Senior Security Dev Ops Engineer (100% remote)
Summary
Senior DevSecOps engineer builds and hardens secure cloud infrastructure for a fintech trading platform, automating security gates in CI/CD and managing Kubernetes clusters on OCI/AWS.
Senior Security Dev Ops Engineer (100% remote)
💰 Salary: 7000-8000 USD/Month
💻 100% remote
🕦 Full-time
☑️ B2B
We’re looking for a Senior Security DevOps Engineer to join a fast-growing fintech company that builds a digital trading and investment platform.
Requirements:
8+ years of experience in DevSecOps, Cloud Security Engineering, or a closely related security-focused infrastructure role.
Experience working in regulated, high-availability environments, such as fintech, banking, trading, or payments.
Demonstrated ability to work across both architecture/design and hands-on implementation without requiring a handoff.
Advanced knowledge of Kubernetes security and cluster hardening, including NetworkPolicies and workload isolation.
Hands-on experience with Infrastructure as Code tools such as Terraform and Ansible, with security scanning via tfsec and Checkov.
Strong understanding of identity and access management, including HashiCorp Vault, HashiCorp Boundary, OAuth2, OIDC, and RBAC/ABAC models.
Experience implementing security gates (SAST, SCA, DAST) within CI/CD pipelines using GitHub Actions, Jenkins, and ArgoCD.
Programming skills in Go and/or Python for security automation, plus Shell scripting.
-
Strong hands-on experience with at least one major cloud provider: OCI, AWS, or GCP.
Nice to Have:
Hands-on experience with Oracle Cloud Infrastructure (OKE, OCI Vault, OCI KMS).
Exposure to trading system environments.
Working knowledge of CSA frameworks and OWASP CI/CD Top 10.
Experience with software supply chain integrity, including SLSA provenance and image signing via Cosign/Sigstore.
-
Relevant certifications: CKS, CISSP, AWS Security Specialty, GCP, or OCI Security certifications.
Key Responsibilities:
Define and drive the DevSecOps roadmap, embedding security across the full SDLC, and architect security controls across infrastructure, pipelines, identity, and APIs aligned with CSA and OWASP CI/CD Top 10.
Own and enforce security standards across IaC using Terraform, Ansible, and Terrateam, with tfsec and Checkov scanning integrated into pipelines.
Harden Kubernetes clusters and OKE environments on OCI, and manage security posture across OCI and AWS.
Design and enforce security gates (SAST, SCA, DAST) across GitHub Actions, Jenkins, and ArgoCD pipelines, and maintain software supply chain integrity via SLSA provenance and image signing with Cosign/Sigstore.
Implement Just-In-Time access via HashiCorp Boundary with RBAC/ABAC, and manage identity protocols across OAuth2 and OIDC.
Own secrets and key lifecycle management using OCI Vault, OCI KMS, and HashiCorp Vault.
Harden API gateways (Kong, API6, Traefik), enforce Kubernetes NetworkPolicies at L3/L4, and manage WAF rules via Incapsula Imperva.
Lead security incident response from triage to post-mortem, support on-call rotations on a 24/7 high-throughput platform, and collaborate with SRE to embed security in reliability workflows, including runbooks and DR protocols.
Build security automation tools in Go and Python, and review application code security across Java, C#/, and JavaScript.
Get to know DevsData:
We are a technology consulting company and a recruitment agency, delivering software solutions to clients from Europe and the US. We work 100% remotely, in an international team, including people from Asia, London, or San Francisco. We employ people with experience in international corporations as well as students of the best technical and business universities. Find out more: