DevSecOps Engineer

Posted 9 Days Ago
Be an Early Applicant
Hiring Remotely in Brazil
Remote
Senior level
Information Technology • Software
The Role
Design, build, and maintain secure cloud infrastructure and CI/CD pipelines. Integrate automated SAST/DAST/container scanning and security-as-code in Terraform. Harden Kubernetes (RBAC, network policies, pod security), manage AWS services (EC2, RDS, OpenSearch, EKS), respond to cloud security incidents, support compliance audits (SOC2, HIPAA, GDPR), automate policies, and document infrastructure while collaborating with security and DevOps leads.
Summary Generated by Built In
About the Role

We are looking for a proactive and skilled DevSecOps Engineer with 5+ years of hands-on experience to join our growing engineering team. You'll be working closely with a small team of five DevOps engineers to build, maintain, and scale secure cloud infrastructure, CI/CD pipelines, and observability stacks. We value a security-first engineering mindset where you will integrate security-as-code practices throughout the entire development lifecycle. If your background is in DevOps, that is a great fit, provided you have always focused on and enjoyed the security aspects of your work, and are now ready to fully commit to a dedicated security role.

We value collaboration, strong communication, and a growth mindset: you'll be expected to contribute ideas, give and receive feedback, and work independently to ensure our platform is as secure as it is performant.

 
 
Your Responsibilities
  • Integrate automated security scanning (SAST, DAST, container scanning) into CI/CD pipelines to ensure early detection of vulnerabilities.

  • Maintain and audit cloud infrastructure compliance (e.g., SOC2, HIPAA, GDPR) through automated policies.

  • Implement security best practices within Terraform/IaC to ensure "security-as-code" consistency.

  • Monitor and respond to cloud security incidents, collaborating closely with security and compliance teams.

  • Design, implement, and maintain cloud infrastructure primarily on AWS, with strong focus on EC2, RDS, OpenSearch, and EKS.

  • Help to manage the Kubernetes clusters running our microservices (we have over a hundred in production) as well as the legacy EC2-based platform.

  • Hardening Kubernetes clusters by implementing network policies, RBAC, and secure pod security standards to protect our microservices environment.

  • Collaborate on maintaining our Infrastructure as Code (IaC) maintenance using Terraform.

  • Identify opportunities for automation and optimization in deployment and infrastructure management.

  • Document processes, infrastructure, and decisions clearly and effectively.

  • Partner closely with our Information Security Lead on compliance audits, control evidence, and security roadmap prioritization, while reporting into the Head of DevOps for day-to-day work.

 
 
Your Profile

Experience with our stack:

  • Proven experience in a DevSecOps or security-focused engineering role.

  • Familiarity with modern security tooling (vulnerability management, secrets management etc.).

  • Strong understanding of "shift-left" security principles.

  • 3+ years of experience in a DevOps or similar role.

  • Deep experience with AWS services, especially IAM, EC2, RDS, EKS, and OpenSearch.

  • Solid understanding and hands-on experience with Kubernetes and related tooling (we use Helm, Kustomize and FluxCD but we value knowing and adhering to the GitOps practices more than the specific tools).

  • Strong proficiency in Terraform for infrastructure automation.

  • Experience in CI/CD tools.

  • Bash or other shell scripting knowledge

Soft Skills & Mindset:

  • Highly proactive and self-motivated; able to identify and address issues before they escalate.

  • Strong communication skills, both verbal and written. We are a remote and distributed team so we focus on effective and async communication.

  • Comfortable working collaboratively within a distributed team but also capable of driving tasks independently.

  • Open to giving and receiving feedback, and eager to grow with the team.

  • Analytical mindset with attention to detail and commitment to high-quality work.

 
 
Nice-to-Have
  • Experience with GitLab CI and GitLab in general.

  • Familiarity with the JVM.

  • Experience in cost optimization on AWS.

  • Having worked with Istio or other service meshes.

  • Exposure to GRC/compliance automation tooling (Drata, Vanta, or similar)

  • Experience with Vulnerability/dependency scanning tools

Skills Required

  • 5+ years hands-on experience in DevSecOps or security-focused engineering role
  • 3+ years of experience in a DevOps or similar role
  • Deep experience with AWS services (IAM, EC2, RDS, EKS, OpenSearch)
  • Strong proficiency in Terraform for infrastructure automation
  • Solid hands-on experience with Kubernetes and related tooling (Helm, Kustomize, FluxCD) and GitOps practices
  • Experience integrating automated security scanning into CI/CD (SAST, DAST, container scanning)
  • Familiarity with modern security tooling (vulnerability management, secrets management)
  • Experience with CI/CD tools and pipelines
  • Bash or other shell scripting knowledge
  • Experience maintaining and auditing cloud infrastructure compliance (SOC2, HIPAA, GDPR)
  • Strong communication skills for remote and asynchronous collaboration
  • Proactive, self-motivated, able to work independently and collaboratively
  • Experience with vulnerability/dependency scanning tools (e.g., OSS scanners)
  • Experience with GitLab CI and GitLab
  • Familiarity with the JVM
  • Experience in AWS cost optimization
  • Experience with Istio or other service meshes
  • Exposure to GRC/compliance automation tooling (Drata, Vanta, or similar)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Berlin
79 Employees
Year Founded: 2013

What We Do

Uberall helps the world’s most innovative brick and mortar businesses stay relevant, competitive, and profitable, by using digital technology to win clicks online and feet offline.

Similar Jobs

N-iX Logo N-iX

Devsecops Engineer

Information Technology • Consulting
Remote
11 Locations
2135 Employees

1GLOBAL Logo 1GLOBAL

Devsecops Engineer

Information Technology • Software
In-Office or Remote
6 Locations
509 Employees
100-100 Annually

Mastercard Logo Mastercard

Enterprise Operations Engineer (A/V)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
São Paulo, BRA
38800 Employees

Mastercard Logo Mastercard

Launch Program, 2027 - São Paulo, Brazil

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Remote or Hybrid
São Paulo, BRA
38800 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account