Lead DevSecOps Engineer

Posted 3 months agoViewed
European UnionFull-TimeIGaming
Company:Playson
Location:European Union
Languages:English
Seniority level:Lead, 5+ years
Experience:5+ years
Skills:
AWSDockerLeadershipPythonAWS EKSBashCloud ComputingKubernetesCI/CDLinuxDevOpsTerraformMicroservicesMentoring
Requirements:
5+ years in Security Engineering / DevSecOps roles with proven success delivering secure infrastructure and applications. Strong skills in Python and Bash for building and automating security workflows. Deep knowledge of AWS Cloud Security (IAM least-privilege, encryption, GuardDuty, Security Hub, multi-account environments). Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code). Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies. Terraform/Terragrunt expertise, including policy-as-code, drift detection, and compliance enforcement. Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent. Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows. In-depth understanding of secure network design, segmentation, and monitoring. Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.). Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access). Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks. Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines.
Responsibilities:
Establish the DevSecOps function, defining best practices and security standards. Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning, container scanning). Harden infrastructure and runtime environments (Linux, Docker, Kubernetes/EKS, RBAC). Design and enforce cloud security controls in AWS (IAM least-privilege, GuardDuty, Security Hub, encryption at rest/in transit). Define and maintain IaC security policies (Terraform/Terragrunt, drift detection, policy-as-code). Implement and manage secrets management solutions (Vault, AWS Secrets Manager). Build centralized security monitoring & alerting (Datadog, ELK, CloudWatch, SIEM/SOAR). Lead vulnerability management and threat modeling practices. Automate workflows through scripting (Python, Bash). Partner with engineers to embed security in design & delivery. Contribute to compliance readiness (ISO 27001, GDPR, PCI-DSS). Act as a security subject-matter expert, mentoring engineers and raising awareness. Continuously evaluate and implement new security tools and approaches.
Similar Jobs:
Posted about 6 hours ago
Moldova, Poland, Slovakia, Hungary, Bulgaria, CzechiaFull-TimeSaaS, Software
(Fluent English) QA Engineer (remotely) - SupportYourApp
Posted about 7 hours ago
SpainContractHealth Tech
Fullstack Software Engineer (x/f/m) - Spain
Company:Alan
Posted about 7 hours ago
France, Belgium, SpainContractHealthtech
Full Software Engineer (x/f/m) - International expansion
Company:Alan