onsite
DevSecOps Engineer - Cohesion Force
Security Engineer
Lead security integration in CI/CD pipelines, automate threat modeling and risk assessments, and enforce secure coding practices across cloud-native deployments using modern DevSecOps tools.
About the role
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines that integrate automated security testing and compliance checks.
- Conduct threat modeling and risk assessments for new and existing applications, translating findings into actionable remediation plans.
- Perform code reviews and enforce secure coding standards across multiple development teams.
- Automate security controls for containerized workloads, including image scanning, runtime protection, and secrets management.
- Collaborate with platform, security, and operations teams to ensure continuous compliance with industry regulations and internal security policies.
Requirements
- 3+ years of experience in DevSecOps or related roles, with hands‑on expertise in CI/CD tooling (GitHub Actions, GitLab CI, Jenkins, etc.).
- Proficiency in container security, Kubernetes, and cloud security best practices (AWS, Azure, or GCP).
- Strong knowledge of threat modeling frameworks (MITRE ATT&CK, STRIDE) and risk assessment methodologies.
- Experience with automated security tools such as Snyk, Trivy, Aqua, or similar.
- Excellent communication skills and ability to work independently or in cross‑functional teams.