DevSecOps Engineer
On-siteSydney, New South Wales, Australia
Job Summary
Embed security practices across the SDLC to promote a shift-left and secure-by-design approach. Automate security controls within CI/CD pipelines and implement application security testing including SAST, DAST, SCA, and container scanning. Strengthen cloud security and infrastructure across AWS, Azure, or GCP, while performing threat modelling, vulnerability management, and risk mitigation activities. Ensure compliance with frameworks such as CIS, NIST, ISO27001, and PCI-DSS. Establish monitoring, logging, and alerting for security events, and support incident response and remediation processes. Manage identity and access controls, secrets management, and Zero Trust practices. Collaborate with Dev, Sec, and Ops teams to promote shared ownership of security and provide guidance on secure coding practices.
Required Qualifications
- Proven experience integrating security into CI/CD pipelines (e.g. Jenkins, GitHub Actions, GitLab CI, Azure DevOps)
- Hands-on experience with security testing tools (SAST, DAST, SCA, container security tools)
- Strong scripting and automation skills (Python, Bash, or similar)
- Experience with cloud platforms and security controls (AWS, Azure, or GCP)
- Knowledge of monitoring, logging, and alerting solutions for security events
- Experience with vulnerability management and remediation practices
- Solid understanding of security frameworks and compliance standards
- Familiarity with IAM, secrets management, WAF, and Zero Trust principles
- Strong problem-solving and risk analysis skills
- Excellent collaboration and communication skills, with the ability to work across multiple teams
- Must be able to undergo a police check
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.