Senior DevOps Engineer (Vulnerability Management + Security)

Softserve — Poland · Posted ~1 day ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

About The Role This role supports and secures customer’s public cloud environments as the firm evolves from a predominantly Azure-based footprint into a multi-cloud operating model with increasing adoption of Google Cloud Platform (GCP) and Oracle Cloud Infrastructure (OCI). The Public Cloud Security Engineer serves as a senior technical leader responsible for identifying, engineering, and operating cloud-native vulnerability and exposure management capabilities across public cloud platforms. The role focuses on reducing systemic risk by detecting control breaks, insecure configurations, and exploitable vulnerabilities before they result in incidents — while ensuring security tooling scales with cloud adoption rather than slowing it down. This position sits at the intersection of cloud engineering, security engineering, and reliability, with accountability for designing, onboarding, and operating security platforms that protect cloud workloads in a highly regulated environment. Responsibilities Vulnerability management, including experience in remediating vulnerabilities and leading a teamExperience in prioritizing team tasksPublic cloud environments including Microsoft Azure (primary/incumbent platform), Google Cloud Platform (GCP) for emerging data, platform, and AI workloads, Oracle Cloud Infrastructure (OCI) for strategic and regulated workloads, Multi-region cloud architectures supporting production, pre-production, and development environments, shared responsibility security models across infrastructure, platform, and application layersCloud vulnerability management across compute, container, platform, and managed servicesDetection of misconfigurations, control drift, and insecure cloud patternsExposure management spanning identity, network, data, and workload layersEngineering control-break detection techniques for cloud environmentsReducing systemic risk through automation, standardization, and preventative controlsCloud-native and enterprise security platforms, including: vulnerability scanning and posture management tools, SIEM and centralized logging platforms, endpoint and workload protection technologies (EDR/XDR), packet capture and network visibility tooling where requiredIntegration of security platforms via APIs into cloud and DevOps workflowsConfiguration management and automation across large-scale security platformsInfrastructure as Code (IaC) and configuration management for security controlsTerraform and cloud-native tooling to enforce secure-by-default patternsCI/CD and DevSecOps integrations to shift vulnerability detection leftPython-based scripting and automation for control validation and responsLead the engineering, onboarding, and production support of cloud security and vulnerability management platformsDesign and operate security controls that support Azure today while scaling into GCP and OCIDetect, analyze, and remediate cloud vulnerabilities, misconfigurations, and control gapsEngineer control-break detection techniques to identify systemic security failures earlyOwn the architecture, deployment, and lifecycle management of cloud security platformsDefine and measure security-focused SLIs and SLOs in partnership with stakeholdersContribute to incident response, mitigation, and post-incident reviews from a cloud security perspectivePartner with cloud engineering teams to embed security controls into platform designResearch, evaluate, and recommend cloud security technologies aligned to customer’s risk postureMentor and develop junior security engineers, promoting strong engineering discipline and operational excellenceApply SRE principles to security platforms to reduce outages and operational frictionParticipate in system design, platform management, and capacity planningEnsure audit-ready documentation, operational hygiene, and clear escalation pathsMaintain a strong understanding of enterprise risk culture, control frameworks, and risk reduction techniques Requirements Bachelor’s degree in Computer Science, Information Systems, or equivalent engineering experienceSenior-level experience engineering and operating security platforms in public cloud environmentsStrong hands-on experience with Azure, plus exposure to GCP and/or OCIDeep experience in vulnerability management, configuration assessment, and exposure reductionProficiency in Python for security automation and toolingExperience operating large-scale distributed systems in regulated environmentsStrong understanding of UNIX/Linux internals, networking, and cloud infrastructureFinancial services or highly regulated industry experienceExperience integrating security platforms using APIsFamiliarity with SIEM query languages (e.g., Splunk SPL, SQL-based analytics)Experience with DevSecOps and CI/CD security integrationsExposure to containerized and Kubernetes-based environmentsExperience applying AI/ML techniques to security analytics or detection SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.