DevSecOps Engineer - Infra
Betsson Group View all jobs
- Malta Island
- Permanent
- Full-time
- Implement and maintain secure infrastructure on the cloud: Design, deploy, and manage secure AWS environments, leveraging various AWS services such as Amazon EC2, Amazon S3, AWS Identity and Access Management (IAM), AWS Lambda, and Edge Security services. Audit and monitor security groups, network access control lists (ACLs), and other security features to protect sensitive data and systems.
- Monitoring & Logging: Implement proactive security monitoring and alerting mechanisms, leveraging AWS services like AWS CloudTrail, Amazon Control Tower,, Amazon GuardDuty, and Amazon Inspector. Work closely with our Information Security team to identify and respond to security incidents, conduct forensic investigations.
- Vulnerability and Patch Management: Coordinate vulnerability scanning and patch management processes to mitigate security risks. Coordinate with external security vendors for penetration testing, security audits and the remediation of findings with operation teams.
- Security Incident response: Assist the Information Security team in managing security incidents, including containment, investigation, and recovery.
- Security architecture and design: Work closely with architects, central security team, and development teams to integrate security controls into the overall system architecture within AWS and Kubernetes infrastructure. Review and provide guidance on secure design principles, secure coding practices, and secure deployment strategies.
- You will be expected to form part of a 24/7 on call roster to support the engineering team during out of office incidents calls
- Development teams
- Product owners
- Information Security teams
- Internal Area teams
- Architects
- Experience with the following technologies:
- AWS
- Kubernetes
- Terraform
- Github Advanced Security
- Strong experience as a DevSecOps Engineer or similar role, with a focus on implementing security practices in AWS environments, including Kubernetes infrastructure.
- In-depth knowledge of AWS services and their security features, such as IAM, VPC, S3, CloudTrail, GuardDuty, Inspector, as well as Kubernetes architecture and security controls.
- Familiarity with infrastructure-as-code (IaC) tools like CloudFormation or Terraform for managing Kubernetes infrastructure.
- Knowledge of best practices in IT operations, such as ITIL (IT Infrastructure Library) and DevOps principles.
- Understanding of secure coding practices, API security, code scanning tools, and vulnerability management processes specific to Kubernetes environments.
- Strong knowledge of security frameworks and standards (e.g., OWASP, NIST, CIS) applicable to both AWS and Kubernetes environments.
JobsinMalta