DevOps Engineer (security)
Quick Summary
Working closely with leadership, product management,
Collaborate with cross-functional teams to evaluate security releases, generate compliance reports, and support security monitoring/observability using Grafana, New Relic, or OpenTelemetry.
About the Role
~1 min readOnapsis is on a mission to safeguard the most critical business applications that business depends on daily. Over 20% of the Fortune 100 rely on Onapsis to secure their business-critical applications and ensure they are compliant and available.
We are looking for self-motivated and enthusiastic DevSecOps Engineers who want to impact cybersecurity by continuing to advance, maintain, and enhance our platform features in Threat Detection & Response, Vulnerability Management, and Compliance Automation.
Responsibilities
~2 min readWorking closely with leadership, product management, and our Engineering and Operations teams to design and implement security-focused capabilities across the SDLC using Shift-Left-On-Security principles.
This role partners with InfoSec, Technical Operations, and Platform Engineering teams to ensure CI/CD frameworks, infrastructure, and automation tooling are secure by design, resilient, and capable of protecting our customers at scale.
- →Security Automation & CI/CD: Embed, maintain, and optimize automated security testing (OSS, SAST, DAST, SCA, Container Security and related K8s configuration management) directly into GitLab CI/CD pipelines.
- →Vulnerability & Patch Management: Perform platform security assessments, verify reported exploits, and support vulnerability remediation activities.
- →Security Compliance: Participate in security audits, provide actionable feedback, and coordinate with engineering teams to meet compliance timelines and regulatory standards.
- →Penetration Testing Enablement: Provision and configure isolated test environments, deploy target application builds, and coordinate secure access requirements for penetration testing activities.
- →Security Operations & Incident Response: Collaborate with cross-functional teams to evaluate security releases, generate compliance reports, and support security monitoring/observability using Grafana, New Relic, or OpenTelemetry.
- →Security Advocacy: Conduct internal software security training and advocate for secure coding standards and DevSecOps best practices across engineering teams.
- →Threat Modeling & Risk Mitigation: Conduct threat modeling exercises for new features and infrastructure changes to identify vulnerabilities before code hits production.
- →Support our Engineering teams: Provide in-depth knowledge of the DevSecOPS principles and tools to our engineering teams. Understand their SDLC challenges and provide automation solutions to improve our delivery lifecycle. Provide support with the self servicing shift left on security CICD tools and pipelines if problems arise.
Cybersecurity Expertise (2+ Years)
- Hands-on experience implementing Shift-Left-On-Security frameworks within the SDLC.
- Practical knowledge of application security testing methodologies, specifically SAST, DAST, SCA, and OSS management.
- Experience conducting Threat Modeling exercises and performing secure code reviews.
- Awareness of penetration testing (blackbox, whitebox) methods
- Plus: Knowledge of compliance and auditing standards (ISO 27001/27002, NIST 800-53, PCI DSS, CIS Controls) or active SecOps experience.
DevOps & Cloud Infrastructure (4+ Years)
- Proven experience in DevOps practices utilizing Cloud Technologies (AWS preferred, Azure, GCP)
- Advanced problem solving skills and distributed systems engineering concepts.
- Advanced knowledge of the Software Development Lifecycle (SDLC), its phases and how to enable the shift left on security paradigm in each
- Advanced knowledge in Source Control Management and CICD tools (Git/GitLab), including branching/versioning strategies, and pipeline development.
- Intermediate knowledge of container infrastructure and related container orchestration platforms (Docker and Kubernetes).
- Advanced knowledge in cloud computing administration skills and related best practices(AWS)
- Advanced Application Performance Management and Observability skills for in depth troubleshooting
- Intermediate Infrastructure as a Code and Configuration management skills using Terraform
- Linux system administration skills, including networking, access management, and basic troubleshooting skills.
- Advanced knowledge in a scripting language (e.g., Python, Bash).
Soft Skills
- Demonstrated effective communication and collaboration across Engineering, Security, SRE, and cross-functional teams to support delivery and operational objectives
- Experience managing priorities, handling operational pressure, and escalating risks or blockers when needed. Identifies and supports continuous improvement initiatives.
- Demonstrated analytical thinking and problem-solving skills to troubleshoot operational, infrastructure, and security-related issues in a structured manner
- Strong attention to detail and a security-first mindset when working with CICD pipelines, infrastructure, automation, and cloud environments
- Continuous learning mindset with willingness to share knowledge, contribute to documentation, and support team growth
What We Offer
~1 min readFor more information, connect with Onapsis on LinkedIn or visit https://www.onapsis.com.
#LI-AC1
#Hybrid
Location & Eligibility
Listing Details
- Posted
- August 25, 2026
- First seen
- August 25, 2026
- Last seen
- August 25, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- August 25, 2026
Signal breakdown
Please let Onapsis know you found this job on Jobera.
3 other jobs at Onapsis
View all →Explore open roles at Onapsis.
Similar Devops Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
