About the Role
Build, test, and maintain infrastructure and tools that allow for secure, agile software development and automated releases;
Document DevOps processes, including developing standards to guide operations, support, and maintenance;
Ensure secure platform/infrastructure/delivery design;
Automate security controls across cloud posture, policy enforcement, and container scanning/hardening, reducing manual effort and improving remediation speed;
Work together with the Security and Platform teams;
Identify manual processes that can be automated efficiently;
Mentor other engineers, define our technical security culture, and help build an Web Security team presence across our product range.
Drive cloud security posture improvements using CSPM tooling, including automation, prioritization, and remediation workflows;
Implement and establish supply-chain security controls, kubernetes security guardrails
Enable and operate cloud-native security controls across CI/CD and Kubernetes (CSPM/CNAPP, policy-as-code, container scanning, image hardening).
Core Requirements
Knowledge in Docker, Kubernetes, CI/CD Pipeline (GitLab, Azure DevOps), Infrastructure design, and IaC (Terraform, Ansible);
Strong Cloud Agnostic experience (AWS preferred);
Demonstrated experience with secure development, coding, and engineering practices;
Proficiency in automation and monitoring tools (ability to automate repeatable tasks via scripting) for Linux and Windows environments;
Experience with Security as Code (SaC) tools;
Understanding of DevSecOps Maturity Model.
Tech Stack
DockerKubernetesCI/CD PipelineGitLabAzure DevOpsInfrastructure designIaCTerraformAnsibleAWSSecure developmentCodingEngineering practicesAutomationMonitoring toolsLinuxWindowsSecurity as CodeCSPMCNAPPPolicy-as-codeContainer scanningImage hardening