As part of its information system overhaul project, our client is looking for an experienced DevSecOps engineer to join its teams. The candidate will have significant experience in securing CI/CD pipelines, cloud environments, and expertise in Kubernetes. The candidate will play a key role in protecting applications and systems throughout the development cycle.
Main Responsibilities:
- Kubernetes Security Management: Configure and maintain the security of Kubernetes clusters (network policies, secrets, activity monitoring, etc.).
- Development and Optimization of Secure CI/CD Pipelines to automate deployments and security tests.
- Management of Incident Detection and Response Systems using tools such as Prometheus, Grafana, etc.
- Implementation of Secure Solutions for Secret and Access Management with Vault.
- Compliance of Environments with Security Standards (ISO 27001, PCI-DSS, GDPR, etc.) by conducting regular audits and documenting processes.
- Collaboration with Development and Infrastructure Teams to integrate security at every stage of the application lifecycle.
- Analysis and Response to Security Incidents by implementing fixes and making recommendations to strengthen resilience.
- Training and Awareness of Internal Teams on security best practices, particularly around Kubernetes and containers.
Required Skills:
- Expertise in Kubernetes.
- Significant experience in CI/CD and integrating security into these pipelines.
- In-depth knowledge of application security principles (OWASP, Zero Trust, etc.).
- Proficiency in configuration management and automation tools (Terraform, Ansible, etc.).
- Knowledge of containerization technologies: Docker, Kubernetes, and associated tools.
- Ability to implement monitoring and alerting solutions (Prometheus, Grafana).
- Good knowledge of security testing: vulnerability scanning, penetration testing, network security.
- Familiarity with DevSecOps security tools.
Qualifications:
- 3 to 5 years of experience in DevSecOps or a similar role.
- Kubernetes certifications and cloud security skills (AWS Certified Security, etc.) are a plus.
- Team spirit, proactivity, and ability to work independently.
- Ability to solve complex problems quickly and efficiently.