ME

DevSecOps Engineer Internship

Hiring from
Worldwide
Work type
Remote
Posted
Sep 24, 2026
Is this job info correct?

Overview: Securing the CI/CD Pipeline

The DevSecOps Engineer is responsible for automating, integrating, and enforcing security controls throughout the entire development lifecycle, from code commit to production deployment. You will be the vital link between Development, Security, and Operations, ensuring that the continuous integration and delivery pipelines for our e-commerce platform, internal tools, and AI agents are secure by design.

Internship Details

Duration: 3 months
Start Date: Immediate
Location: Remote
Stipend: None initially. Based on your first-quarter performance, you may be offered a paid full-time opportunity, or even be absorbed directly by the client as an FTE.

Key Responsibilities & Core Projects

You will embed security into the automation processes across the entire tech stack.

  • Security Automation (CI/CD): Integrate automated security scanning tools, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), directly into our CI/CD pipelines (managed via Makefile and automated testing pipelines).

  • Infrastructure Security: Enforce secure Infrastructure-as-Code (IaC) practices using Terraform for provisioning and managing our Oracle Cloud Free VMs. Continuously monitor the cloud infrastructure for vulnerabilities and misconfigurations.

  • Container and Runtime Security: Manage and secure the application deployment environment by implementing robust container security policies for Docker and ensuring runtime threat detection and logging for production services.

  • Collaboration & Remediation: Collaborate directly with development teams to promote secure coding practices, provide guidance on vulnerability remediation, and ensure security findings are addressed before deployment.

  • Secrets Management: Implement automated injection and rotation of secrets using Vault into the applications and deployment environment.

  • Observability Integration: Integrate security logs and metrics into the observability stack (Prometheus, Grafana, Loki) to ensure real-time security monitoring and alerting.

Required Technologies & Tools

Candidates must have strong hands-on experience in both DevOps automation and security implementation:

  • Automation/CI/CD: Makefile, automated testing, scripting (Bash/Python/Node.js).

  • Security Tools: SAST/DAST tools, vulnerability scanners, runtime protection.

  • Infrastructure: Terraform (IaC), Docker, Oracle Cloud/equivalent IaaS.

  • Security & Auth: Vault (Secrets Management), Traefik (Edge Security), Observability stack (Prometheus, Loki).

  • Codebase: Experience securing applications built with Node.js/NestJS and Next.js/React/TypeScript.

AI Agent Focus

You will ensure the secure deployment and operation of our AI layer.

  • Secure Deployment: Implement dedicated, hardened deployment pipelines for AI agents (built on LangChain/LlamaIndex), isolating them and controlling their access to core supply chain data (MES, WMS, OMS).

  • Runtime Monitoring: Establish specific security logging and monitoring for LLM-related services to detect unusual access patterns or potential data leakage.

Success Metrics & Career Path

Performance will be measured by:

  • Pipeline Security: Percentage of security checks automated and integrated into the CI/CD pipeline.

  • Vulnerability Reduction: Measurable reduction in critical and high-priority findings in production and pre-production environments.

  • Compliance: Successful auditing and enforcement of secure IaC and container security policies.

Mentorship Structure: Reports to the Solution Architect or DevOps Lead, working directly with infrastructure and development teams to implement security-as-code.


Similar jobs

Apply for this job