Mô Tả Công Việc
We are looking for a dedicated **DevSecOps Engineer** to build, automate, and maintain the security framework for our fintech platform. In this role, you will focus on implementing "Security-as-Code" to ensure our financial applications and AI-driven features remain secure and reliable.You will be responsible for hands-on technical tasks, from hardening **Docker** environments to securing **AI models**, all while maintaining strict adherence to **PCI DSS** standards. This is a perfect opportunity for an engineer who thrives on technical execution and wants to scale a secure, modern fintech ecosystem. Key ResponsibilitiesCI/CD Security Integration : Design, implement, and manage **security gates** within CI/CD pipelines (e.g., GitHub Actions, GitLab CI) by integrating **SAST, DAST, and SCA** tools to detect and block vulnerabilities early in the delivery lifecycle.Cloud Engineering (AWS or Azure) : Design, secure, and operate multi-account / multi-subscription cloud environments. Implement **IAM/RBAC**, security baselines, network segmentation, and cloud-native security services (e.g., Azure Defender, Microsoft Sentinel, AWS Security Hub, GuardDuty).Container Security : Secure the full **Docker lifecycle**, including base image hardening, container image scanning, secure registries, runtime protection, and container orchestration security.Infrastructure as Code (IaC) : Build, maintain, and scale cloud infrastructure using **Terraform**, ensuring all environments are **reproducible, auditable, and version-controlled**, with zero manual configuration drift.AI Model & Data Security : Implement security controls for **AI / Machine Learning workflows**, focusing on protecting model endpoints, securing API integrations, controlling access to training and inference data, and preventing data leakage.PCI DSS Compliance & Security Controls : Act as the **Technical lead for PCI DSS** requirements, including: Vulnerability scanning (internal & ASV)Vulnerability scanning (internal & ASV)File Integrity Monitoring (FIM)Centralized logging and audit trailsSecure network segmentation and access controlThreat Modeling & Incident Response : Conduct threat modeling for new features and architectural changes. Lead technical response efforts during **security incidents, data breaches, or major cloud outages.Vulnerability Management : Own the end-to-end vulnerability management process across applications, containers, cloud infrastructure, and third-party dependencies, from identification and risk prioritization to remediation and verification.
Xem toàn bộ Mô Tả Công Việc
Yêu Cầu Công Việc
Experience: 5+ years of hands-on experience in DevOps, SRE, or Security Engineering, with a proven track record of implementing Shift-Left security practices.English Proficiency:Strong spoken and written English.Ability to communicate confidently with external vendors and partners, including penetration testing teams, stress/load testing providers, and security auditors.Cloud Platforms: Strong proficiency in either AWS or Azure, with deep experience in cloud security services such as AWS Security Hub, GuardDuty, or Azure Defender / Microsoft Sentinel.Containerization: Expert-level knowledge of Docker and hands-on experience securing and operating containerized workloads in production.Infrastructure Automation: Advanced skills in Terraform and scripting (Python, Bash, or Go) to automate infrastructure provisioning and security workflows.Financial & Security Compliance:Direct, hands-on experience implementing and maintaining PCI DSS technical controls.Familiarity with SOC 2, ISO 27001, or NIST frameworks is a strong advantage.Collaboration & Communication: Ability to work effectively with Developers, Product Managers, and Security stakeholders to balance delivery speed with robust security practices.Databases: Experience with PostgreSQL, MySQL, and MongoDB (including HA setups, replication, backup strategies, and performance tuning).Networking & Infrastructure: Solid understanding of networking fundamentals, including DNS, load balancing, CDN, firewalls, and network segmentation*Monitoring & Observability: Hands-on experience with monitoring and observability tools such as Prometheus, Grafana, ELK Stack, CloudWatch, or equivalent platforms.Nice to HaveExperience working in fintech, payments, or regulated industriesPrior involvement in security audits and coordination with external assessorsKnowledge of zero-trust architecture or security platform engineeringMentoring or leading other DevOps / security engineers
Xem toàn bộ Yêu Cầu Công Việc
Hình thức
Full-time
Quyền Lợi
Own and shape the security architecture of a modern fintech platformWork on AI-driven products with real-world security impactHigh level of technical autonomy and ownershipOpportunity to influence security strategy, tooling, and engineering culture
Mức lương
Thỏa thuận
Báo cáo tin tuyển dụng: Nếu bạn thấy rằng tin tuyển dụng này không đúng hoặc có dấu hiệu lừa đảo,
hãy phản ánh với chúng tôi.
Tham khảo: 10 Dấu hiệu nhận biết hành vi lừa đảo qua tin tuyển dụng.
Tham khảo: 10 Dấu hiệu nhận biết hành vi lừa đảo qua tin tuyển dụng.