
Senior DevSecOps Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Cyprus.
• Continuously enhance the security of AWS and Kubernetes platforms.
• Strengthen IAM, RBAC, encryption, secrets management, and network controls through secure-by-default policy-as-code.
• Oversee edge security, which includes traffic filtering, WAF configuration, and management of external exposure.
• Conduct security assessments of new services, architectural modifications, and platform elements.
• Integrate automated security controls within the SDLC and CI/CD processes, incorporating SAST, dependency and container scanning, and policy enforcement.
• Lead vulnerability management efforts, which encompass detection, assessment, prioritization, and reporting.
• Incorporate automation and AI-assisted tools to improve security evaluations and minimize manual labor.
• Define and apply security measures for AI infrastructure elements, including gateways, MCP servers, and model proxies.
• Identify and address AI-specific vulnerabilities such as prompt injection, data leakage, and agent privilege escalation.
• Collaborate closely with security and engineering teams to implement hands-on enhancements and shape long-term security strategies.
• Over 5 years of practical experience in DevSecOps, Cloud Security, or related domains.
• Extensive hands-on experience managing AWS and Kubernetes in live production settings.
• Proven experience in implementing security within Infrastructure as Code and CI/CD processes.
• Comprehensive understanding of access control, secrets management, network security, and encryption practices.
• Familiarity with container security and prevalent application security threats.
• Profound knowledge of AI/LLM security challenges, including prompt injection, data leakage, model abuse, and agent privilege escalation.
• Practical experience in securing AI infrastructure components such as LLM gateways, MCP servers, or agent-based workflows.
• Proficient in scripting and comfortable working within Git-based development environments.
• Ability to collaborate effectively with engineering and product teams.
• Excellent written and verbal communication skills in English.
• Experience in scaling security practices within rapidly growing or regulated environments is a plus.
• Experience in developing internal security tools or automation from the ground up is a plus.
• Hybrid working model available in the Limassol or Almaty office, or fully remote for those outside office locations.
• Relocation assistance to Cyprus, including visa and package support, when necessary.
• Budget allocated for learning and development.
• Fully compensated vacation and sick leave.
• Sports compensation provided.
• Real opportunities for career growth.
• Significant responsibility with the ability to make an immediate impact.
CWILL
a37
GT
Sigma Software Group
Get handpicked remote jobs straight to your inbox weekly.