Job Closed
This listing is no longer active.
Learn how to leverage the new world of Decentralized Finance to multiply your capital.
DevOps Security Engineer
Location
Germany
Posted
105 days ago
Salary
0
Seniority
Senior
Job Description
DevOps Security Engineer
Decentralized Masters
• Own the security posture across all products: Legacy, Trading Bot, and future platforms. If something gets breached, it is your problem. If nothing gets breached, it is because of your work. • Conduct regular penetration testing, vulnerability assessments, and threat modeling aligned with OWASP standards and methodologies • Ensure full coverage of the OWASP Top 10 in application security testing, code reviews, and deployment checks • Perform security-focused code reviews across frontend, backend, and infrastructure code, catching what standard code reviews miss • Implement and manage secrets management (Vault, AWS Secrets Manager, or KMS), access controls, and least-privilege policies • Build and maintain incident response playbooks. When something breaks, you lead the response, run the post-mortem, and ship the fix • Stay ahead of Web3 and crypto-specific attack vectors: phishing campaigns, wallet exploits, API key compromises, supply chain attacks, and social engineering • Manage and coordinate external security audits and penetration tests from third-party firms • Design and implement test strategies across all products: unit tests, integration tests, end-to-end tests, API tests, and regression suites • Build and maintain automated testing frameworks and CI quality gates that prevent broken code from reaching production • Define and track quality metrics: test coverage, flakiness rate, regression detection latency, and bug escape rate • Write and execute security test cases: authentication flows, authorization controls, input validation, API abuse scenarios, and edge cases around financial data • Perform both white-box and black-box testing, leveraging full codebase access to catch issues that surface-level QA would miss • Test across the full stack: frontend UI, backend APIs, database queries, third-party integrations, and on-chain interactions • Maintain and improve cloud infrastructure on AWS using Infrastructure as Code (Terraform or CloudFormation) • Own CI/CD pipelines (GitHub Actions preferred): automated testing, security scanning, linting, and deployment • Harden infrastructure: network security, IAM policies, container security, and environment isolation • Build logging, monitoring, and alerting across all services (CloudWatch, Prometheus, Grafana, or equivalent) • Ensure audit trails for user actions, system changes, and access events • Manage production reliability, incident response, and cost optimization • Contribute production code across frontend and backend, bringing a security-first mindset to every feature you build • Build features, fix bugs, and ship improvements alongside the engineering team • Every line you write should make the product better and harder to break: input validation, error handling, authentication, and data protection by default • Participate in architecture discussions and code reviews, advocating for testability, reliability, and security in every decision
Job Requirements
- 5+ years in software engineering roles with meaningful, hands-on security and QA experience. We will verify this. If your security experience is theoretical, this is not the right fit.
- Fullstack development experience: you can build and ship features across frontend (React or equivalent) and backend (Node.js, Python, Go, or equivalent)
- Hands-on penetration testing and vulnerability assessment experience across web applications, APIs, and cloud infrastructure
- Strong working knowledge of OWASP standards, including the OWASP Top 10, OWASP Testing Guide, and OWASP secure coding practices
- Experience building automated test frameworks and integrating testing into CI/CD pipelines
- AWS expertise (EC2, ECS/EKS, Lambda, VPC, IAM, S3, RDS, CloudFront, WAF)
- Infrastructure as Code experience (Terraform, CloudFormation, or Pulumi)
- Container technologies: Docker and Kubernetes in production environments
- Scripting and automation proficiency in Bash and Python
- Experience with secrets management tools (HashiCorp Vault, AWS Secrets Manager, or similar)
- Familiarity with security and testing tools (Burp Suite, OWASP ZAP, Selenium, Cypress, Jest, Postman, or equivalent)
- Strong communication skills: you can explain security risks and quality tradeoffs clearly to non-technical stakeholders.
