Devsecops Engineer

clinikally

📍 Worldwide🕐 1mo ago🔗 findwork

Skills

kubernetesdockerawsazurejenkinsgithubgcppythonterraformhelmbashfintechgitlab

Job Description

We are looking for a **security-focused DevSecOps Engineer with 1-2 years of experience** to help embed security across the software development lifecycle while maintaining deployment speed, platform reliability, and compliance. This role will work closely with engineering, infrastructure, and security teams to strengthen CI/CD security, cloud governance, infrastructure automation, vulnerability management, monitoring, and secure deployment practices. **Roles and Responsibilities** Secure DevOps & CI/CD * Build, maintain, and optimize secure CI/CD pipelines for reliability, speed, and controlled releases. * Implement **shift-left security** by integrating security checks early in the development lifecycle. * Configure automated quality, vulnerability, and security gates within release pipelines. * Support secure, zero-downtime deployment strategies and rollback mechanisms. * Ensure release workflows follow secure SDLC and change-management practices. Cloud and Infrastructure Security * Manage and secure cloud environments across AWS, GCP, or Azure. * Develop and maintain Infrastructure-as-Code using Terraform. * Package and deploy applications to Kubernetes using Helm. * Implement cloud security controls, including IAM policies, least-privilege access, network segmentation, and secure configuration management. * Strengthen Docker and Kubernetes security, including image hardening, access controls, and workload protection. Application and Platform Security * Integrate SAST, DAST, SCA, container scanning, and vulnerability assessment tools into CI/CD pipelines. * Track vulnerabilities, coordinate remediation, and ensure closure within defined timelines. * Implement secure secrets management, certificate management, and encryption practices. * Participate in application, infrastructure, and architecture security reviews. * Support security testing and remediation across applications and platforms. Compliance, Monitoring and Incident Readiness * Support compliance with frameworks such as ISO 27001, SOC 2, PCI-DSS, and other regulatory requirements. * Maintain centralized security logging, monitoring, alerting, and audit trails. * Track security posture, vulnerabilities, access reviews, and compliance metrics. * Support incident response readiness, security investigations, and remediation activities. * Maintain documentation required for audits, risk assessments, and compliance reviews. Automation and Reliability * Automate repetitive infrastructure, deployment, and security processes. * Improve observability through effective logging, monitoring, alerting, and dashboards. * Support disaster recovery, backup validation, resilience testing, and business continuity initiatives. * Collaborate with SRE and platform teams to improve availability, scalability, and operational security. Required Qualifications * **1-2 years of experience** in DevSecOps, DevOps, Cloud Security, SRE, or a related role. * Hands-on experience with at least one cloud platform: AWS, GCP, or Azure. * Strong working knowledge of Terraform for Infrastructure-as-Code. * Hands-on experience with Kubernetes, Docker, and Helm. * Experience with CI/CD tools such as Jenkins, GitHub Actions, GitLab CI, Azure DevOps, or similar platforms. * Practical understanding of DevSecOps, secure SDLC, vulnerability management, and security automation. * Experience integrating or working with SAST, DAST, SCA, container scanning, or vulnerability management tools. * Understanding of IAM, least-privilege access, network security, secrets management, and encryption. * Proficiency in at least one scripting or programming language, such as Python, Go, or Bash. * Ability to collaborate with engineering teams and drive timely closure of security issues. Good to Have * AWS, GCP, Azure, Kubernetes, CKA, or CKAD certification. * Exposure to ISO 27001, SOC 2, PCI-DSS, HIPAA, or similar compliance frameworks. * Experience working in healthcare, fintech, or another regulated industry. * Familiarity with SIEM, CSPM, WAF, cloud-native security tools, and incident-response processes. * Experience with tools such as SonarQube, Snyk, Trivy, Checkmarx, Veracode, OWASP ZAP, or similar platforms.
Devsecops Engineer at clinikally | MergeJobs