Security Engineer
Job Description
- 4+ years in DevOps / DevSecOps or software engineering with a strong security focus.
- Hands-on with CI/CD tooling (e.g. GitLab CI, GitHub Actions, Jenkins, Azure DevOps).
- Security scanning in pipelines: SAST, DAST, SCA, secrets scanning (e.g. Semgrep, Snyk, Trivy, OWASP ZAP).
- Infrastructure-as-Code (e.g. Terraform) and IaC security.
- Containers and Kubernetes security (Docker, K8s, image scanning, hardening).
- Cloud platforms (AWS / Azure / GCP) and cloud security fundamentals.
- Secrets management (e.g. HashiCorp Vault, cloud KMS) and IAM basics.
- Scripting and automation (Python, Bash) and Git.
- Familiarity with standards and frameworks: OWASP, NIST, CIS Benchmarks, ISO 27001.
- Understanding of and hands-on experience with different LLMs; ability to build AI agents; and knowledge of embedding LLMs into the SDLC and pipelines.
- Strong Linux skills (administration, hardening, command line, shell scripting).
Nice to have: certifications (e.g. CKA/CKS, AWS/Azure Security, CISSP); pentesting or vulnerability-management exposure.
Job Responsibilities
- Build and maintain secure CI/CD pipelines; embed security gates (SAST, DAST, SCA, secrets scanning) into the build.
- Automate security testing and policy checks across the SDLC (shift-left).
- Implement Infrastructure-as-Code (IaC) security and secure baseline configuration.
- Manage secrets, keys and credentials (vaulting, rotation) across environments.
- Secure containers and Kubernetes (image scanning, hardening, runtime policies).
- Set up security tooling and route findings into developer workflows and dashboards.
- Define and enforce policy-as-code guardrails; track exceptions and drift.
- Support vulnerability management: triage, prioritize and follow remediation through pipelines.
- Work with developers and architects to embed security by design.
- Monitor, log and respond to pipeline and cloud security events; support incident response.
- Contribute to AI-assisted automation (LLMs/agents) for security tasks in the pipeline.
Department/Project Description
An enterprise technology group is building a dedicated security validation team focused on vulnerability assessment and security testing across the group's products and systems. The team runs structured testing campaigns: penetration testing, vulnerability discovery and triage, secure code review, and building automated test suites to make the process repeatable at scale.
The team also gets early access to specialized AI models and evaluates how they can accelerate security testing - an area we're actively investing in, though the core of the work remains hands-on security engineering. Scope covers internal systems as well as business-unit products across the group, agreed campaign by campaign. The team starts small and scales into a permanent capability.