- Nice-to-Have
- Security certifications: OSCP, CISSP, CompTIA Security+, AWS Security Specialty, or equivalent
- Experience at a crypto, DeFi, Web3, or fintech product company (Coinbase, Phantom, Stripe, Casa, MetaMask, Zerion, Ramp, or similar)
- Familiarity with Web3-specific security concerns: wallet security, key management, on-chain monitoring, phishing mitigation
- SDET background or experience in a hybrid development-and-testing role
- Experience testing financial systems: payment flows, ledger integrity, double-spend prevention, or transaction monitoring
- Experience implementing zero-trust architectures
- Bug bounty participation, CVE publications, or contributions to open-source security tooling
Benefits
- Competitive salary + performance-based incentives tied to retention & LTV improvement
- Direct exposure to founders
- Team Offsites
- Remote work
- High ownership, high-impact role
Related Guides
Related Categories
Related Job Pages
More DevOps Engineer Jobs
Senior DevOps Engineer
EIG Services IncAs a dynamic, fast-growing provider of workers' compensation insurance and services, we are seeking a goal-oriented individual willing to put their ideas to work! We offer a positive, challenging work environment, combined with an opportunity to build your career as you help us grow our business. EMPLOYERS attributes its long-standing success to its most valuable resource, our employees across the United States. Known for the quality service and expertise we provide to our clients, and the exemplary work environment we provide for our employees. We live and breathe our core values: Integrity, Customer Focus, Collaboration, Initiative, Accountability, Innovation, and Personal Fulfillment. Discover an energetic environment that inspires top achievement.
Senior DevOps Engineer | 100% Remote (WFH) Opportunity General Summary The Senior DevOps Engineer is a key member of the IT Operations team, responsible for designing, automating, and maintaining the infrastructure and CI/CD systems that enable reliable, secure, and efficient software delivery across the organization. This role operates at the intersection of cloud infrastructure, container orchestration, and developer experience—ensuring that development, QA, data, and application teams can ship with confidence. Reporting directly to the IT Operations Director, this engineer will own critical systems including OpenShift/ROSA clusters on AWS, Jenkins and GitHub Actions pipelines, Argo-based GitOps workflows, and a multi-cluster observability stack built on OpenTelemetry. The ideal candidate brings deep hands-on experience with Kubernetes at scale, AWS infrastructure as code, and CI/CD pipeline design—combined with the judgment and communication skills to collaborate effectively across a broad set of cross-functional teams. Essential Duties and Responsibilities Infrastructure & Cloud - Design, provision, and maintain AWS infrastructure using Terraform, including VPCs, IAM roles (IRSA), PrivateLink, Route 53, S3, RDS, etc. - Leverage deep proficiency in Terraform and Ansible to grow the organization's infrastructure-as-code footprint across current and future platforms — using Terraform to provision and define infrastructure, and Ansible to configure, tune, and operationalize it. - Operate and maintain Red Hat OpenShift (ROSA) clusters on AWS, including upgrades, operator lifecycle management, and platform-level troubleshooting. - Implement and enforce Infrastructure-as-Code (IaC) practices across all environments, ensuring consistency, security, and repeatability. - Manage cross-account AWS patterns including IAM role chaining, S3 replication, and security services (GuardDuty, CloudTrail). CI/CD & Automation - Own and improve Jenkins pipelines end-to-end, including Jenkinsfile development, Ansible playbook integration, and credential management. - Build and maintain GitHub Actions workflows, including reusable workflow templates, composite actions, OIDC-based AWS auth, and enterprise policy configuration. - Manage and evolve ArgoCD-based GitOps deployment workflows, including ApplicationSets and multi-environment promotion strategies. - Automate operational processes across Linux and Windows targets, including certificate rotation, AD group management, and environment provisioning. Observability & Reliability - Configure and maintain the observability stack (OpenTelemetry Collectors, Prometheus, etc.) across multiple clusters. - Define and implement SLIs, SLOs, and actionable alerting to support reliability goals and reduce mean time to detection. - Develop and maintain runbooks, troubleshooting guides, and incident response documentation. - Collaborate with application teams to instrument services and improve end-to-end traceability. Collaboration & Mentorship - Partner with application development and data engineering teams to streamline deployment workflows and troubleshoot environment issues. - Collaborate with security and compliance teams on IAM policy design, secrets management, and vulnerability remediation. - Provide mentorship to junior team members and contribute to team knowledge sharing through documentation and technical presentations. - Communicate project status, risks, and infrastructure decisions clearly to leadership and non-technical stakeholders. Requirements - 7–11 years of experience in DevOps, Platform Engineering, SRE, or Infrastructure Engineering roles. - Deep hands-on experience with Kubernetes or OpenShift in production, including operator management, RBAC, ingress configuration, and cluster upgrades. ROSA or OCP on AWS strongly preferred. - Strong AWS infrastructure experience including VPC design, IAM (IRSA, cross-account trust), S3, Route 53, PrivateLink, RDS, etc.. Must be comfortable working in Terraform (or equivalent IaC tooling) at scale. - Strong experience with Ansible for configuration management, playbook development, and operational automation across Linux and Windows targets, including integration with orchestration platofrms and credential management. - Demonstrated experience building and maintaining CI/CD pipelines across Jenkins and GitHub Actions, reusable workflows, OIDC auth, and enterprise governance. - Experience with GitOps tooling (Argo) and deployment strategies (blue/green, canary, progressive rollout). - Working knowledge of observability tooling: