GoMining
DevSecOps Engineer
NEWWorldwideFull-timeGlobal
š Remote
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will integrate security practices into the software development lifecycle, embedding security checks and automated compliance tests into CI/CD pipelines. You will secure cloud and on-premises infrastructure, harden containerized and Kubernetes environments, monitor systems for security threats, respond to incidents, and drive continuous improvements. You will collaborate with developers, SREs, and QA to guide secure coding, perform threat modeling, and ensure compliance with standards such as ISO27001, SOC 2, GDPR, and NIST.
Requirements
- āStrong knowledge of cloud platforms (AWS, GCP, Azure) and their security services
- āProficiency in scripting and programming (Python, Bash, Go, TypeScript)
- āExperience with CI/CD tools (GitLab, Jenkins, CircleCI) and integrating security into pipelines
- āHands-on experience with Kubernetes, Docker, and container security tools (Trivy, Clair, Anchore)
- āFamiliarity with infrastructure as code (Terraform, Pulumi) and securing IaC workflows
- āUnderstanding of network security, identity and access management, and secrets management (Vault, AWS Secrets Manager)
- āKnowledge of monitoring and logging tools (Prometheus, Grafana, OpenTelemetry) for security observability
Responsibilities
- āEmbed security checks, vulnerability scanning, and automated compliance tests into CI/CD pipelines
- āImplement secure cloud and on-premises infrastructure using access control, encryption, and network segmentation best practices
- āManage and harden containerized environments, including image scanning, runtime protection, and pod security policies
- āMonitor systems for security threats, respond to incidents, and implement continuous improvements
- āCollaborate with developers, SREs, and QA to ensure security-first development practices, provide guidance on secure coding, and conduct threat modeling
- āEnsure systems and processes comply with standards like ISO27001, SOC 2, GDPR, and NIST and maintain audit readiness
Benefits & Perks
- āLearning support with courses, English classes, and conferences (up to 100% reimbursement)
- āUnique loyalty program offering corporate digital miners to earn passive income
- āRetreats in international locations (for example, company apartments in Cyprus)
- āMemorable events with prizes and an Employee of the Month award
- āPaid leave: up to 28 vacation days plus 8 company holidays and 5 personal days per year
- āFlexible hours and remote work
Tech Stack
CircleCIcontainer scanningAnchoreClairAWS Secrets ManagerInfrastructure-as-CodeBashTypeScriptcomplianceidentity and access management