DevSecOps Engineer

Randstad España·Vigo, Spain

What they offer

  • Permanent contract

    Full-time hours.

  • Fully remote

    Per the ad.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Have 3+ years of experience

    Mid-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 1 month ago
Read the full advert

What you'll do

  • Integrate security into the software development lifecycle (SDLC) and CI/CD pipelines, applying a "shift-left" approach and "security as code" principles.
  • Define secure standards, archetypes, and methodologies for application deployments, and periodically verify compliance with them.
  • Configure and govern Static Application Security Testing (SAST) with SonarQube in conjunction with the QA team, integrating it into the pipelines and defining quality and security gates.
  • Manage the Cloud Security Posture Management (CSPM) strategy with the Infrastructure team using Prisma Cloud (or other equivalent industry tools), ensuring compliance with AWS best practices.
  • Coordinate and execute automated penetration testing (pentesting) with Pentera, prioritizing and tracking the remediation of findings.
  • Implement additional security controls in the pipelines: Software Composition Analysis (SCA), secret detection, and container image scanning for containers and Infrastructure as Code (IaC).
  • Oversee and improve Infrastructure as Code (IaC) using Terraform and AWS architectures, and promote security observability and monitoring (metrics, logs, traces, and alerts).
  • Evaluate DevSecOps trends and tools through proof of concept (PoC) and disseminate security best practices among development teams.

Requirements

Essential requirements

  • University degree or equivalent experience in computer engineering or related fields.
  • Minimum of 3 years of experience with AWS: EC2, RDS, S3, ELB/ALB, ECR, VPC, or other equivalent services.
  • Demonstrable experience in DevSecOps: integrating security controls into CI/CD pipelines (AWS CodePipeline, Jenkins, Bitbucket, etc.).
  • Experience with SAST/SCA tools (SonarQube or equivalents) and defining security gates.
  • Knowledge of cloud security and posture management (CSPM), preferably with Prisma Cloud or equivalent industry tools.
  • Minimum of 2 years of experience with Infrastructure as Code (preferably Terraform) and container orchestration (AWS ECS, Docker, Kubernetes, or Nomad).
  • Advanced knowledge of Git (preferably Bitbucket) and a B2 level of English.

Valuable knowledge

  • Experience with pentesting tools (Pentera or equivalents), vulnerability management, and incident response.
  • Knowledge of security frameworks and standards: OWASP (Top 10, ASVS), ISO 27001, or NIST.
  • Security certifications (AWS Security Specialty, CompTIA Security+, CEH, OSCP, …).
  • Observability (Grafana, Datadog, Prometheus, OpenTelemetry), programming languages (Java, Node.js, Python), and Confluent/Kafka.

This job was automatically translated to English, .

About the company

Randstad España

Randstad España

Staffing

View company profile
International company

Randstad España is a staffing agency.They recruit for client companies, so the employer you would work for is not named on this ad.