DevSecOps Specialist
Posted 72ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
First DevSecOps at Tivita creating a secure foundation for a scalable infrastructure. Establishing security measures and collaborating with engineering teams for enhanced health management solutions.
Responsibilities:
- You will be Tivita's first dedicated DevSecOps, responsible for establishing the foundations of a secure, predictable, resilient, and scalable infrastructure.
- Create a DevSecOps foundation that enables structured growth without hindering the development team's velocity.
- Identify critical risks, define realistic priorities, and create roadmaps that balance speed, reliability, and security.
- Map the attack surface and assess the current state of infrastructure and security pipelines.
- Identify critical vulnerabilities, exposures of sensitive data, and inadequate access policies.
- Implement IAM and least-privilege policies in cloud environments.
- Validate, automate, and test backup and disaster recovery procedures.
- Integrate essential security stages into CI/CD pipelines (Secrets Scan, SAST, SCA, IaC Scan) without introducing blocking gates at the outset.
- Protect applications against the OWASP Top 10 using WAFs, rate limiting, and anti-bot measures.
- Implement encryption at rest and in transit, and deploy DLP controls on critical interfaces.
- Establish canary releases, automatic rollback, and secure deployment practices.
- Build a SIEM layer and create incident response playbooks.
- Review LGPD/privacy policies, onboarding/offboarding processes, and governance.
- Engage the engineering team with contextualized training and security testing.
- Implement the “paved road” concept to provide autonomy and reduce dependence on Infra/Sec.
Requirements:
- 5+ years of experience in DevOps, SRE, cloud infrastructure, or security in critical environments
- Deep security knowledge: hands-on experience with security in CI/CD pipelines, secrets management, IaC scanning, vulnerability assessment, and threat modeling
- Google Cloud Platform (GCP): advanced hands-on experience with IAM, Compute Engine, Cloud Storage, Cloud SQL, VPC, networking, and security
- Infrastructure as Code (IaC): advanced proficiency with Terraform or CloudFormation; ability to structure IaC for multiple environments
- CI/CD and Automation: hands-on experience with GitHub Actions, GitLab CI, or Jenkins; automation of security pipelines
- Containerization and Orchestration: strong practical knowledge of Docker and Kubernetes; ability to implement container security
- Security Tools: hands-on experience with SAST (Semgrep), SCA (Snyk, Aikido), secrets scanning (git-leaks), IaC scanning (Trivy), and WAFs
- Systems Thinking: proven ability to identify structural risks, prioritize trade-offs (cost vs. security vs. speed), and create realistic roadmaps
- Strategic Communication: ability to explain technical decisions to non-technical stakeholders and to clearly structure 30/60/90-day plans
Benefits:
- Not specified



















