في المكتب دوام كامل
--
Company

تفاصيل الوظيفة

Job Description – DevSecOps Engineer

Position

DevSecOps Engineer

Experience

4–8 Years

Location

UAE – Dubai / Abu Dhabi

Employment Type

Full-Time / Contract

Work Mode

Onsite / Hybrid – As per client requirement

Role Overview

We are looking for an experienced DevSecOps Engineer to integrate security practices throughout the software development and deployment lifecycle. The candidate will be responsible for building secure CI/CD pipelines, automating security controls, managing cloud infrastructure, and implementing security best practices across application and infrastructure environments.

The ideal candidate should have strong hands-on experience with DevOps, Cloud, Kubernetes, CI/CD, Infrastructure as Code, and application security, with the ability to embed security into automated development and deployment processes.

Key Responsibilities

  • Design, implement, and maintain secure CI/CD pipelines.

  • Integrate security controls and automated security testing into the software development lifecycle.

  • Implement DevSecOps practices across development, testing, deployment, and production environments.

  • Automate infrastructure provisioning, configuration, security controls, and compliance checks.

  • Manage and secure cloud infrastructure across AWS, Azure, or GCP.

  • Implement and manage Infrastructure as Code (IaC) using Terraform, CloudFormation, or equivalent tools.

  • Deploy and manage containerized applications using Docker and Kubernetes.

  • Implement container and Kubernetes security controls.

  • Integrate SAST, DAST, SCA, secrets scanning, vulnerability scanning, and other security tools into CI/CD pipelines.

  • Monitor infrastructure and applications for security vulnerabilities and misconfigurations.

  • Work with development teams to identify and remediate security issues early in the development lifecycle.

  • Implement secure authentication, authorization, secrets management, and encryption mechanisms.

  • Support vulnerability management and security remediation activities.

  • Automate security monitoring, reporting, and compliance processes.

  • Participate in incident response and security investigations when required.

  • Ensure compliance with organizational security policies and applicable industry standards.

  • Collaborate with Developers, Cloud Engineers, Security Teams, Architects, and DevOps teams.

  • Continuously evaluate emerging DevSecOps tools, technologies, and security practices.

Mandatory Skills

  • 4–8 years of experience in DevOps / DevSecOps / Cloud Engineering.

  • Strong experience with CI/CD pipelines.

  • Hands-on experience with Jenkins, GitLab CI, GitHub Actions, Azure DevOps, or equivalent.

  • Strong experience with Docker and Kubernetes.

  • Experience with Terraform / Infrastructure as Code.

  • Strong knowledge of AWS, Azure, or GCP.

  • Experience integrating security tools into CI/CD pipelines.

  • Knowledge of SAST, DAST, SCA, vulnerability scanning, and secrets management.

  • Strong understanding of Linux/Unix environments.

  • Good knowledge of networking and cloud security concepts.

  • Experience with Git and source-code management platforms.

  • Scripting/programming experience using Python, Bash, or PowerShell.

  • Understanding of secure software development and DevSecOps lifecycle practices.

Security Tools – Preferred


Desired Candidate Profile

Experience with one or more:

  • SonarQube

  • Checkmarx

  • Veracode

  • Snyk

  • Trivy

  • Aqua Security

  • Fortify

  • OWASP ZAP

  • HashiCorp Vault

  • CyberArk

  • Microsoft Defender for Cloud

  • Prisma Cloud

Cloud & DevOps Technologies

Azure

  • Azure DevOps

  • Azure Kubernetes Service (AKS)

  • Microsoft Defender for Cloud

  • Azure Key Vault

  • Azure Container Registry

AWS

  • AWS CodePi

وظائف مشابهة