- Страна
- Израиль
Откликайтесь
на вакансии с ИИ

DevSecOps Engineer
Привлекательная позиция для тех, кто хочет полной ответственности за направление DevSecOps в успешной e-commerce компании. Гибридный график в Тель-Авиве и работа с современным стеком (AI/LLM) делают вакансию актуальной.
Сложность вакансии
Роль требует высокого уровня самостоятельности, так как кандидат будет единственным специалистом по DevSecOps в команде. Необходимо глубокое знание как AWS/GCP, так и специфических инструментов безопасности (SAST/DAST) и Kubernetes.
Анализ зарплаты
Зарплата не указана, но для позиции DevSecOps с опытом от 3 лет в Тель-Авиве рыночные показатели являются одними из самых высоких в индустрии. Предложенный диапазон соответствует средним ставкам для опытных инженеров в израильском хайтеке.
Сопроводительное письмо
I am writing to express my interest in the DevSecOps Engineer position at Resident. With over three years of experience in securing cloud-native environments and a strong background in DevOps, I am excited about the opportunity to take end-to-end ownership of the security posture for your AWS/GCP infrastructure and Kubernetes clusters.
In my previous roles, I have successfully integrated SAST/DAST/SCA tools into CI/CD pipelines and implemented robust IAM policies following the principle of least privilege. I am particularly drawn to Resident's data-driven culture and your interest in securing emerging technologies like LLMs, which aligns perfectly with my proactive approach to modern security challenges. I am confident that my technical expertise and ability to collaborate across R&D and Data teams will help raise the security bar across the company.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в residenthome уже сейчас
Присоединяйтесь к лидеру e-commerce в Тель-Авиве и станьте ключевым экспертом по безопасности облачных платформ!
Описание вакансии
Who we are:
Resident is an industry leader in the Direct-to-Consumer (e-commerce) space. While our customers are primarily based in the US, our R&D, Product, and Data teams have been operating out of Tel Aviv since our founding. Our mission is simple: we are building a best-in-class e-commerce platform that leverages data and technology to create a competitive advantage for our brands. Starting from the marketing acquisition funnel and continuing through each customer’s journey, our tools and technology enable us to go the extra step to deliver a world-class customer experience.
Our company is built around continuously improving our ability to introduce new customers to our products and wow them with exceptional experiences through the shopping and post-purchase journey. We love to use data and metrics to drive our decisions while keeping in mind that customers don’t speak in numbers and that each one should be treated as a member of our family. Oh, and by the way, you’ll get to work with a diverse group of experts around the globe. You can expect a hard-working team of people who understand how to create meaningful connections and get great work done virtually - it’s in our nature!
What we do:
Our DevOps team is responsible for the Resident platforms end-to-end, from cloud infrastructure to production delivery. We build and operate the systems that enable engineering teams to move fast and safely, while ensuring high standards of reliability, security, performance, and scalability. Through automation, strong architecture, and secure-by-design practices, we continuously improve how we deploy, monitor, and protect our production environments.
What you will be doing:
As the sole DevSecOps owner within the DevOps team, you will take end-to-end responsibility for improving the security of our cloud and production environments. You will design and implement security controls across AWS/GCP- from hardening infrastructure and securing Kubernetes to ensure our platform stays secure as it scales.
You will work closely with cross-functional teams such as DevOps, R&D, Product, and Data to embed security into the way we build software. This role is ideal for someone who wants to make a real impact, takes ownership of cross-team initiatives, is curious and eager to learn, and enjoys driving improvements that raise the security bar across the company.
This is a hybrid role, requiring 2 days per week at our R&D site in Tel Aviv.
Responsibilities:
- Architect, implement, and maintain a strong security posture across cloud environments (AWS / GCP), aligned with best practices (CIS Benchmarks, Well-Architected Framework)
- Own and integrate automated security controls into CI/CD pipelines (SAST, DAST, SCA, container scanning), including tuning to reduce noise and enforce policy gates
- Secure Infrastructure as Code (IaC) and harden servers, services, and Kubernetes clusters
- Design and manage IAM, roles, policies, and secrets management to enforce Least Privilege
- Lead security initiatives around emerging technologies, including AI models, LLM integrations, and data pipelines
- Continuously monitor and drive remediation of vulnerabilities and security findings across the stack
- Partner with Developers and Data Engineers to embed security into the SDLC and strengthen security culture
- Support security operations, including incident response and root cause analysis
Qualifications:
- 3+ years of hands-on experience in DevOps, SRE, DevSecOps, or Cloud Security roles in production environments
- Strong ownership mindset with proven ability to lead initiatives end-to-end with minimal supervision
- Strong cloud security expertise (AWS or GCP preferred), including IAM, networking, and managed services
- Strong Linux fundamentals and hardening experience; scripting/automation skills in Python and/or Bash
- Solid experience with CI/CD pipelines (GitHub Actions, Jenkins, etc.) and container platforms (Docker, Kubernetes)
- Strong understanding of system architecture, REST APIs, and networking fundamentals (DNS, TCP/IP, load balancing)
- Strong knowledge of authentication and authorization mechanisms (OAuth, OIDC, SAML) and secure token/secret handling
- Hands-on experience implementing security scanning tools (SAST/DAST/SCA), including tuning and enforcing build-blocking when required
- Familiarity with security standards and best practices (OWASP Top 10, NIST, CIS)
- Exposure to AI/ML security and securing LLM integrations - major plus
- Strong English communication skills, with the ability to explain risk clearly to both technical and non-technical stakeholders
- Analytical thinker, with a proactive approach, who can prioritize effectively in a fast-paced environment
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- AWS
- Python
- Linux
- Terraform
- SAML
- OAuth
- GCP
- Kubernetes
- GitHub Actions
- Bash
- IAM
- Docker
- Jenkins
- OIDC
- SCA
- SAST
- DAST
Возможные вопросы на собеседовании
Проверка практического опыта внедрения политик безопасности в облаке.
Расскажите о вашем опыте реализации принципа наименьших привилегий (Least Privilege) в среде AWS или GCP. С какими трудностями вы сталкивались?
Оценка навыков автоматизации безопасности в процессе разработки.
Как вы подходите к настройке порогов срабатывания (noise reduction) в инструментах SAST/DAST, чтобы не блокировать работу разработчиков ложными срабатываниями?
Проверка знаний безопасности контейнеризации.
Какие основные шаги вы предпримете для харденинга (укрепления защиты) кластера Kubernetes в продакшене?
Оценка способности работать с новыми технологиями, упомянутыми в вакансии.
Какие специфические риски безопасности вы видите при интеграции LLM (больших языковых моделей) в продукт и как их можно минимизировать?
Проверка навыков взаимодействия с другими командами.
Как вы убеждаете команду разработки приоритизировать исправление уязвимостей, если они сосредоточены на выпуске новых фич?
Похожие вакансии
Devops Middle+/Senior
DevOps Middle +/ Senior
Senior DevOps/Mlops
Middle DevOps Engineer
Senior DevOps/SRE Engineer (On-Premise инфраструктура)
DevOps - senior
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- Израиль