
DevSecOps Engineer, SentinelOps, DevEx, Cloud Enablement
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Romania.
• Incorporate security practices throughout the entire Software Development Life Cycle (SDLC), from code review to production deployment;
• Integrate and sustain security tools within GitLab CI/CD pipelines, offering them as reusable templates instead of custom solutions for each team;
• Identify and resolve security vulnerabilities within infrastructure and CI/CD pipelines; strengthen merge and approval policies in GitLab;
• Contribute to threat modeling initiatives and assist teams in applying these practices to their designs;
• Integrate and maintain tools for risk assessment, vulnerability detection, prevention, and resolution.
• Operate and manage Kubernetes clusters deployed both on-premises and in the cloud, ensuring high availability, scalability, and security;
• Implement disaster recovery and high availability strategies across various environments;
• Automate operational workflows and infrastructure management through scripting (Bash, Python, Go);
• Document infrastructure configurations, deployment procedures, and operational runbooks;
• Concentrate on managing infrastructure using Infrastructure as Code (IaC) tools (terraform/terragrunt), standardizing reusable GitLab CI/CD pipelines;
• Leverage AI and specialized agents to analyze our multi-account, multi-cloud infrastructure, correlating findings, misconfigurations, and drift at scale to minimize time-to-fix;
• Transform cross-account analyses into actionable insights for the teams responsible for the affected workloads;
• Establish standards for the safe use of agentic tooling on production infrastructure, including scoped permissions, guardrails, and necessary human review.
• Design and implement preventive controls across various cloud environments, including organization-level deny and audit policies, Service Control Policies (SCPs), GCP Organization Policies, and account factory standards;
• Write infrastructure and policy as code using Terraform; scripting and automation are integral to daily operations, not just occasional tasks;
• Develop compliance drift detection, alerting, and conduct periodic compliance reviews focusing on NIS2, DORA, and GDPR obligations;
• Manage cloud security posture by triaging and driving remediation efforts based on findings from cloud security tools.
• Create and maintain security monitoring, alerting, and incident response playbooks, consolidating cloud-native detections into a unified Security Information and Event Management (SIEM) system;
• Implement observability measures such as monitoring, alerting, and logging to facilitate proactive incident response;
• Oversee vulnerability assessments, coordinate remediation with development teams, and track resolution against Service Level Agreements (SLAs);
• Support and coordinate regular security audits and penetration testing activities;
• Engage in production incident response and participate in the on-call rotation with the team.
• A minimum of 3 years of hands-on experience as a DevOps, DevSecOps, Platform, Site Reliability Engineer (SRE), or Security Engineer, or as a developer who has transitioned towards infrastructure and security.
• Practical experience with at least one major cloud provider and solid Linux systems administration.
• Proficiency in using Terraform for Infrastructure as Code.
• Familiarity with cloud security tools (such as AWS GuardDuty, Security Hub, and GCP Security Command Center).
• Experience with containers and orchestration technologies (Docker, Kubernetes) and CI/CD pipelines (GitLab CI, Jenkins, or similar).
• Strong understanding of security fundamentals, including Identity and Access Management (IAM), encryption, network security, and secrets management.
• Experience with monitoring, logging, and alerting solutions; working knowledge of High Availability (HA), disaster recovery, and business continuity concepts.
• Comfort in utilizing AI tools as part of the daily engineering workflow.
• A proactive attitude with the ability to prioritize tasks in a fast-paced environment.
• Medical subscription options: Medicover or Regina Maria.
• A flexible budget to invest in personal development as desired: meal tickets, holiday tickets, cultural vouchers, private pension, foreign language classes, eMAG, Fashion Days, Therme & Genius, gym memberships, or even professional development courses.
• Various discounts from our partners, including banking, mobile services, dental care, and wellness.
• Access to the Bookster library and free credits on the Hilio psycho-emotional health platform.
• An accelerated learning environment with access to over 100,000 curated online resources and platforms, learning academies, and development programs.
• A new headquarters featuring sleek design, natural light, and flexible spaces that foster an energizing and comfortable atmosphere for hybrid work.
CWILL
a37
GT
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.