We are looking for a DevSecOps Engineer to join our vibrant Devops team within the Platform group in Tel- Aviv!
As a DevSecOps Engineer, you'll play a crucial role in securing our AWS cloud infrastructure and CI/CD pipelines. You'll work closely with our development and security teams to integrate security best practices into our development lifecycle and cloud infrastructure.
What You'll Do:
Infrastructure Security:
Implement and enforce security policies and controls, such as IAM roles, access policies, K8S clusters security configuration, and network security groups.
Proactively identify and mitigate security risks and vulnerabilities in our AWS infrastructure.
Collaborate with security teams to improve our overall security posture.
CI/CD Security:
Integrate security tools and processes into our CI/CD pipeline to automate security testing and vulnerability scanning.
Collaborate with development teams to establish and enforce security best practices throughout the development lifecycle.
Incident Response:
Develop and maintain incident response plans to effectively address security incidents.
Conduct thorough investigations to determine the root cause of security breaches and implement corrective actions.
Vulnerability Management:
Stay up-to-date with the latest security threats and vulnerabilities.
Prioritize and remediate security vulnerabilities identified through vulnerability scans and security assessments.
Work closely with development teams to address vulnerabilities in code and infrastructure.
Requirements: At least 2 years of experience in DevSecOps or 4 year of experience in DevOps role from product companies
Strong understanding of cloud security principles and best practices, particularly in AWS.
Proficiency in scripting languages and IaC tools. We use mostly bash for scripting and argocd, terraform for IaC but if you have experience with equivalent languages and/or tools thats good as well
Hands-on experience with security configuration tools such as Wiz or similar.
Experience with CI/CD pipelines (CodeFresh, Jenkins, GitLab CI/CD, etc.) and security tools (e.g., vulnerability scanners, security testing tools).
Hands-on experience with Kubernetes and containerization technologies (Docker).
Experience with Linux system administration skills.
Knowledge of network security concepts (e.g. DNS, SSL, reverse proxy, Nginx, WebSockets).
An ability to assess and prioritize tasks based on both business and security risks.
A passion for security and a commitment to continuous improvement.
Team player, strong communication skills, egoless, transparency, and positive attitude.
Ability to take ownership and make an impact.
Preferred Skills:
Certifications in cloud security (e.g., AWS Certified Security Specialty).
Knowledge of security frameworks and standards (e.g., NIST, CIS).
This position is open to all candidates.