
Senior DevSecOps Engineer
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Netherlands.
• Develop and sustain secure CI/CD pipelines utilizing Azure DevOps or GitHub Actions.
• Enforce secrets hygiene, signed artifacts/SBOMs, SAST/DAST/container scanning, least-privilege service connections, and enhance supply-chain security.
• Automate infrastructure security through Terraform, implement policy-as-code guardrails, and conduct continuous IaC scanning.
• Strengthen Kubernetes security by leveraging RBAC, NetworkPolicies, Pod Security Standards, secret management, image signing/scanning, and admission policies.
• Safeguard cloud identities and data with Entra ID roles/Managed Identities, Key Vault, Private Link/NSGs, encryption, and least-privilege access controls.
• Secure ML/MLOps environments, including Databricks, MLflow/model registry, feature stores, model artifact signing, provenance, and runtime isolation.
• Integrate platform and security telemetry with Microsoft Sentinel and Defender; establish alerts and runbooks, and support incident response and tabletop exercises.
• Manage CVEs and vulnerabilities, publish SBOMs, coordinate mitigations and patches, monitor exposure windows and SLAs, verify remediation, and report metrics.
• Create and maintain reference architectures, trust-boundary diagrams, data-classification schemes, environment isolation patterns, secret/key-management patterns, and network segmentation.
• Participate in risk assessments, threat modeling, DPIAs, vendor risk reviews, penetration tests, control testing, evidence collection, and audit readiness for ISO 27001, GDPR, EU AI Act, and NIS2 as applicable.
• Uphold security baselines and exceptions, own platform security KPIs, ensure retention policies and access reviews, and maintain comprehensive audit trails.
• Proven experience as a DevSecOps / Cloud Security Engineer or DevOps Engineer with a strong emphasis on security within Azure and Kubernetes environments.
• Practical experience with Azure DevOps or GitHub Actions.
• Proficient understanding of Azure security, encompassing Entra ID, Key Vault, Azure Policy, Defender for Cloud, and Microsoft Sentinel.
• Familiarity with Kubernetes security practices.
• Knowledge of vulnerability management and CVEs, including SBOM creation, dependency/container/IaC scanning, triage and prioritization, remediation workflows, and SLA tracking.
• Insight into Data & AI/ML security, comprising Databricks, Unity Catalog, SCIM/AAD, MLflow/model registry, secrets management, data governance, and privacy-by-design principles.
• Comfortable working with central Security and compliance teams and contributing to audits and group standards.
• Capability to translate requirements into actionable controls.
• Shift-left approach and ability to collaborate across teams effectively.
• Experience with Terraform, policy-as-code, Azure Policy, OPA/Conftest, Checkov/tfsec, RBAC, NetworkPolicies, Pod Security Standards, Gatekeeper/Kyverno, image scanning, CodeQL/Dependabot, and Databricks security is advantageous or relevant to the position.
• Work-from-home flexibility, including up to 20 days annually anywhere within the EU.
• Regular team gatherings and celebrations.
• Kindergarten grant of €100 per month for employees covering childcare expenses.
• Anonymous, complimentary professional psychological support.
• Access to internal and external training and career development resources.
• Fully sponsored Deutschland Ticket.
• Urban Sports Club membership (M package) and opportunities for sports and health activities.
Cisco
Stefanini Brasil
Study Now
Spring Financial
Get handpicked remote jobs straight to your inbox weekly.