- Location
- MX
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Source
- Breezy HR
Description
We are looking for a hands-on Senior DevSecOps Engineer to help build secure, scalable, and reliable cloud infrastructure, Kubernetes platforms, and CI/CD pipelines. You will work closely with engineering and platform teams to integrate security into the software delivery lifecycle and make secure-by-default practices easy to adopt.
The role combines DevSecOps, cloud security, infrastructure automation, Kubernetes security, and software supply-chain security, with a strong focus on practical engineering and automation.
Project Details
- Start: ASAP
- Project duration: 12 months+
- Locations: Argentina, Brazil, Mexico
- Working hours: EST business hours
- English: B2+
Responsibilities
- Integrate security into cloud infrastructure, Kubernetes platforms, CI/CD pipelines, and developer self-service workflows.
- Design and implement secure-by-default patterns for IAM, workload identity, secrets management, network security, infrastructure as code, application deployment, and workload protection.
- Assess the current security landscape, identify gaps and risks, and establish scalable security practices within DevOps and platform teams.
- Build automated, risk-based security guardrails across source control, container builds, infrastructure changes, and application deployments using policy-as-code.
- Strengthen Kubernetes, container, and software supply-chain security, including cluster configuration, workload isolation, ingress, admission controls, runtime protection, dependency management, SBOMs, artifact signing, and build provenance.
- Partner with engineering teams to identify, prioritize, and remediate vulnerabilities and security misconfigurations across cloud, Kubernetes, and CI/CD environments.
- Support security incident response across infrastructure and delivery systems, including investigation, containment, recovery, and post-incident improvements.
- Translate security, regulatory, and audit requirements into practical and maintainable engineering controls.
- Create automation, documentation, runbooks, and security standards, while mentoring engineers on DevSecOps best practices.
Requirements
- 5+ years of hands-on experience in DevSecOps, DevOps, Cloud Security, Platform Engineering, or a related role, with significant responsibility for security engineering and automation.
- Strong hands-on experience securing AWS or Google Cloud, including IAM, workload identity, networking, encryption, logging, and cloud-native security controls.
- Deep experience operating and securing Kubernetes and containerized workloads, including managed platforms such as Amazon EKS or Google Kubernetes Engine.
- Strong hands-on experience with Terraform, including reusable modules, dependency management, policy enforcement, and safe change management.
- Strong understanding of CI/CD and release engineering, including artifact security, deployment controls, approval gates, trusted builds, and rollback strategies.
- Experience implementing automated security controls such as vulnerability and dependency scanning, container image scanning, secrets detection, policy-as-code, infrastructure scanning, cloud configuration assessment, and software supply-chain security.
- Strong scripting or programming skills for automation, integrations, tooling, and operational problem-solving.
- Experience working in regulated or audited environments and translating frameworks such as HIPAA, SOC 2, PCI DSS, HITRUST, or SOX into engineering controls.
- Strong communication and technical leadership skills, with the ability to balance security, reliability, developer experience, maintainability, and delivery speed.
- English: B2+ or higher.
Nice to have
- Experience with Terraform Cloud, including workspace management, policy controls, remote execution, and state governance.
- Experience with GitOps and delivery platforms such as Argo CD, Harness, or Codefresh.
- Experience with observability and incident-management platforms such as Datadog, Groundcover, or PagerDuty.
- Experience with cloud security posture management, vulnerability management, workload/runtime protection, and endpoint security platforms such as Qualys, CrowdStrike, Prisma Cloud, Lacework, Wiz, or comparable tools.