SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
inDrive is seeking a Senior DevSecOps Engineer to join AppSec Cheetahs, their team of ethical hackers focused on vulnerability discovery, application security strengthening, and knowledge sharing across the engineering organization.
In this role, you will design and build secure CI/CD pipelines by integrating static (SAST), dynamic (DAST), and interactive (IAST) application security testing tools. You'll develop automation for security processes, vulnerability management, and compliance checks to enable continuous security feedback. You will secure Infrastructure as Code scripts (Terraform, CloudFormation) by scanning for misconfigurations and vulnerabilities before deployment, and evaluate, implement, and manage security tools for vulnerability scanning, monitoring, and compliance.
Beyond technical execution, you'll act as a security champion within the organization, mentoring developers and operations teams on secure coding practices and DevSecOps principles. This is an opportunity to combine DevOps and Python expertise with application security, work on real security challenges, and have direct impact on product security.
REQUIREMENTS:
- 5+ years of experience in DevOps, Security Engineering, or similar role, with at least 2 years specifically focused on DevSecOps
- Proven experience with CI/CD tools such as Jenkins, GitLab CI, or equivalent
- Strong scripting skills in Python, Bash, or Go for automation tasks
- Knowledge of at least one major cloud provider (AWS, Azure, or GCP) and its security services (AWS Security Hub, Azure Security Center, GCP Security Command Center)
- Experience with Infrastructure as Code tools like Terraform, Ansible, or CloudFormation
- Strong understanding of containerization technologies (Docker, Kubernetes) and their security challenges, including securing container images and runtime environments
- Familiarity with security tools: SAST (SonarQube, Checkmarx), DAST (OWASP ZAP, Burp Suite), and vulnerability scanners (Trivy, Nessus)
- Problem-solving abilities, strong communication skills, and ability to collaborate across teams