DevSecOps Engineer integrating security practices throughout the development lifecycle at Keboola. Join a growing SaaS company focusing on cloud security and AI automation.
Responsibilities
Design and oversee security architecture with a focus on DevSecOps principles (shift-left security).
Integrate security controls into CI/CD pipelines and automate security testing (SAST, DAST, SCA, container scanning).
Lead security assessments and audits, identify vulnerabilities and implement countermeasures.
Conduct security code reviews and provide feedback to developers on best practices.
Implement security monitoring tools to detect and respond to security incidents.
Guide and mentor team members on security best practices, DevSecOps culture, and emerging threats.
Build and maintain "security as code" approaches - policy as code, compliance as code.
Own end-to-end resolution of security findings from client security teams - from analysis through infrastructure fixes to communication of remediation status.
Collaborate with the SRE team on reliability improvements that enhance security posture.
Requirements
5+ years' experience securing production services and Kubernetes environments.
Automation-first mindset, including using modern tools (including AI-assisted workflows) to streamline security operations.
Experience integrating security into CI/CD pipelines and automating security checks.
Expertise securing applications and infrastructure on GCP, AWS, or Azure (IAM, network security, encryption, logging).
Hands-on experience with infrastructure as code (Terraform) and securing IaC configurations.
Experience with security monitoring, intrusion detection, and incident response.
Ability to perform threat modeling and vulnerability assessments.
Experience with zero trust architecture in cloud environments.
Proficiency with UNIX systems and scripting (Python, Bash, Go).
Experience with GitOps workflows using ArgoCD.
Experience working with external security teams and managing security findings from discovery through resolution.
(nice to have) Experience with policy as code tools (Open Policy Agent, Kyverno), chaos engineering for security, or service mesh security (Istio, Linkerd).
(nice to have) Understanding of SOC 2 or ISO 27001 compliance frameworks.
Strong documentation, analytical and problem-solving skills.
Collaborative approach, promoting a "security is everyone's responsibility" mindset.
Excellent communication skills - ability to explain security concepts to developers and external security teams.
Self-organized with ability to manage multiple priorities.
Proactive mindset with commitment to continuous learning.
Resilience in handling stressful situations.
Ability to balance security requirements with developer experience.
Benefits
Competitive compensation.
Generous paid vacation time. And we mean generous.
Cool new offices in the heart of Holesovice in Prague. You need to be 3 times a week in the office.
Senior Backend Engineer building product features and maintaining infrastructure for insurance platform. Employing tools like Terraform, Kafka, Datadog and Qovery with a strong DevOps focus.
DevOps Systems Engineer supporting customer operations in Annapolis Junction, MD. Responsible for creating, sustaining, and troubleshooting complex operational data flows.
OpenShift Fresher assisting Cloud team in managing containerized applications using Red Hat OpenShift. Supporting CI/CD, deployment automation, and cloud - native application environments.
Site Reliability Engineer for Leidos ensuring reliability, performance, and scalability of complex distributed systems for the Navy - Marine Corps Intranet. Collaborating with teams to maintain and optimize network operations and services.
DevOps Engineer evolving banking infrastructure for a fintech company. Focusing on observability, incident response, and platform automation in a hybrid work setup.
Lead Site Reliability Engineer managing critical IT systems for S&P Dow Jones Indices. Focused on service availability, incident management, and developer collaboration to enhance operational reliability.
Lead DevOps Engineer developing AI - powered supply chain intelligence solutions at S&P Global Mobility. Collaborate with data scientists and engineers to optimize operational infrastructure and continuous delivery processes.
Senior DevOps Engineer managing development and deployment pipelines for AI products at Plaud. Optimize infrastructure, enhance productivity, and collaborate with cross - functional teams.
Senior SRE Engineer ensuring reliability and performance of AI products at Plaud. Designing scalable systems and leading incident response to improve operational maturity.
DevOps Engineer supporting big data solutions and AWS infrastructure deployment at Enlighten. Collaborating with teams to ensure reliability, scalability, and performance of cloud services.