Job Openings
DevSecOps Engineer
About the job DevSecOps Engineer
Key Role & Responsibility:
Responsible for designing, automating, and maintaining secure, scalable, and resilient infrastructure and deployment pipelines:
- Develop automation capabilities to deploy, manage, monitor, and maintain applications and infrastructure.
- Design and maintain CI/CD pipelines for application deployment and release management.
- Implement infrastructure-as-code and environment automation practices.
- Manage cloud resources and platform services.
- Develop and maintain CI/CD tooling and automation to support software build, testing, integration, and release processes.
- Monitor and optimise platform availability, performance, utilisation, reliability, and operational health.
- Implement security controls and ensure compliance with government security requirements.
- Plan, implement, and monitor system security architecture, including threat and risk assessments.
- Conduct vulnerability assessments, system hardening, security reviews, and remediation activities.
- Implement disaster recovery, backup, and business continuity measures.
- Investigate, troubleshoot, and resolve system, application, and infrastructure issues.
- Collaborate closely with developers to integrate security throughout the software development lifecycle.
- Coordinate and work together with other members of the team.
Experience & Skills Needed:
- Strong understanding of Software Development Lifecycle (SDLC), CI/CD, Test-Driven Development (TDD), and DevSecOps practices.
- Experience designing, deploying, and supporting cloud-native applications and infrastructure on AWS. Experience with GCC environment is advantageous.
-
Proficiency in at least two programming/scripting languages:
- Bash
- PowerShell
- Python
- JavaScript
- Java
- Experience with infrastructure-as-code and automation tools such as Terraform, Ansible, or equivalent technologies.
- Experience with containerisation and orchestration technologies including Docker and Kubernetes.
- Experience with source code management, GitLab workflows, and CI/CD platforms.
- Experience implementing monitoring, logging, and observability solutions to support platform reliability and operational excellence.
- Knowledge of application security and cloud security, secure coding practices, and DevSecOps principles.
- Hands-on experience with vulnerability management, security assessments, system hardening, and remediation activities.
- Familiarity with cloud-native and Cloud Native Computing Foundation (CNCF) tools (Prometheus, Helm, ArgoCD, Istio, Gatekeeper, Crossplane).
- Familiarity with enterprise security and secrets management solutions (HashiCorp Vault, Tenable, Fortify, Sonatype Nexus IQ, AWS security services).
- Experience with AWS services related to identity and access management, networking, monitoring, container platforms, and security.
- Strong troubleshooting, incident response, and operational support skills.
- Experience working in regulated or government environments is preferred.