We’re looking for a Senior DevSecOps Engineer to help us take our security work further through automation across SOC and DevSecOps processes. You’ll join AppSec Cheetahs, our team of ethical hackers. We look for vulnerabilities, strengthen application security, and share our knowledge with other engineers. In this role, you’ll build and improve security solutions, develop automation with Python, create and maintain CI/CD pipelines, and explore AI integrations to make security processes more efficient. It’s a great opportunity to combine your DevOps and Python expertise with Application Security, work on real security challenges, and have a direct impact on the security of our products. Key Responsibilities Integrate Security into CI/CD: Design, build, and maintain a secure CI/CD pipeline by integrating static (SAST), dynamic (DAST), and interactive (IAST) application security testing tools. Automation: Develop and implement automation for security processes, vulnerability management, and compliance checks to ensure continuous security feedback. Infrastructure as Code (IaC) Security: Secure IaC scripts (e.g., Terraform, CloudFormation) by scanning for misconfigurations and vulnerabilities before deployment. Tooling & Maintenance: Evaluate, implement, and manage security tools for vulnerability scanning, monitoring, and compliance. Mentorship & Advocacy: Act as a security champion within the organization. Mentor developers and operations teams on secure coding practices and DevSecOps principles. Skills, Knowledge and Expertise Experience: 5+ years of experience in a DevOps, Security Engineering, or a similar role, with at least 2 years focused specifically on DevSecOps. CI/CD Expertise: Proven experience with CI/CD tools such as Jenkins, GitLab CI, any else. Scripting Proficiency: Strong scripting skills in languages like Python, Bash, or Go for automation tasks. Cloud Platform Knowledge: Knowledge of at least one major cloud provider (AWS, Azure, or GCP) and its security services (e.g., AWS Security Hub, Azure Security Center, GCP Security Command Center). IaC Skills: Experience with Infrastructure as Code tools like Terraform, Ansible, or CloudFormation. Container Security: Strong understanding of containerization technologies (Docker, Kubernetes) and their security challenges, including securing container images and runtime environments. Security Tools: Familiarity with a wide range of security tools, such as SAST (e.g., SonarQube, Checkmarx), DAST (e.g., OWASP ZAP, Burp Suite), and vulnerability scanners (e.g., Trivy, Nessus). Soft Skills: Problem solving abilities, strong communication skills, and the ability to work collaboratively across different teams.
DevSecOps Engineer
Sumsub
NetSuite Developer
TradingView
Backend Team Lead - Payment Systems (.NET)
B2Tech
Head of IT Support & Workplace
Vivid
Backend Unit Lead
TradingView
Mid-Senior PHP Developer
Fayara