EU remote
DevOps Engineer (security)
About this role
About the job: Onapsis is on a mission to safeguard the most critical business applications that business depends on daily. Over 20% of the Fortune 100 rely on Onapsis to secure their business-critical applications and ensure they are compliant and available. We are looking for self-motivated and enthusiastic DevSecOps Engineers who want to impact cybersecurity by continuing to advance, maintain, and enhance our platform features in Threat Detection & Response, Vulnerability Management, and Compliance Automation.
What you will be doing: Working closely with leadership, product management, and our Engineering and Operations teams to design and implement security-focused capabilities across the SDLC using Shift-Left-On-Security principles. This role partners with InfoSec, Technical Operations, and Platform Engineering teams to ensure CI/CD frameworks, infrastructure, and automation tooling are secure by design, resilient, and capable of protecting our customers at scale.
Key Responsibilities: Security Automation & CI/CD: Embed, maintain, and optimize automated security testing (OSS, SAST, DAST, SCA, Container Security and related K8s configuration management) directly into GitLab CI/CD pipelines. Vulnerability & Patch Management: Perform platform security assessments, verify reported exploits, and support vulnerability remediation activities. Security Compliance: Participate in security audits, provide actionable feedback, and coordinate with engineering teams to meet compliance timelines and regulatory standards.
Penetration Testing Enablement: Provision and configure isolated test environments, deploy target application builds, and coordinate secure access requirements for penetration testing activities. Security Operations & Incident Response: Collaborate with cross-functional teams to evaluate security releases, generate compliance reports, and support security monitoring/observability using Grafana, New Relic, or OpenTelemetry.
Security Advocacy: Conduct internal software security training and advocate for secure coding standards and DevSecOps best practices across engineering teams. Threat Modeling & Risk Mitigation: Conduct threat modeling exercises for new features and infrastructure changes to identify vulnerabilities before code hits production. Support our Engineering teams: Provide in-depth knowledge of the DevSecOPS principles and tools to our engineering teams.