Prometheus, Grafana, OpenTelemetry, or similar. - Proficiency in scripting and automation with Bash, Python, or Go. PowerShell experience is a plus given hybrid Linux/Windows environment. - Experience working in hybrid environments spanning Linux containers and Windows server administration. - Familiarity with Kafka or event-driven architecture on Kubernetes is a plus. - Experience in regulated industries (insurance, finance, healthcare) is preferred. Soft Skills & Working Style - Strong written and verbal communication skills with the ability to explain complex infrastructure concepts to non-technical stakeholders. - Collaborative mindset with willingness to work across domain boundaries — helping a data engineer debug a DAG or pairing with security on IAM policy review. - Documentation-oriented: writes runbooks, architectural decision records, and onboarding material as a natural part of the work. - Self-directed with the ability to manage multiple priorities, escalate appropriately, and make pragmatic trade-off decisions. - Curiosity and ownership mentality Education/Certifications - Bachelor’s degree in Computer Science, Systems Engineering, or a related field, or equivalent professional experience. - Certifications (Preferred, Not Required) - AWS Certified DevOps Engineer, Solutions Architect, or SysOps Administrator. - Certified Kubernetes Administrator (CKA) or Red Hat Certified Specialist in OpenShift. - HashiCorp Certified: Terraform Associate. Work Environment - Remote: This role is 100% remote, open to candidates currently located in the United States who are able to work without sponsorship. - Requires a private, quiet workspace suitable for focused work and video collaboration. - Hours: Schedules are set to accommodate the needs of the role and organization, and may be adjusted as needed. - Travel: Occasional travel to off-site locations for meetings may be required. Salary Range : $90,000 - $135,000 with a comprehensive benefits package. Details: EMPLOYERS Benefits and Perks About EMPLOYERS As a dynamic, fast-growing provider of workers' compensation insurance and services, we are seeking a goal-oriented individual willing to put their ideas to work! We offer a positive, challenging work environment combined with an opportunity to build your career as you help us grow our business in innovative and imaginative ways that are uniquely EMPLOYERS! Headquartered in Nevada, EMPLOYERS attributes its long-standing success to its most valuable resource, our employees across the United States. We are known for the quality service and expertise we provide to our clients and the exemplary work environment we provide for our employees. We live and breathe our core values: Integrity, Customer Focus, Collaboration, Initiative, Accountability, Innovation, and Personal Fulfillment. At EMPLOYERS, you will discover an energetic environment that inspires top achievement. As "America's small business insurance specialist," we have the resources, reputation, and expanding nationwide identity to enrich your work/life and enhance your career. About EMPLOYERS #LI-Remote
DevOps Engineering Manager
Highmark HealthCreating remarkable health experiences, freeing people to be their best.
Company : enGenJob Description : JOB SUMMARY The DevOps Manager will lead the DevOps function and drive the evolution of our infrastructure, automation, and deployment practices to support rapid, reliable product delivery. This role is responsible for overseeing a team of DevOps engineers and architects while working closely with Engineering, Security, and IT to design and operate scalable, secure, and highly available systems. The DevOps Manager will create and execute a strategic DevOps roadmap aligned with business and engineering objectives, assess the viability of current platforms and processes, and recommend improvements to meet both current and future needs. This role includes people leadership, technical oversight, and operational stewardship, with accountability for DevSecOps practices, system reliability, cost optimization, and compliance. ESSENTIAL RESPONSIBILITIES 1. Communicate effectively with all levels of the organization by: - Managing customer and expectations; facilitating, planning and meetings; translating customer expectations for staff and peers; representing Highmark with outside entities. - Preparing written procedures, policies, reports and correspondence; collaborating and negotiating with departments corporate wide. - Collaborating with company customers, staff, IT colleagues, and other stakeholders in identifying customer requirements, assessing impacts to other areas, considering available options, comparing costs and benefits, and recommending solutions. 2 Management Consulting - Identify issues and recommend solutions. - Create presentation and present concept to clients, tailoring presentation to audiences of varies levels, subject knowledge and size. - Implement recommendations/solutions and ensure client receives the necessary assistance to carry out solutions. - Liaising with clients to keep them informed of progress and to make relevant decisions. - Advise clients on options, risks, cost vs benefit, impact on other business processes and system priorities. 3. Ensure continuous improvement of processes and delivery of results within assigned unit/area. - Organize, direct and coordinate cross-functional activities including staff not under direct managerial control. - Encourage innovation and focus resources to ensure successful delivery of desired results. - Apply quantitative risk assessment to team's assignments to understand potential threats and the probability they will occur. - Lead team in mitigating risks and applying appropriate contingency plans to ensure minimal impacts to customers. 4. Provide leadership to the organization to respond to business opportunities/challenges, new technologies, legislation and other environmental factors. - Oversee analysis of issues or needs and review recommended solutions. - Assess the impact of strategic business and technical changes on the environment. - Responsible for managing all activities within an assigned business unit/area. - Foresee organizational impacts and understand the procedures associated with introducing new technologies, while seeking ways to collaborate with other teams outside area of responsibility to facilitate transitions. 