IGAMINGHUNT→
DevSecOps Engineer at IGAMINGHUNT in Portugal, Portugal
Mid LevelRemoteFull-timePortugal, Portugal
Skills
kuberneteseksistioservice meshterraformansiblechefawsgcpgitopasastdastdependency scanningcontainer scanningvaultpamtcp/iposi modelinfrastructure-as-codeci/cdcommunicationproblem solvingcollaboration
Job Description
We are looking for a hands-on DevSecOps Engineer to join a fast-growing software development company delivering fintech and iGaming products. In this role, you will take ownership of security across cloud infrastructure, CI/CD pipelines, and development processes, helping build secure and scalable products.
Responsibilities:
- Drive the evolution of the company’s DevSecOps function by defining security initiatives, long-term priorities, and promoting a security-first engineering mindset.
- Partner with the DevOps team to improve the security and resilience of Kubernetes (EKS), Istio, Service Mesh, and related cloud-native infrastructure.
- Support engineering teams during service transitions by embedding security best practices into operational processes and ensuring effective knowledge sharing.
- Develop and maintain policy-as-code frameworks and infrastructure validation mechanisms using technologies such as OPA and other compliance automation tools.
- Improve the security of infrastructure provisioning and deployment workflows across Terraform, Ansible, and other Infrastructure-as-Code solutions.
- Integrate, maintain, and optimise security testing and scanning capabilities throughout the software development and release lifecycle.
- Build automation around security monitoring, compliance checks, and operational controls to increase efficiency and reduce manual effort.
Requirements:
- Strong practical understanding of modern DevOps principles and secure CI/CD pipeline design.
- Hands-on experience with Kubernetes or other enterprise-grade container orchestration platforms.
- Proven experience working with Infrastructure-as-Code and configuration management technologies such as Terraform, Ansible, Chef, or equivalent tools.
- Solid background in administering production infrastructure, including web servers, databases, and supporting services.
- Good understanding of networking concepts, including TCP/IP, routing principles, and the OSI model.
- Experience securing distributed systems and microservices-based architectures.
- Proficiency with Git or other source code version control platforms.
- Practical experience securing cloud environments, preferably AWS, though experience with GCP or other major cloud providers is also valuable.
- Ability to assess infrastructure security posture, identify vulnerabilities, and implement appropriate remediation measures.
- Experience implementing identity and access management controls together with security automation practices.
- Hands-on knowledge of secrets management platforms (such as Vault) and Privileged Access Management (PAM) solutions.
- Experience integrating SAST, DAST, dependency scanning, container scanning, or similar security tooling into CI/CD workflows.
- Good understanding of Secure Software Development Lifecycle (SSDLC) principles and familiarity with security maturity frameworks such as OWASP SAMM v2.
- English level: Upper-intermediate or higher.
What’s in it for you:
- 24 days of annual leave plus paid sick leave
- Private health insurance and a sports & wellbeing allowance
- Recognition gifts for important life milestones
- Learning & development budget for courses, certifications and conferences
- Regular team events and company gatherings
- Clear opportunities for career growth in a fast-growing business
- Company-supported language learning
Benefits
24 days of annual leave plus paid sick leave
Private health insurance
Sports & wellbeing allowance
Recognition gifts for important life milestones
Learning & development budget
Regular team events and company gatherings
Career growth opportunities
Company-supported language learning