DevSecOps Specialist

Posted 72ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

First DevSecOps at Tivita creating a secure foundation for a scalable infrastructure. Establishing security measures and collaborating with engineering teams for enhanced health management solutions.

Responsibilities:

  • You will be Tivita's first dedicated DevSecOps, responsible for establishing the foundations of a secure, predictable, resilient, and scalable infrastructure.
  • Create a DevSecOps foundation that enables structured growth without hindering the development team's velocity.
  • Identify critical risks, define realistic priorities, and create roadmaps that balance speed, reliability, and security.
  • Map the attack surface and assess the current state of infrastructure and security pipelines.
  • Identify critical vulnerabilities, exposures of sensitive data, and inadequate access policies.
  • Implement IAM and least-privilege policies in cloud environments.
  • Validate, automate, and test backup and disaster recovery procedures.
  • Integrate essential security stages into CI/CD pipelines (Secrets Scan, SAST, SCA, IaC Scan) without introducing blocking gates at the outset.
  • Protect applications against the OWASP Top 10 using WAFs, rate limiting, and anti-bot measures.
  • Implement encryption at rest and in transit, and deploy DLP controls on critical interfaces.
  • Establish canary releases, automatic rollback, and secure deployment practices.
  • Build a SIEM layer and create incident response playbooks.
  • Review LGPD/privacy policies, onboarding/offboarding processes, and governance.
  • Engage the engineering team with contextualized training and security testing.
  • Implement the “paved road” concept to provide autonomy and reduce dependence on Infra/Sec.

Requirements:

  • 5+ years of experience in DevOps, SRE, cloud infrastructure, or security in critical environments
  • Deep security knowledge: hands-on experience with security in CI/CD pipelines, secrets management, IaC scanning, vulnerability assessment, and threat modeling
  • Google Cloud Platform (GCP): advanced hands-on experience with IAM, Compute Engine, Cloud Storage, Cloud SQL, VPC, networking, and security
  • Infrastructure as Code (IaC): advanced proficiency with Terraform or CloudFormation; ability to structure IaC for multiple environments
  • CI/CD and Automation: hands-on experience with GitHub Actions, GitLab CI, or Jenkins; automation of security pipelines
  • Containerization and Orchestration: strong practical knowledge of Docker and Kubernetes; ability to implement container security
  • Security Tools: hands-on experience with SAST (Semgrep), SCA (Snyk, Aikido), secrets scanning (git-leaks), IaC scanning (Trivy), and WAFs
  • Systems Thinking: proven ability to identify structural risks, prioritize trade-offs (cost vs. security vs. speed), and create realistic roadmaps
  • Strategic Communication: ability to explain technical decisions to non-technical stakeholders and to clearly structure 30/60/90-day plans

Benefits:

  • Not specified