Job Summary
As a DevSecOps Engineer, you will design and build secure-by-default CI/CD pipelines and cloud architectures You will ensure that security, compliance, and governance are embedded across the entire software delivery lifecycle, supporting FAIR+ mission while enabling speed, reliability, and scalability.
Key Responsibilities
- Design, implement, and maintain secure CI/CD pipelines using GitHub Actions with integrated security and compliance controls.
- Build and operate cloud-native infrastructure on GCP using Terraform and Google Kubernetes Engine (GKE).
- Implement policy-as-code using OPA/Gatekeeper to enforce security and governance standards automatically.
- Lead vulnerability management practices using tools such as Trivy, including scanning, remediation, and reporting.
- Embed secure-by-default engineering practices across application, infrastructure, and platform components.
- Integrate GCP security services for identity, access management, logging, monitoring, and threat detection.
- Automate security configurations, secrets management, and compliance documentation.
- Support SRE-based operations including observability, incident response, and post-mortem practices.
- Collaborate with engineering teams through Agile ceremonies and maintain clear technical documentation.
Skill Requirements
- Strong experience building secure CI/CD pipelines with GitHub Actions.
- Hands-on expertise with Terraform, GKE, and Google Cloud Platform (GCP).
- Strong knowledge of cloud security principles, IAM, and GCP security services.
- Experience implementing policy-as-code frameworks such as OPA/Gatekeeper.
- Proven experience with vulnerability management and container security tools such as Trivy.
- Solid background in DevSecOps, automation scripting, and Linux environments.
- Experience with Infrastructure as Code, containerisation, and cloud-native architectures.
- Strong communication skills and ability to work effectively in Agile/Scrum teams.
Other Requirements
Builds secure CI/CD pipelines and cloud architectures using GitHub Actions, Terraform, OPA/Gatekeeper, Trivy, GKE, and GCP security services. Leads vulnerability management, policy‑as‑code, and secure‑by‑default engineering.