Blockdaemon
DevOps Security Engineer
Dublin, Ireland, Galway, ...Full-timeGlobal
š Midš On-site
ActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will secure software from first line of code to production by reviewing releases, triaging vulnerabilities, and building automated pipeline and infrastructure controls. You will integrate and tune security tools into CI/CD, write automation and policy-as-code, audit IaC and cloud configurations, and harden container orchestration. You will enable engineers with self-service guardrails, run threat modeling for high-risk changes, and contribute runbooks and incident response practices.
Requirements
- ā3ā5+ years in a combined DevOps, Security Engineering, or DevSecOps role building and operating systems
- āHands-on CI/CD pipeline engineering experience with Jenkins, GitLab CI, or GitHub Actions
- āExperience implementing and tuning SAST, DAST, and SCA tools in automated pipelines
- āProven ability to secure production workloads on AWS, Azure, or GCP including IAM and network segmentation
- āHands-on experience securing Docker and Kubernetes environments including image scanning and runtime security
- āProficiency with Infrastructure as Code (Terraform, CloudFormation, or Pulumi) and auditing IaC with policy-as-code
- āStrong scripting and automation skills in Python, Go, or Bash
- āExperience running or contributing to a vulnerability management program
- āStrong understanding of OWASP Top 10, CWE/CVE ecosystems, secrets management, TLS/mTLS, and common web/API attack vectors
Responsibilities
- āConduct deep-dive vulnerability and security reviews of releases before production
- āOwn and enforce pre-shipment security gates in CI/CD with pass/fail criteria
- āTriage and classify vulnerabilities from SAST, DAST, SCA, and container scans
- āMaintain and improve a vulnerability management program with SLAs
- āBuild and improve automated security tooling integrated into CI/CD
- āDevelop and operate security-focused pipeline stages (static analysis, SCA, dynamic testing, IaC validation, container scanning)
- āBuild custom security automation and policy-as-code enforcement
- āAudit infrastructure-as-code for misconfigurations and policy violations
- āDefine and enforce cloud security policies across AWS, Azure, or GCP
- āHarden container orchestration: RBAC, network policies, pod security, runtime threat detection
- āEnsure logging, monitoring, and alerting support incident detection and forensics
- āProvide developers with self-service tooling, documentation, and fast feedback
- āBuild internal security guardrails such as pre-commit hooks, IDE integrations, and hardened CI templates
- āRun targeted threat modeling sessions for high-risk features
- āContribute to security standards, runbooks, and incident response playbooks
Tech Stack
DevOpsCheckovDevSecOpsDockerKubernetesGitOpsFluxFalcoGrypeTLS