Truelogic is seeking a Senior DevSecOps Engineer to strengthen the security posture of our software development and deployment lifecycle. The ideal candidate will partner closely with Engineering, DevOps, and Product teams to embed security best practices into CI/CD pipelines, infrastructure, and codebases.
Requirements
- 5+ years of experience in DevSecOps, Application Security, or related roles.
- Strong understanding of cloud environments (AWS preferred) and associated native security services.
- Experience with CI/CD tools (e.g., GitHub Actions, Jenkins, CircleCI) and integrating security into pipelines.
- Hands-on experience with SAST/SCA tools (e.g., SonarQube, Snyk, Semgrep, Trivy) and vulnerability management platforms.
- Familiarity with IaC (Terraform, CloudFormation) and security configuration management.
- Comfort with scripting and automation (Python, Bash, or similar).
- Strong communication skills and the ability to collaborate effectively with other departments asynchronously or via Slack.
- Demonstrated familiarity with AI-based coding tools, MCP servers, and secure implementation considerations preferred.
- Working knowledge of SIEM platforms and log analysis tools a plus (e.g., Splunk, Panther, Coralogix).
- Knowledge of security frameworks and best practices a plus (NIST CSF, CIS Benchmarks, OWASP Top 10).
- Self-directed, curious, and able to manage priorities in a fast-paced environment.
Benefits
- 100% Remote Work
- Highly Competitive USD Pay
- Paid Time Off
