Devsecops
Job description
A skilled and security-minded DevSecOps Engineer to embed security practices across software delivery lifecycle, cloud infrastructure, and operations. This engineer will work at the intersection of development, security, and operations - helping engineering teams ship software faster and more securely by automating security controls, integrating testing into CI/CD pipelines, and building a culture of security-by-design. This is a hands-on role that requires deep technical capability across cloud platforms, automation, and application/infrastructure security. You will partner closely with software engineers, platform engineers, and the security team to identify vulnerabilities early, enforce policies as code, and respond to threats across the software development and deployment landscape.
Key responsibilities
Secure CI/CD Pipeline & DevOps Integration • Design, implement, and maintain secure CI/CD pipelines by integrating automated security testing at every stage - SAST, DAST, SCA, secrets scanning, and container image scanning. • Embed security gates and policy enforcement into build and release pipelines (GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or equivalent). • Implement and manage software composition analysis (SCA) to track open-source dependencies, license risk, and vulnerability exposure. • Enforce code signing, artefact integrity, and secure supply chain practices across development and deployment workflows. • Champion shift-left security, working with development teams to resolve vulnerabilities early in the development lifecycle. Cloud Security & Infrastructure as Code • Implement and enforce cloud security controls across Azure, GCP, and/or AWS environments, covering IAM, network security, data protection, logging, and monitoring. • Write and maintain security-focused Infrastructure as Code (IaC) using Terraform, Bicep, Pulumi, or CloudFormation - with policy-as-code guardrails (OPA, Checkov, Sentinel, or equivalent). • Perform IaC scanning and configuration drift detection to ensure cloud environments remain compliant with security baselines. • Design and manage cloud security posture management (CSPM) tooling to provide continuous visibility into misconfiguration and risk. • Implement workload identity, secrets management (HashiCorp Vault, Azure Key Vault, GCP Secret Manager), and zero trust network access for cloud workloads. • Support container and Kubernetes security - including image hardening, admission controllers, network policies, and runtime threat detection (Falco, Sysdig, or equivalent). Vulnerability Management & Threat Detection • Own and drive the vulnerability management lifecycle - scanning, prioritization, remediation tracking, and reporting - across code, containers, cloud, and infrastructure. • Integrate vulnerability findings from tooling (Snyk, Qualys, Tenable, Prisma Cloud, or equivalent) into developer workflows for rapid triage and resolution. • Monitor threat intelligence and CVE disclosures; assess exposure and coordinate patching and remediation with engineering and operations teams. • Support SIEM onboarding, threat detection rule development, and security monitoring for cloud and application events. • Participate in incident response activities - containing, investigating, and remediating security incidents across cloud and application environments. Security Automation & Tooling • Develop and maintain security automation scripts, runbooks, and tooling using Python, Bash, Go, or equivalent languages. • Build automated compliance checks, security dashboards, and reporting to give teams real-time visibility into security posture. • Manage and tune security tooling across the technology stack - SAST, DAST, SCA, CSPM, EDR, WAF, and SIEM platforms. • Evaluate and onboard new security technologies and frameworks to continuously improve detection, prevention, and response capability. Governance, Compliance & Security Culture • Implement and maintain policy-as-code frameworks to enforce compliance with internal security standards and regulatory requirements (ISO 27001, SOC 2, NIST CSF, PCI DSS, GDPR). • Support security audits, penetration testing engagements, and risk assessments - coordinating remediation of findings. • Develop and deliver developer security training, secure coding guidance, and threat modelling workshops. • Contribute to security documentation, architecture review processes, and the organization’s security roadmap. • Collaborate with GRC, platform engineering, and application development teams to ensure security standards are understood and consistently applied.
Qualifications
• 5+ years of experience in DevSecOps, application security, cloud security, or a combined security and software engineering role. • Hands-on experience integrating security tooling (SAST, DAST, SCA, secrets scanning, container scanning) into CI/CD pipelines. • Strong experience with cloud security on at least one major platform - Azure, GCP, or AWS - including IAM, network controls, CSPM, and logging. • Proficiency with Infrastructure as Code (Terraform, Bicep, CloudFormation, or Pulumi) and policy-as-code tools (OPA, Checkov, Sentinel). • Experience with container security - Docker, Kubernetes, and runtime security tooling (Falco, Sysdig, or equivalent). • Scripting and automation skills in Python, Bash, and/or Go for building security tooling and workflows. • Solid understanding of application security principles - OWASP Top 10, threat modelling, secure SDLC, and vulnerability management. • Experience with vulnerability management platforms and the remediation lifecycle across code, cloud, and infrastructure. • Knowledge of security frameworks and standards including NIST CSF, ISO 27001, CIS Controls, SOC 2, and GDPR. • Strong communication skills - able to articulate technical security risks clearly to both engineering and non-technical audiences. PREFERRED QUALIFICATIONS • Experience with GitOps workflows and securing software supply chains (SBOM, SLSA, Sigstore, or equivalent). • Familiarity with service mesh security, mTLS, and zero trust architecture for microservices environments. • Experience with SIEM platforms (Splunk, Microsoft Sentinel, Chronicle, or equivalent) - including detection engineering and alert tuning.
Job overview
Number of positions
Salary range
Posted date
About RSNG Info Solutions
Founded
Company size
Industry
Website
Contact information
About
At RSNGINFO, we prioritize customer needs and dedicate ourselves to quality creations that aim to meet every aspect of our client’s requirements. We collaborate and contribute our expertise to adapt the best ways to improve our product services that are accessible, light, and easy to implement.