5. Optimize the utilization of resources by applying appropriate concepts, technologies and workflows - Ability to accept direction and provide leadership to develop/maintain a high-performance work team. - Respond to feedback and champion process improvement initiatives by empowering their team to deliver quality services/products to internal and external customers. - Implement solutions that are consistent with Highmark’s strategic direction. - Keep abreast of current industry standards and trends. 6. Staff Management accountabilities to include but not limited to: - Developing and providing input to skills assessment and oversee personal development plans as it relates to career development. - Coaching, managing and developing employees by establishing clear goals, expectations, and strategies for employee performance. - Develop and administer performance reviews with measurable goals. - Provide opportunities for staff to maintain current industry knowledge. - Provide opportunities for employees to build collaborative relationships with customers. 7. Departmental Management planning and administrative accountabilities to include, but not limited to: - Departmental budgeting and fiscal responsibilities. - Manage teams that span geographic areas or functional areas. - Ensure compliance with corporate standards, policies and regulations (SOX, SSP, DIACAP, PHPLC, etc.). - Establish and use metrics as a tool to benchmark and improve operational excellence - Develop and implement short-term and long-term departmental plans. - Consult and evaluate vendor solutions where appropriate. 8. Other duties as assigned or requested. EDUCATION Required - Bachelor’s Degree in Information Technology, Management Information Systems, Computer Science or closely related discipline Substitutions - None Preferred - Master’s Degree in Information Technology, Management Information Systems, Computer Science or closely related discipline EXPERIENCE Required - 5 years in a leadership / mentoring role - 5 years of planning, implementing, maintaining and growing capabilities within relevant discipline - 3 years of developing, communicating and presenting concepts to varying audience Preferred - 5+ years in a leadership / mentoring role including leading engineers/architects in complex, hybrid on-prem and cloud environments - Management experience in: employee development plans, performance evaluations, goals development - Experience in budget administration and process improvement - Knowledge and experience in developing strategic plans - Demonstrated competency in the execution of multiple projects, including managing resources across multiple projects to meet goals LICENSES or CERTIFICATIONS Required - None Preferred - None SKILLS - Knowledge of company’s business practices and direction as well as familiarity with the company’s products and resources - Knowledge of the assigned business unit/area's direction and practices - This position is required to comply with all Highmark Corporate Policies and IT Procedures, Standards and Strategies - Demonstrated ability to own vendor relationships for key DevOps platforms (e.g. GitLab, JFrog Artifactory), including regular touchpoint, roadmap reviews, and escalation management. - Proven team leadership and mentoring experience, including setting technical direction, prioritizing work (Gitlab Plan), and coaching DevOps Engineers and Architects. - Deep hands-on expertise with GitLab CI/CD for pipeline design, merge-request workflows, security/scanning integration, and release orchestration. - Expertise in JFrog Artifactory and related tooling (e.g., Curation, XRay) for artifact lifecycle management, repository strategy, security scanning, and software supply-chain governance. - Operational and architectural experience with containerization and orchestration (OpenShift, Docker, Kubernetes). - Expertise in Ansible (or equivalent configuration-management/IaC tooling) to provision, configure, and maintain infrastructure consistently. - Strong scripting skills (Python, YAML, Bash/Shell or similar) for CI/CD pipeline logic, internal tooling, and automation of build, test, deployment, and operational tasks. - Solid understanding of DevSecOps practices, including embedding SAST/SCA/container scanning into CI/CD pipelines and enforcing consistent security controls. - Demonstrated ability to design and manage end-to-end CI/CD pipelines that connect source control, artifact management, automated testing, security gates, and deployment across multiple environments. - Deep understanding of networking, security best practices, and system architecture. - Excellent communication and stakeholder management skills. - Solid understanding of networking concepts and protocols, security best practices, and system administration. - Strong understanding of security principles and best practices. - Excellent problem-solving and debugging skills. - Strong communication and collaboration skills, with the ability to communicate core DevOps concepts (CI/CD, SAFe Agile & Automation) - Background in high-availability, distributed systems. - Experience in scaling SaaS platforms. - Familiarity with compliance frameworks (SOC 2, ISO 27001, FedRAMP, etc.). - Experience managing multi-region or global infrastructure. Language (Other than English): None Travel Requirement: 0% - 25% PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS Position Type Office-based Teaches / trains others regularly Occasionally Travel regularly from the office to various work sites or from site-to-site Occasionally Works primarily out-of-the office selling products/services (sales employees) Never Physical work site required Yes Lifting: up to 10 pounds Constantly Lifting: 10 to 25 pounds Occasionally Lifting: 25 to 50 pounds Never Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job. Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies. As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements. Pay Range Minimum: $118,400.00 Pay Range Maximum: $196,800.00 Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets. Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law. We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below. For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Cloud DevSecOps Search Engineer
SAICAdvancing the power of technology and innovation to serve and protect our world.
