dedication to producing high-quality work.
• Excellent communication skills, both verbal and written.
• Comfortable collaborating within a distributed team while also being capable of independently driving tasks to completion.
• Health insurance.
• Flexible work arrangements.
CWILL
a37
GT
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.