DevSecOps Engineer
Upload My Resume
Drop here or click to browse · PDF, DOCX, DOC, RTF, TXT
Requirements
• 5+ years in Security Engineering / DevSecOps roles, with proven success delivering secure infrastructure and applications. • Strong skills in Python and Bash for building and automating security workflows. • Cloud Security (AWS focus) - Deep knowledge of IAM least-privilege design, encryption at rest/in transit, GuardDuty, Security Hub, and best practices for securing multi-account environments. • Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code). • Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies. • Terraform/Terragrunt, including policy-as-code, drift detection, and compliance enforcement. • Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent. • Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows. • In-depth understanding of secure network design, segmentation, and monitoring. • Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.). • Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access). • Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks. • Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines. • Exposure to Kafka or ClickHouse in security-sensitive environments. • Familiarity with GitOps tooling (FluxCD/ArgoCD). • Broader knowledge of SOC 2, HIPAA, or other regulatory frameworks.
Responsibilities
• Establish the DevSecOps function at Playson, defining best practices and security standards across the Platform Tribe. • Integrate security into CI/CD pipelines including SAST, DAST, dependency scanning, container image scanning, policy-as-code implementation. • Harden infrastructure and runtime environments such as Linux systems, Docker, Kubernetes/EKS with a focus on RBAC policies. • Design and enforce cloud security controls in AWS focusing on IAM least-privilege design, GuardDuty integration, Security Hub usage, encryption at rest/in transit practices. • Define and maintain Infrastructure as Code (IaC) security policies using Terraform or Terragrunt with policy-as-code implementation and drift detection mechanisms. • Implement and manage secrets management solutions like HashiCorp Vault, AWS Secrets Manager, ensuring secure handling of sensitive data. • Build centralized security monitoring & alerting systems utilizing tools such as Datadog Security, ELK stack (ELK), CloudWatch for SIEM/SOAR capabilities and incident response workflows. • Lead vulnerability management and threat modeling practices to identify and mitigate potential risks within the platform's infrastructure. • Automate security workflows through scripting in Python or Bash, enhancing efficiency of DevSecOps processes. • Partner with backend, infrastructure, and platform engineers for embedding security into design & delivery phases effectively. • Contribute to compliance readiness by aligning practices with standards like ISO 27001, GDPR, PCI-DSS ensuring regulatory adherence in operations. • Act as a subject matter expert and mentor within the organization for security best practices awareness among engineers. • Continuously evaluate and implement new tools and approaches to maintain cutting-edge DevSecOps capabilities at Playson.
Benefits
• Compensation at top industry standards + quarterly bonuses based on transparent evaluation. • Remote-first flexibility and adaptable working hours. • Unlimited paid vacation & sick leave. • Comprehensive medical insurance (for you and your partner). • Financial support for major life events. • Professional growth budget for courses, training, and certifications. • Recruitment Process • 1. Recruiter Interview – 45 min • 2. Hiring Manager Interview – 60 min • 3. Technical Interview – 90 min • 4. Final Interview with Head of Platform & CTO – 60 min