DevSecOps 工程师 – 远程工作模式
DevSecOps Engineer – Remote Work Type
Directio 是一家全球 IT 服务公司。我们主要提供基于云和移动应用的咨询、编码、测试、部署和管理服务,并从波兰、菲律宾、墨西哥和美国的办公室提供全天候支持。我们通过加速客户的数字化转型,帮助快消品、零售、汽车和 SaaS 客户迎接未来。我们秉承“我们编写成功”的理念,优先考虑客户、顾问和合作伙伴的成功。
项目简介
我们正在寻找一名 DevSecOps 工程师加入一个为国际公司提供的项目,该公司在多个市场运营。
你将加入一个负责 Azure、Kubernetes、部署、Microsoft 365 和值班支持的小型平台团队。这是一个需要动手操作的角色,结合平台工程和 DevOps 职责,并对安全工程实践拥有所有权。
你将支持客户从单体架构向服务架构迁移,构建所需的基础设施、环境、CI/CD 管道和可观测性,同时确保现有平台的稳定性。
同时,你将负责加强组织内的安全实践,并支持 ISO 27001 认证的技术方面。
职责
- 你将与团队一起运行和维护平台,使用 Azure、AKS、部署、升级、事件响应和值班支持;
- 你将构建并运营迁移单体架构到服务所需的基础设施,包括环境、Azure DevOps 中的 CI/CD 管道、基础设施即代码、监控和告警;
- 你将管理外部攻击面,维护面向互联网的资产清单,监控潜在暴露,并确保漏洞得到有效处理;
- 你将把安全集成到 Azure DevOps 和 Kubernetes 交付管道中,包括代码、依赖项、密钥、容器和基础设施即代码扫描;
- 你将建立并维护 Azure 和 Microsoft 365 的安全基线,包括身份和访问管理、多因素认证、云安全态势、Microsoft Defender 和访问管理流程;
- 你将全程管理漏洞管理流程,从识别漏洞、协调修复到验证解决并保持适当的证据;
- 你将负责
查看英文原文
Directio is a global IT services company. We consult, code, test, deploy, and manage mainly cloud-based and mobile applications, providing around-the-clock support from our offices in Poland, the Philippines, Mexico, and the USA. We prepare our FMCG, retail, automotive, and SaaS clients for the future by accelerating their digital transformation. Operating under the “We Code Success” principle, we prioritize the success of our clients, consultants, and partners.
About project
We are looking for a DevSecOps Engineer to join a project for our client, an international company operating across multiple markets.
You will be joining a small platform team responsible for Azure, Kubernetes, deployments, Microsoft 365, and on-call support. This is a hands-on role combining platform engineering and DevOps responsibilities with ownership of security engineering practices.
You will be supporting our client’s migration from a monolithic architecture to services, building the required infrastructure, environments, CI/CD pipelines, and observability while ensuring the stability of the existing platform.
At the same time, you will be responsible for strengthening security practices across the organization and supporting the technical side of the ISO 27001 certification journey.
Responsibilities
- You will be running and maintaining the platform together with the team, working with Azure, AKS, deployments, upgrades, incident response, and on-call support;
- You will be building and operating infrastructure required for the migration from a monolithic architecture to services, including environments, CI/CD pipelines in Azure DevOps, Infrastructure as Code, monitoring, and alerting;
- You will be managing the external attack surface, maintaining an inventory of internet-facing assets, monitoring potential exposures, and ensuring vulnerabilities are addressed effectively;
- You will be integrating security into Azure DevOps and Kubernetes delivery pipelines, including code, dependency, secrets, container, and Infrastructure as Code scanning;
- You will be establishing and maintaining the Azure and Microsoft 365 security baseline, including identity and access management, MFA, cloud security posture, Microsoft Defender, and access management processes;
- You will be managing the vulnerability management process end-to-end, from identifying vulnerabilities and coordinating fixes to verifying their resolution and maintaining appropriate evidence;
- You will be responsible for the technical security controls supporting the ISO 27001 certification programme, working closely with the compliance lead;
- You will be providing technical input for customer security questionnaires and audits and participating in discussions with customers and auditors when deeper technical expertise is required;
- You will be supporting penetration testing activities performed by an external partner, including defining the scope, coordinating testing activities, and ensuring identified findings are properly addressed;
- You will be automating operational and security processes wherever possible and continuously improving the reliability and security of the platform.
Requirements
- You have 5+ years of professional experience in Platform Engineering, DevOps, or a similar role;
- You have strong hands-on experience with Microsoft Azure and Kubernetes/AKS in production environments, including building clusters, pipelines, and environments, performing upgrades, and supporting production systems;
- You have hands-on experience in security engineering and have taken ownership of security-related processes rather than only supporting them;
- You have experience with the technical side of ISO 27001 or an equivalent security framework, or you have managed vulnerability management processes end-to-end;
- You have practical knowledge of security tooling and practices, including external attack surface monitoring, DAST, SAST, SCA, secrets scanning, container scanning, and cloud security posture management;
- You have experience with Azure DevOps and CI/CD pipelines;
- You have experience with Infrastructure as Code and infrastructure automation;
- You have scripting and automation skills using Bash, PowerShell, or Python;
- You are comfortable documenting technical processes and security controls and communicating technical topics clearly to customers, security teams, and auditors;
- You are able to independently prioritize tasks and take ownership in a small, senior team environment;
- You are fluent in English.
Nice to have
- Knowledge of Estonian or German;
- Previous experience working with enterprise or banking customers and supporting customer security audits;
- Experience supporting organizations through security certification programmes;
- Experience working on modernization projects involving migration from monolithic architectures to services.
We offer
- Salary: 25 000 - 33 000 PLN netto / B2B;
- Private healthcare, Multisport card and trainings.
Originally posted on Himalayas