- Company Name
- Next Ventures
- Job Title
- DevSeOps Engineer
- Job Description
-
**Job Title:** DevSecOps Engineer (Senior / Expert)
**Role Summary:**
Senior engineer responsible for securing large‑scale Azure cloud platforms, containerized workloads, and automated CI/CD pipelines. Combines deep offensive security expertise with infrastructure and DevOps engineering to embed security throughout the infrastructure lifecycle, partner with Cloud, SRE, Platform, and Architecture teams, and drive continuous hardening and remediation.
**Expectations:**
- 8+ years of experience in infrastructure, cloud (Azure), and DevSecOps.
- Offensive security mindset with proven ability to assess, pen‑test, and threat‑model cloud and container environments.
- Strong automation skills; able to build and tune security tooling, AI‑assisted detection, and compliance pipelines.
- Leadership and mentorship capacity to guide engineering teams on secure design and incident response.
- Excellent communication and analytical problem‑solving abilities.
**Key Responsibilities:**
- Conduct security assessments, penetration testing, and threat modeling of Azure services, IAM, networking, and Kubernetes clusters.
- Review and remediate IaC (Terraform/Bicep/ARM) and platform configurations for misconfigurations.
- Integrate and manage security tools (Snyk, DAST, SAST, SCA, container scanners) within Azure DevOps pipelines; automate security gates and policy enforcement.
- Harden Docker images, container registries, and Kubernetes runtime (network policies, PSP/Pod Security Standards).
- Lead security reviews for new infrastructure components and major platform changes; provide secure design patterns.
- Participate in incident response, root‑cause analysis, and long‑term remediation for infrastructure‑level incidents.
- Develop dashboards, metrics, and telemetry pipelines for infrastructure security visibility.
- Mentor cross‑functional teams and promote a security‑first culture.
**Required Skills:**
- Offensive security targeting cloud, APIs, and containers; hands‑on exploitation (Burp Suite, ZAP, Nmap, Metasploit).
- Deep Azure expertise: IAM, networking, App Services, Functions, Storage, Key Vault, monitoring.
- IaC proficiency (Terraform, Bicep, ARM) and secure code review (C#, Java, JavaScript/TypeScript, Python).
- CI/CD security with Azure DevOps; Snyk (SAST, SCA, IaC, Cloud) integration.
- Container & Kubernetes security fundamentals; Docker image hardening.
- Identity & access security (OAuth2, OIDC, JWT, Azure AD).
- Threat‑modeling frameworks (MITRE ATT&CK, STRIDE).
- Strong analytical, problem‑solving, and communication skills; ability to mentor teams.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent professional experience.
- Security certifications preferred (e.g., CISSP, OSCP, CEH, Azure Security Engineer Associate).