Design and implement security automation across CI/CD pipelines
Own and evolve the organizations DevSecOps strategy and security-as-code practices
Collaborate with devs and SREs to embed threat modeling, SAST, DAST, and IaC scanning
Establish own relevant healthy DevOps processes and practices within the team
Define secure cloud architecture standards for GCP-based services
Continuously assess risks, vulnerabilities, and compliance gaps through tooling and process
Establish and champion secure coding and deployment practices
Lead incident response and create playbooks for security incident
Required:
6+ years in DevOps using Cloud Native Technologies
2+ years focused on DevSecOps/Security Engineering
Strong experience in CI/CD tools (Jenkins, GitLab CI, ArgoCD, etc.) with security integrations
Hands-on with infrastructure as code (Terraform, Helm) and security linters
Expertise in container security (Docker, Kubernetes, Aqua/Trivy/Anchore)
Ability to implement and maintain SAST, IaC, SCA, DAST, IAST, Container Runtime Security Runtime SCA
Familiarity with threat modelling, attack surface reduction, and vulnerability management
Experience with REST APIs and GraphQL API design and development
Proficient in GCP security services
Experience with compliance (SOC2, ISO27001) and policy-as-code (OPA, Sentinel)
Why us
You will be working with a lean team of passionate and talented individuals. We know that working with like-minded people is important.
We are on a mission to supercharge brick-and-mortar retail stores in the era of e-commerce. Our customers give us confidence in our journey, and you will have a huge impact with your wor.k
You will be free to experiment and can choose to do things differently.
Lastly, we deeply care about a culture of being a solver. Come, be one with us!
Equal opportunity employer
Grey Orange Inc. is an equal employment opportunity employer. The company s policy is not to discriminate against any applicant or employee based on race, color, religion, national origin, gender, age, sexual orientation, gender identity or expression, veteran status, marital status, mental or physical disability, and genetic information, or any other basis protected by applicable law. Grey Orange also prohibits harassment of applicants or employees based on any of these protected categories.
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: Engineering - Software & QARole Category: DevOpsRole: DevOps EngineerEmployement Type: Full time