Our client is a software development and digital solutions company serving clients across the FinTech, Gaming, and Marketing sectors. The company has successfully delivered 20+ innovative products across 5 international markets, including Brazil, Armenia, Saudi Arabia, and the UAE.
As the company scales its platforms across these markets, they're looking for a Security Engineer to embed security into the software development lifecycle, secure their cloud-native infrastructure, and help engineering teams ship applications that are resilient, compliant, and built to last.
⟢ Responsibilities:
- Weave security into the SDLC from design through deployment, running threat models and risk assessments before code ships.
- Automate security testing across the pipeline — SAST, DAST, SCA, and IaC scanning — to catch issues early.
- Harden Kubernetes and Docker environments with RBAC, network policies, and least-privilege access controls.
- Build and maintain security guardrails inside CI/CD pipelines (Jenkins, GitLab CI, GitHub, Azure DevOps, Bitbucket).
- Secure cloud workloads across Azure, AWS, and GCP, and strengthen IAM, MFA, and RBAC practices.
- Investigate security alerts, drive root-cause analysis, and support incident response end-to-end.
- Partner with engineering, DevOps, and QA to remediate vulnerabilities and design secure-by-default systems.
- Strengthen software supply-chain security through SBOMs, dependency scanning, and secret detection.
- Support audits and help maintain compliance with frameworks like ISO 27001, NIST CSF, and CIS Benchmarks.
- Run secure-coding sessions and security awareness training for development teams.
⟢ Requirements:
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field.
- 5+ years of experience in Application Security, Security Engineering, DevSecOps, or Cloud Security.
- Hands-on experience securing web applications, REST APIs, containers, and cloud-native workloads.
- Practical experience with Kubernetes, Docker, and at least one major cloud provider (Azure, AWS, or GCP).
- Comfortable running SAST, DAST, SCA, and IaC scans as part of a vulnerability management program.
- Experience embedding security into CI/CD pipelines (Jenkins, GitLab CI, GitHub, Bitbucket, or Azure DevOps).
- Solid grounding in secure SDLC principles and threat modeling.
- Familiarity with tools such as SonarQube, Trivy, OWASP ZAP, Burp Suite, Nessus, Microsoft Defender, or Wazuh.
- Working knowledge of Python or Bash for security automation.
⟢ Benefits:
- Flight ticket and full working visa provided.
- Full sponsorship and support throughout the visa and work permit process.
- Top-tier equipment, including a MacBook and iPhone.
- Competitive compensation tailored to your skills and experience.
- Comprehensive leave package.
- A dynamic, inclusive culture that invests in your growth.
⟢ Recruitment Process:
- HR Interview
- Technical Interview (take-home assignment & 2 technical interviews)
- Background Check
- Offer