SENIOR DEVSECOPS ENGINEER
helpware-inc
Full-timesenior
Job description
We are looking for a hands-on Senior DevSecOps Engineer to help build secure, scalable, and reliable cloud infrastructure, Kubernetes platforms, and CI/CD pipelines. You will work closely with engineering and platform teams to integrate security into the software delivery lifecycle and make secure-by-default practices easy to adopt.
The role combines DevSecOps, cloud security, infrastructure automation, Kubernetes security, and software supply-chain security , with a strong focus on practical engineering and automation.
Project Details
• Start: ASAP
• Project duration: 12 months+
• Locations: Argentina, Brazil, Mexico
• Working hours: EST business hours
• English: B2+
Responsibilities
• Integrate security into cloud infrastructure, Kubernetes platforms, CI/CD pipelines, and developer self-service workflows.
• Design and implement secure-by-default patterns for IAM, workload identity, secrets management, network security, infrastructure as code, application deployment, and workload protection.
• Assess the current security landscape, identify gaps and risks, and establish scalable security practices within DevOps and platform teams.
• Build automated, risk-based security guardrails across source control, container builds, infrastructure changes, and application deployments using policy-as-code.
• Strengthen Kubernetes, container, and software supply-chain security, including cluster configuration, workload isolation, ingress, admission controls, runtime protection, dependency management, SBOMs, artifact signing, and build provenance.
• Partner with engineering teams to identify, prioritize, and remediate vulnerabilities and security misconfigurations across cloud, Kubernetes, and CI/CD environments.
• Support security incident response across infrastructure and delivery systems, including investigation, containment, recovery, and post-incident improvements.
• Translate security, regulatory, and audit requirements into practical and maintainable engineering controls.
• Create automation, documentation, runbooks, and security standards, while mentoring engineers on DevSecOps best practices.
Requirements
• 5+ years of hands-on experience in DevSecOps, DevOps, Cloud Security, Platform Engineering, or a related role, with significant responsibility for security engineering and automation.
• Strong hands-on experience securing AWS or Google Cloud , including IAM, workload identity, networking, encryption, logging, and cloud-native security controls.
• Deep experience operating and securing Kubernetes and containerized workloads , including managed platforms such as Amazon EKS or Google Kubernetes Engine.
• Strong hands-on experience with Terraform , including reusable modules, dependency management, policy enforcement, and safe change management.
• Strong understanding of CI/CD and release engineering , including artifact security, deployment controls, approval gates, trusted builds, and rollback strategies.
• Experience implementing automated security controls such as vulnerability and dependency scanning, container image scanning, secrets detection, policy-as-code, infrastructure scanning, cloud configuration assessment, and software supply-chain security.
• Strong scripting or programming skills for automation, integrations, tooling, and operational problem-solving.
• Experience working in regulated or audited environments and translating frameworks such as HIPAA, SOC 2, PCI DSS, HITRUST, or SOX into engineering controls.
• Strong communication and technical leadership skills, with the ability to balance security, reliability, developer experience, maintainability, and delivery speed.
• English: B2+ or higher.
Nice to have
• Experience with Terraform Cloud , including workspace management, policy controls, remote execution, and state governance.
• Experience with GitOps and delivery platforms such as Argo CD, Harness, or Codefresh.
• Experience with observability and incident-management platforms such as Datadog, Groundcover, or PagerDuty.
• Experience with cloud security posture management, vulnerability management, workload/runtime protection, and endpoint security platforms such as Qualys, CrowdStrike, Prisma Cloud, Lacework, Wiz, or comparable tools.