- Company Name
- Maverc Technologies
- Job Title
- DevSecops Engineer
- Job Description
-
**Job title:** DevSecOps Engineer
**Role Summary:**
Design, implement, and maintain secure, scalable CI/CD pipelines and cloud infrastructure for high‑traffic e‑commerce platforms, embedding security controls throughout the software development lifecycle while ensuring compliance with industry regulations.
**Expactations:**
- Deliver robust, automated deployment workflows that reduce release times and operational risk.
- Maintain and evolve security posture of payment systems, customer data, and integrations with third‑party services.
- Support continuous compliance with PCI DSS, SOC 2, ISO 27001, and related frameworks.
**Key Responsibilities:**
- Create and manage secure CI/CD pipelines in GitHub Actions, GitLab CI, Jenkins, or Azure DevOps.
- Integrate automated security testing (SAST, DAST, SCA, IaC scanning) into all stages of the SDLC.
- Build and maintain infrastructure-as-code using Terraform, CloudFormation, or ARM.
- Configure and manage Cloudflare services (WAF, CDN, DDoS protection, Zero Trust, bot management).
- Implement secrets, certificate, and key management with automated rotation.
- Conduct threat modeling and risk assessments for new e‑commerce features and vendor integrations.
- Develop monitoring, alerting, and incident‑response procedures using Prometheus, Grafana, ELK, or Datadog.
- Participate in on‑call rotations and production release support.
**Required Skills:**
- 5+ years in DevOps/DevSecOps roles, with hands‑on experience on e‑commerce platforms (Swell, Shopify, Magento, BigCommerce, or custom).
- Expertise in CI/CD, IaC (Terraform, CloudFormation, ARM), and container orchestration (Docker, Kubernetes).
- Strong knowledge of web application security, OWASP Top 10, and secure payment processing (PCI DSS).
- Experience securing AWS, Azure, or GCP environments.
- Proficiency with security scanning tools (Snyk, Checkmarx, Veracode, etc.).
- Scripting skills in Bash, Python, or equivalent.
- Familiarity with monitoring/logging stacks (Prometheus, Grafana, ELK, Datadog).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field (preferred).
- Industry certifications (e.g., CISSP, AWS Certified Security – Specialty, Azure Security Engineer Associate, or equivalent) highly desirable.