Job Openings DevSecOps Engineer

About the job DevSecOps Engineer

Key Role & Responsibility:
Responsible for designing, automating, and maintaining secure, scalable, and resilient infrastructure and deployment pipelines:
  • Develop automation capabilities to deploy, manage, monitor, and maintain applications and infrastructure.
  • Design and maintain CI/CD pipelines for application deployment and release management.
  • Implement infrastructure-as-code and environment automation practices.
  • Manage cloud resources and platform services.
  • Develop and maintain CI/CD tooling and automation to support software build, testing, integration, and release processes.
  • Monitor and optimise platform availability, performance, utilisation, reliability, and operational health.
  • Implement security controls and ensure compliance with government security requirements.
  • Plan, implement, and monitor system security architecture, including threat and risk assessments.
  • Conduct vulnerability assessments, system hardening, security reviews, and remediation activities.
  • Implement disaster recovery, backup, and business continuity measures.
  • Investigate, troubleshoot, and resolve system, application, and infrastructure issues.
  • Collaborate closely with developers to integrate security throughout the software development lifecycle.
  • Coordinate and work together with other members of the team.
Experience & Skills Needed:
  • Strong understanding of Software Development Lifecycle (SDLC), CI/CD, Test-Driven Development (TDD), and DevSecOps practices.
  • Experience designing, deploying, and supporting cloud-native applications and infrastructure on AWS. Experience with GCC environment is advantageous.
  • Proficiency in at least two programming/scripting languages:
    • Bash
    • PowerShell
    • Python
    • JavaScript
    • Java
  • Experience with infrastructure-as-code and automation tools such as Terraform, Ansible, or equivalent technologies.
  • Experience with containerisation and orchestration technologies including Docker and Kubernetes.
  • Experience with source code management, GitLab workflows, and CI/CD platforms.
  • Experience implementing monitoring, logging, and observability solutions to support platform reliability and operational excellence.
  • Knowledge of application security and cloud security, secure coding practices, and DevSecOps principles.
  • Hands-on experience with vulnerability management, security assessments, system hardening, and remediation activities.
  • Familiarity with cloud-native and Cloud Native Computing Foundation (CNCF) tools (Prometheus, Helm, ArgoCD, Istio, Gatekeeper, Crossplane).
  • Familiarity with enterprise security and secrets management solutions (HashiCorp Vault, Tenable, Fortify, Sonatype Nexus IQ, AWS security services).
  • Experience with AWS services related to identity and access management, networking, monitoring, container platforms, and security.
  • Strong troubleshooting, incident response, and operational support skills.
  • Experience working in regulated or government environments is preferred.