We are seeking a highly experienced and results-driven Cloud DevSecOps Search Engineer with a minimum of 10 years of relevant industry experience. The ideal candidate will be a hands-on developer with a strong technical foundation in AWS cloud native architecture, SOLR/Zookeeper Search, DevSecOps automated secure pipelines, Web based Search architecture, and infrastructure integration. This exceptional position will be a key member of the USPTO internal and external hosted website agile development teams specifically responsible for the search infrastructure that supports the product teams as they seek to migrate, modernize, automate, and innovate their search applications. This role requires deep technical expertise and the ability to architect, design, develop, and engineer the innovation, automation, and modernization of complex projects that drive business value and strategic insights. This position is remote and can be worked from any location in the continental U.S. Key Responsibilities: - Operate and maintain the internal and external website search infrastructure, including SOLR/Zookeeper servers, security, indexing, analytics. - Collaborate with cross functional Agile Drupal development teams for search requirements and reporting integration. Manage search indexing and analytics/reporting needs. - Develop, Build, and deploy search automation, CI/CD pipelines, scripts, and infrastructure from the ground up using Infrastructure as Code - IaC (tools such as Terraform, CloudFormation). - Leverage automation and containerization (Docker, Kubernetes) and serverless architectures to modernize the SOLR/Zookeeper environment. - Develop end-to-end plans for migration of cloud based SOLR/ZooKeeper search capability to an AWS managed search service. - Architect, Develop, Build and Deploy pilots, prototypes, and proof of concept solutions to validate potential search modernizations and updates in an AWS cloud native environment. - Implement transparency, traceability, and appropriate security handling in line with best practices and applicable compliance standards including Authorization to Operate certifications. - Design scalable, secure and cost-effective infrastructure for search implementation, deployment, and maintenance. - Implement and document reusable code libraries, SOPs and best practices for modernization, automation, and innovation development and deployment. SAIC® is a premier Fortune 500® mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives. We are approximately 24,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.5 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Senior Java Developer
SAICAdvancing the power of technology and innovation to serve and protect our world.
SAIC is seeking an experienced Senior Java Developer and AWS engineer to join our dynamic Agile teams delivering software solutions to the United States Patent and Trademark Office. In this role you will develop and maintain robust, scalable, and reliable Java applications within an automated DevSecOps AWS Environment. Responsibilities - Design, develop, maintain, and deliver highly scalable and reliable software using Java web technologies. - Demonstrate experience developing enterprise web-based applications. - Develop and deploy Java applications on AWS using best practices and cloud-native services Ensure compliance with AWS security and compliance standards (FedRAMP, HIPAA, etc.) - Complete tasks to migrate large, complex Java applications from on-premises to AWS cloud - Optimize application performance, scalability, and cost efficiency on AWS - Create Terraform scripts to automate various DevOps tasks - Provide software development support to translate the enterprise's strategy for legacy system upgrade/migration to the desired future state - Design and implement database and data storage solutions. - Develop and maintain automated CI/CD pipelines integrated with automated testing, code quality, and security scans. - Plan and implement automation and orchestration tools to streamline infrastructure provisioning. - Ensure code, cloud platform and infrastructure are designed and optimally configured for scalability, performance, resiliency, reliability, and security. - Collaborate with other engineers and product owners to analyze, design, and implement user stories using an agile methodology. - Write high-quality software code that complies with design specifications and meets development and support requirements. - Experience in Oracle and other RDBMS. - Experience working in fast-paced Agile Environment and familiarity with tools like Rally and JIRA. SAIC® is a premier Fortune 500® mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives. We are approximately 24,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.5 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.


