Nauchsoft is an international IT consulting and software development company. We have been in the IT business for 37 years and continue growing.
We are looking for a Senior DevSecOps Engineer. This role is prospective and has been created in line with the company’s planned team expansion.
In this role, you will be responsible for integrating security into every stage of the software development lifecycle, building secure CI/CD pipelines, automating security controls, and helping development teams deliver secure cloud-native applications.
You will work closely with DevOps engineers, software developers, cloud architects, and security specialists to improve the organization's overall security posture while enabling fast and reliable software delivery.
Key Responsibilities
DevSecOps & CI/CD
- Design, implement, and maintain secure CI/CD pipelines.
- Integrate automated security testing into software delivery processes.
- Configure and maintain security gates for build and deployment pipelines.
- Automate security validation throughout the SDLC.
- Integrate secrets scanning and software supply chain security controls into CI/CD workflows.
Application Security
- Implement and manage Static Application Security Testing (SAST).
- Integrate Software Composition Analysis (SCA) into development workflows.
- Configure Dynamic Application Security Testing (DAST) solutions.
- Support developers in vulnerability remediation and secure coding practices.
- Perform threat modeling, secure design reviews, and security risk assessments for new and existing solutions.
- Identify and mitigate software supply chain risks, including open-source dependency risks and secure build and release practices.
Cloud & Infrastructure Security
- Secure AWS, Azure, or GCP environments following security best practices.
- Implement Identity and Access Management (IAM) policies based on least privilege.
- Secure cloud networking, encryption, and key management.
- Review cloud configurations for security risks.
Container & Kubernetes Security
- Secure Docker images and container registries.
- Implement Kubernetes security controls, including RBAC, Pod Security Standards, Network Policies, and Admission Controllers.
- Configure runtime protection for Kubernetes workloads.
- Perform container image vulnerability assessments.
Infrastructure as Code (IaC)
- Review and secure Terraform, CloudFormation, ARM, or Bicep templates.
- Integrate IaC security scanning into CI/CD.
- Maintain infrastructure security baselines.
Secrets Management
- Implement enterprise secrets management solutions.
- Manage certificate lifecycle and encryption keys.
- Prevent credential exposure across development environments.
- Detect and prevent exposed secrets and credentials in source code, repositories, and CI/CD pipelines.
Vulnerability Management
- Analyze, prioritize, and track remediation of security findings.
- Work closely with engineering teams to resolve vulnerabilities.
- Improve vulnerability management processes and reporting.
- Prioritize vulnerabilities based on technical severity, exploitability, business impact, and overall security risk.
- Support penetration testing activities by reviewing findings, coordinating remediation, and tracking remediation follow-up.
Security Automation
- Develop automation using Python, Bash, or PowerShell.
- Automate security scanning, reporting, alerting, and remediation workflows.
- Improve security operations through scripting and orchestration.
Compliance & Governance
- Support compliance initiatives such as ISO 27001, SOC 2, PCI DSS, HIPAA, CIS Benchmarks, and NIST.
- Participate in internal and external security audits.
- Maintain security documentation and operational procedures.Collaboration
- Partner with development teams to promote secure software development.
- Conduct architecture and security design reviews.
- Provide technical guidance on DevSecOps best practices.
- Mentor engineers on secure development principles.
- Communicate security risks and remediation priorities clearly to both technical and non-technical stakeholders.
Required Qualifications
- 5+ years of experience in DevSecOps, DevOps, Cloud Security, Application Security, or a related field.
- Strong understanding of Secure SDLC and DevSecOps methodologies.
- Hands-on experience with AWS, Azure, or Google Cloud Platform.
- Experience with Docker and Kubernetes security.
- Strong knowledge of CI/CD platforms such as GitHub Actions, GitLab CI/CD, Jenkins, or Azure DevOps.
- Experience with SAST, DAST, and SCA tools.
- Hands-on experience with Infrastructure as Code, preferably Terraform.
- Experience implementing secrets management solutions.
- Strong scripting skills in Python, Bash, or PowerShell.
- Experience with Linux administration.
- Understanding of OWASP Top 10, CWE, MITRE ATT&CK, and common application security risks.
- Understanding of threat modeling and security risk assessment principles.
- Understanding of software supply chain security, dependency risks, and secure build and release practices.
- Experience with risk-based vulnerability prioritization and remediation tracking.
- Excellent analytical and troubleshooting skills.
- Strong communication skills and ability to work in cross-functional teams.
- Professional proficiency in English.
Nice to Have
- Experience with Product Security or Application Security practices.
- Experience with SBOM processes and tooling.
- Experience owning or coordinating penetration testing programmes, including scoping and vendor coordination.
- Experience supporting customer or enterprise security reviews and security questionnaires.
- Experience defining and tracking security metrics and communicating security risks to technical and non-technical stakeholders.
- Experience with Kubernetes security tools such as Kyverno, Falco, Kubescape, or OPA Gatekeeper.
- Experience with container security platforms such as Prisma Cloud, Aqua Security, or Trivy.
- Familiarity with SIEM and monitoring solutions such as Microsoft Sentinel, Splunk, Elastic, or Datadog.
- Experience implementing Zero Trust principles.
- Experience working in regulated or security-sensitive domains such as healthcare, medical devices, fintech, or AI/ML-enabled products.
- Familiarity with security standards and frameworks such as NIST SSDF, ISO 27001/2, IEC 62304, ISO 14971, FDA cybersecurity guidance, EU MDR, or NIS2.
Preferred Certifications
One or more of the following certifications is a plus:
- Certified Kubernetes Security Specialist (CKS)
- Certified Kubernetes Administrator (CKA)
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
- CISSP
- CSSLP
- CompTIA Security+
- GIAC Cloud Security Automation (GCSA)
We offer:
- Opportunity for professional self-realization and growth.
- Friendly team.
- 25-days of paid vacation.
- Medical insurance and 100% payment for sick leave.
- Professional training and obtaining certificates at the company's expense.
- Foreign language courses and other corporate programs.
- A variety of corporate events.
- Bonuses in case of wedding or a child’s birth.
- The possibility of remote work from any location.