← Усі вакансії

Security DevOps Engineer (DevSecOps)

Джерело:
djinni.co
Відгукнутись на вакансію →

Що робити

  • Harden cloud infrastructure (AWS: EKS, EC2, RDS, S3, IAM), secondary hosting and the CDN/WAF layer against CIS Benchmarks — everything as code in Terraform.
  • Access management: least-privilege IAM roles, MFA, privileged access (session-based access, no static keys), break-glass procedures; user and role exports for periodic access reviews.
  • Security monitoring: operate the SIEM/HIDS (Wazuh — rules, decoders, configuration assessment, agent rollout), GuardDuty, CloudTrail and Security Hub; route security alerts to the on-call engineer (duty rotation in PagerDuty, including out-of-hours escalation; tune false positives).
  • Vulnerability management: scanning (Inspector, Trivy, Wazuh), prioritisation, tracking remediation against SLA, retesting.
  • CI/CD security (GitHub Actions with self-hosted runners): SAST and SCA (Sonar, Trivy), secret scanning, branch protection, container image scanning, no secrets in code.

Що очікуємо

  • 3+ years in DevOps / SRE / cloud engineering, of which at least 1 year with security responsibilities.
  • Solid AWS: IAM, VPC, EKS, KMS, CloudTrail, GuardDuty.
  • Kubernetes in production: RBAC, network policies, Pod Security, secrets handling.
  • Terraform and an infrastructure-as-code mindset; Git workflow with code review.
  • Linux administration and hardening.

Що пропонуємо

  • Fintech or payments background; PCI DSS (CDE segmentation, QSA audit preparation).
  • Familiarity with DORA, ISO/IEC 27001, CIS Controls.
  • Teleport, JumpCloud, Falco, Cloudflare Zero Trust / WAF.
  • Certifications: AWS Certified Security – Specialty, CKS, CKA, CompTIA Security+.
  • Python or Bash scripting for automated checks.

Схожі вакансії

З блогу Trackr

Усі статті →

Знайдено через trackr.help/jobs · Канал: @trackrhelp · Бот для персональних сповіщень: @trackrhelpBot