DevSecOps Engineer
from 🇧🇷 Brazil
About the Role
We are looking for a proactive and skilledDevSecOps Engineer with5+ years of hands-on experience to join our growing engineering team. You'll be working closely with a small team of five DevOps engineers to build, maintain, and scale secure cloud infrastructure, CI/CD pipelines, and observability stacks. We value asecurity-first engineering mindset where you will integrate security-as-code practices throughout the entire development lifecycle. If your background is in DevOps, that is a great fit, provided you have always focused on and enjoyed the security aspects of your work, and are now ready to fully commit to a dedicated security role.
We value collaboration, strong communication, and a growth mindset: you'll be expected to contribute ideas, give and receive feedback, and work independently to ensure our platform is as secure as it is performant.
Your Responsibilities
Integrate automated security scanning (SAST, DAST, container scanning) into CI/CD pipelines to ensure early detection of vulnerabilities.
Maintain and audit cloud infrastructure compliance (e.g., SOC2, HIPAA, GDPR) through automated policies.
Implement security best practices within Terraform/IaC to ensure "security-as-code" consistency.
Monitor and respond to cloud security incidents, collaborating closely with security and compliance teams.
Design, implement, and maintain cloud infrastructure primarily onAWS, with strong focus onEC2, RDS, OpenSearch, andEKS.
Help to manage theKubernetes clusters running our microservices (we have over a hundred in production) as well as the legacy EC2-based platform.
Hardening Kubernetes clusters by implementing network policies, RBAC, and secure pod security standards to protect our microservices environment.
Collaborate on maintaining ourInfrastructure as Code (IaC) maintenance usingTerraform.
Identify opportunities for automation and optimization in deployment and infrastructure management.
Document processes, infrastructure, and decisions clearly and effectively.
Partner closely with our Information Security Lead on compliance audits, control evidence, and security roadmap prioritization, while reporting into the Head of DevOps for day-to-day work.
Your Profile
Experience with our stack:
Proven experience in a DevSecOps or security-focused engineering role.
Familiarity with modern security tooling (vulnerability management, secrets management etc.).
Strong understanding of "shift-left" security principles.
3+ years of experience in a DevOps or similar role.
Deep experience withAWS services, especiallyIAM,EC2, RDS, EKS, andOpenSearch.
Solid understanding and hands-on experience withKubernetes and related tooling (we use Helm, Kustomize and FluxCD but we value knowing and adhering to the GitOps practices more than the specific tools).
Strong proficiency inTerraform for infrastructure automation.
Experience in CI/CD tools.
Bash or other shell scripting knowledge
Soft Skills & Mindset:
Highlyproactive and self-motivated; able to identify and address issues before they escalate.
Strong communication skills, both verbal and written. We are a remote and distributed team so we focus on effective and async communication.
Comfortable workingcollaboratively within a distributed team but also capable of driving tasksindependently.
Open togiving and receiving feedback, and eager to grow with the team.
Analytical mindset with attention to detail and commitment to high-quality work.
Nice-to-Have
Experience with GitLab CI and GitLab in general.
Familiarity with the JVM.
Experience in cost optimization on AWS.
Having worked with Istio or other service meshes.
Exposure to GRC/compliance automation tooling (Drata, Vanta, or similar)
Experience with Vulnerability/dependency scanning tools