- Company Name
- Epsilon Solutions Ltd.
- Job Title
- DevSecOps Engineer
- Job Description
-
Job title: DevSecOps Engineer
Role Summary: Architect, build, and secure APIs and CI/CD pipelines while integrating threat modeling, secure coding, and automation across development, operations, and security teams.
Expactations: Deliver secure, well‑tested code, maintain database integrity, run automated security scans, and ensure compliance with industry standards (OWASP, SANS, ISO 27001, SOC 2). Execute continuous security integration and promote a culture of security throughout the software lifecycle.
Key Responsibilities:
- Design and implement RESTful APIs with robust authentication (OAuth2, JWT).
- Secure and optimize PostgreSQL and RDBMS against injection, data leakage, and unauthorized access.
- Conduct threat modeling and secure architecture reviews during planning stages.
- Script automation for security scans, compliance checks, and deployment workflows.
- Build and maintain CI/CD pipelines with integrated SAST, DAST, dependency scanning, and secrets management.
- Debug and resolve functional and security issues in dev, test, and prod environments.
- Collaborate with developers, ops, and security to embed security into all cross‑functional work.
Required Skills:
- Secure coding (OWASP Top 10, SANS CWE).
- API security (OAuth2, JWT, input validation).
- CI/CD security integration (SAST, DAST, dependency scanning).
- Proficiency in Python, JavaScript, Java, or Go with secure coding focus.
- PostgreSQL database security.
- Threat modeling and secure architecture reviews.
- Security automation scripting.
Desired Skills:
- Cloud security (AWS, GCP, Azure).
- Container security (Docker, Kubernetes, image scanning).
- IaC security (Terraform, Ansible).
- Security compliance (SOC 2, ISO 27001).
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Certifications: CISSP, CISM, CompTIA Security+, or equivalent.
- DevOps relevant certifications (AWS DevOps Engineer, Azure DevOps Engineer, GCP Professional DevOps Engineer) are a plus.