Job Openings
M06 - DevSecOps Engineer
About the job M06 - DevSecOps Engineer
Responsibilities
- Develop automation capabilities to deploy, manage, monitor, and maintain applications and infrastructure.
- Design and maintain CI/CD pipelines for application deployment and release management.
- Implement Infrastructure-as-Code (IaC) and environment automation.
- Manage cloud resources and platform services.
- Develop CI/CD tooling and automation for software build, testing, integration, and release processes.
- Monitor and optimise platform availability, performance, utilisation, reliability, and operational health.
- Implement security controls and ensure compliance with government security requirements.
- Plan, implement, and monitor system security architecture, including threat and risk assessments.
- Conduct vulnerability assessments, system hardening, security reviews, and remediation.
- Implement disaster recovery, backup, and business continuity measures.
- Investigate and resolve system, application, and infrastructure issues.
- Collaborate with developers to integrate security throughout the software development lifecycle.
Experience & Skills
- Strong understanding of SDLC, CI/CD, TDD, and DevSecOps practices.
- Experience designing, deploying, and supporting cloud-native applications and infrastructure on AWS; GCC experience is advantageous.
- Proficiency in at least two scripting/programming languages such as Bash, PowerShell, Python, JavaScript, or Java.
- Experience with Terraform, Ansible, or equivalent IaC/automation technologies.
- Experience with Docker and Kubernetes.
- Experience with GitLab workflows and CI/CD platforms.
- Experience implementing monitoring, logging, and observability solutions.
- Knowledge of application security, cloud security, secure coding, and DevSecOps principles.
- Hands-on experience with vulnerability management, security assessments, system hardening, and remediation.
- Familiarity with CNCF/cloud-native tools such as Prometheus, Helm, ArgoCD, Istio, Gatekeeper, and Crossplane.
- Familiarity with enterprise security and secrets-management solutions such as HashiCorp Vault, Tenable, Fortify, Sonatype Nexus IQ, and AWS security services.
- Experience with AWS services covering IAM, networking, monitoring, container platforms, and security.
- Strong troubleshooting, incident-response, and operational-support skills.
- Experience working in regulated or government environments is preferred.