Join Qualysoft as a DevSecOps Engineer to design and implement cloud security controls across AWS, focusing on defense-in-depth across identity, network, and infrastructure layers. This role requires translating security requirements into automated guardrails and integrating security into CI/CD pipelines.
🏢 About Qualysoft
Qualysoft is a company dedicated to providing innovative DevSecOps solutions, helping organizations build secure and efficient software delivery processes.
🎯 The Role
As a DevSecOps Engineer, you will be responsible for developing automation scripts and tools in Python and Bash to streamline security operations, enforce compliance, and reduce manual effort across the environment. You will also integrate security into CI/CD pipelines and DevOps workflows, ensuring security is a first-class component of the delivery process.
✅ Key Responsibilities
Cloud Security Engineering: Design and implement cloud security controls across AWS (primary), applying defense-in-depth across identity, network, and infrastructure layers.
Security Automation: Develop automation scripts and tools in Python and Bash to streamline security operations, enforce compliance, and reduce manual effort across the environment.
Secure CI/CD: Integrate security into CI/CD pipelines and DevOps workflows, ensuring security is a first-class component of the delivery process.
DevSecOps Architecture: Design, implement, and maintain enterprise DevSecOps architectures that integrate security throughout all phases of the SDLC.
Automated Security Testing: Integrate automated security testing into software delivery pipelines, including SAST, DAST, SCA, container and image scanning, secret detection, and infrastructure security scanning.
Vulnerability Management: Operate the vulnerability management lifecycle end to end using tools such as Qualys.
Governance and Compliance: Implement security measures and governance policies aligned with regulatory requirements (e.g., NIS2, GDPR).
Container and Kubernetes Security: Apply security best practices to containerized workloads and Kubernetes (EKS).
Documentation and Standards: Produce architecture artifacts and security documentation to support audit readiness and continuous compliance initiatives.
Collaboration: Work with cross-functional teams to ensure security controls are practical, adopted, and maintained.
📌 Required Qualifications
Minimum 3 years of relevant experience in DevSecOps, security engineering, or DevOps with a strong security focus.
Solid understanding of AppSec principles, the OWASP Top 10, and secure coding practices.
Good knowledge of Linux OS administration, TCP/IP networking concepts, virtualization, and databases.
Proficiency with versioning tools (Git) and hands-on experience with CI/CD concepts and methodologies.
Good understanding of cloud platforms, particularly AWS.
⭐ Desirable Experience
Experience with containerization technologies such as Docker and Kubernetes.
Knowledge of security tools and frameworks such as Qualys, OWASP ZAP, and SonarQube.
Understanding of security compliance standards such as NIS2 and GDPR.
Please let Qualysoft know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.