AI Summary
SoftServe is seeking a Senior DevOps Security Engineer to develop and implement security measures throughout the software development lifecycle. The ideal candidate will have 5+ years of experience in DevOps and Security Engineering, with expertise in cloud security, DevSecOps, and automation.
Key Highlights
Develop and implement security measures throughout the software development lifecycle
Build and maintain automated pipelines for asset and Software Bill of Materials (SBOM) generation
Implement and manage scalable IAM guardrails for cloud and corporate environments
Technical Skills Required
Benefits & Perks
Health insurance package
Mentoring Program
Customer Hero Program
Code! The project is not overwhelmed with meetings and other non-development-related activities
Job Description
WE ARE
SoftServe is a dynamic digital service and consulting company, founded in 1993, with a global presence across the USA, Europe, APAC, and LATAM regions. Our team of skilled professionals collaborates on over 2,000 projects, driving transformation and optimizing business strategies for ISVs and Fortune 500 companies.
Our Critical Services Center of Excellence (CoE) is a group of passionate technologists specializing in software architecture, startups, and enterprise platforms. As part of SoftServe’s Cybersecurity Practice Team, we help clients build trust in their systems by delivering reliable, tailored security solutions. We don’t just identify gaps – we guide organizations through every step of the improvement journey, making sure they’re equipped to handle today’s threats and tomorrow’s challenges.
With deep expertise across a wide range of technologies, we adapt our approach to meet each client’s unique needs. Our team covers a broad spectrum of cybersecurity domains: cost optimization & migration efficiency, infrastructure and application modernization, regulatory compliance & governance excellence, security posture strengthening, data protection and privacy assurance, and secure use of AI.
We are a diverse, distributed team with members based in Poland, Ukraine, Spain, and other European countries, collaborating across borders to deliver world-class cybersecurity solutions.
IF YOU ARE
- An expert with 5+ years of experience in DevOps and Security Engineering
- Passionate about building secure cloud infrastructure (AWS, Azure, GCP) for software development lifecycle needs
- Strong in several security domains (e.g. IAM, IaaS, network) and willing to learn others
- Skilled in at least one major cloud provider (AWS preferred) and its security services
- Experienced with identity and access management platforms (IdP, IGA, PAM) and concepts (SAML, Oauth 2.0 OIDC)
- Familiar with modern DevSecOps tooling (SAST, DAST, SCA, IaC scanning)
- Confident with securing CI/CD pipelines
- Competent in performing threat modeling and risk assessments for cloud-native applications and architectures
- Strong in automation and scripting skills (Python, Go or similar)
- A professional with strong communication skills to work with cross-functional teams
- Capable of communicating in English freely in a multicultural environment
- Develop and implement security measures throughout the software development lifecycle, including requirements gathering, design, development, testing, and deployment phases
- Build and maintain automated pipelines for authoritative asset and Software Bill of Materials (SBOM) generation
- Implement and manage scalable IAM guardrails for cloud (AWS/GCPAzure) and corporate (Okta) environments
- Contribute to the technical roadmap and execute on projects for data protection, including key management, encryption, and tokenization
- Develop and implement secure configurations for containerized (Kubernetes, EKS) and IaC (Terraform) workflows
- Work with SRE and GRC team to test and validate resilience patterns and disaster recovery capabilities
- Provide clear technical context on security controls and architecture to GRC and Internal Audit teams
- Develop and enforce security policies, standards, and procedures, ensuring compliance with relevant regulations and industry best practices
- Stay up to date with the latest security threats, vulnerabilities, and industry trends, and provide recommendations on security enhancements and risk mitigation strategies
- Collaborate with cross-functional teams to educate and promote security awareness, conducting training sessions and workshops on secure coding practices and security-related topics
- Gain certifications from leading providers (Google, AWS & others)
- Empower you to scale your expertise with others by joining the Mentoring Program
- Excel business of our clients from startups and ISVs to Enterprise and Fortune 500 companies
- Create an exceptional customer experience and impact the company's global success, and be recognized by the Customer Hero Program
- Care for your wellness with a health insurance package
- Code! The project is not overwhelmed with meetings and other non-development-related activities
- Support hundreds of thousands of people every day by helping them not to waste precious time on maintaining healthy nutrition
- Help you with your individual initiatives — we are open to them, just come and share your ideas!