2coms logo

DevSecOps/Secure DevOps Engineer

2coms

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

SUMMARY

DevSecOps/Secure DevOps Engineer

About the Role:

We are hiring a hands-on Secure DevOps Engineer to build and secure AWS environments, automate deployments, and own CI/CD, infrastructure as code, containerized workloads, monitoring, and vulnerability remediation across development, UAT, and production. You'll integrate security into delivery pipelines, independently troubleshoot issues, and drive remediation to closure.

Key Responsibilities

  • Build and manage secure AWS infrastructure using EC2, VPC, IAM, S3, RDS, ECR/EKS, ALB, Route 53, CloudWatch, KMS, and related services.
  • Design and maintain CI/CD pipelines using Jenkins, GitLab CI, GitHub Actions, or equivalent.
  • Manage controlled deployments across Dev/UAT/Production, including configuration management, rollback, and release support.
  • Implement Terraform-based Infrastructure as Code with secure state management and version-controlled changes.
  • Secure AWS environments using least-privilege IAM, network controls, encryption, secrets management, logging, WAF, CloudTrail, GuardDuty, and Security Hub.
  • Manage Docker and Kubernetes/EKS workloads, including image security, RBAC, secrets, and workload access.
  • Integrate SAST, DAST, SCA, secrets scanning, IaC scanning, and container vulnerability scanning into CI/CD pipelines.
  • Identify, prioritize, remediate, retest, and close Critical/High vulnerabilities and VAPT findings.
  • Monitor application infrastructure, troubleshoot deployment/infrastructure incidents, and improve availability and observability.
  • Review existing environments for configuration drift, excessive access, exposed services, insecure credentials, manual deployment risks, and monitoring gaps.
  • Manage Linux administration, DNS/SSL, backup/recovery, and incident troubleshooting across environments.
  • Support VAPT, security reviews, ISO 27001/SOC 2 evidence, technical questionnaires, and client audits.

Requirements

  • 4-6 years of hands-on DevSecOps experience.
  • Strong practical AWS infrastructure and security experience.
  • Hands-on Terraform/Infrastructure as Code experience.
  • Strong CI/CD and deployment automation experience.
  • Hands-on Docker and Kubernetes/EKS experience (practical working knowledge; deep platform engineering only where EKS is a core production dependency).
  • Working knowledge of SAST, DAST, SCA, secrets, IaC, and container scanning.
  • Experience with SonarQube, Trivy, OWASP ZAP, or equivalent tools.
  • Good Linux administration and Bash/Python scripting skills.
  • Git/GitLab or equivalent source-control experience.
  • Strong troubleshooting, incident handling, vulnerability remediation, deployment rollback, secrets handling, and communication skills.

Good to Have

  • Azure security exposure such as Defender for Cloud, Entra ID/Azure AD, and Key Vault.
  • ISO 27001, SOC 2, or similar compliance exposure.
  • AWS, Kubernetes, Terraform, or Security certifications.
  • Experience with backup/restore, disaster recovery, and cost optimization.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at 2coms was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.