DevSecOps Engineer
PureLogics
Published Date: • Lahore, Pakistan (On-Site)
Description
Knowledge of cloud platforms (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes, OpenShift).
Implement security tools and best practices within CI/CD pipelines to automate security testing, vulnerability assessments, and ethical hacking.
Design, deploy, and manage secure infrastructure using Infrastructure as Code (IaC) principles and tools like Terraform, CloudFormation, or Ansible.
Lead and perform ethical hacking, penetration testing, and security audits to identify vulnerabilities, assess risks, and recommend mitigation strategies.
Conduct penetration testing on applications, networks, and cloud environments using tools like Burp Suite, Metasploit, Nmap, and Kali Linux.
Develop, maintain, and enhance security-focused regression testing frameworks to proactively identify and address security vulnerabilities.
Monitor and respond to security threats, perform regular security assessments, and implement remediation strategies using SIEM tools like Splunk, ELK, or AWS Security Hub.
Participate in incident response and post-incident analysis, contributing to continuous improvement and learning.
Collaborate with cross-functional teams to define and implement best practices for secure DevOps processes.
Ensure adherence to security compliance frameworks (e.g., NIST, CIS, ISO 27001, SOC 2) and assist in security audits.
Implement security hardening techniques for applications, networks, and infrastructure.
Develop and enforce security policies for secrets management, identity & access management (IAM), and role-based access control (RBAC).
Automate security scanning, configuration management, and patch management processes.
Conduct threat modeling and risk assessment to improve security posture.
Work with developers to integrate security best practices into the software development lifecycle (SDLC).
Stay updated with the latest security threats, vulnerabilities, and industry trends.
Required Skills:
Required Qualification:
Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field.
About Us:
PureLogics is a full services technology company with having presence in the USA, UAE, and in Lahore. Over the past 18+ years, we have matured from a narrowly-focused five-person team to a well-established technology hub with around employees. We’re CMMI Level 2 and ISO Certified company and highly acclaimed AWS consulting partners.
The success of our business mainly lies in building a team of A-players, who work together and build together, and who crave perfection in everything they produce for our elite clients. We offer the opportunity to individuals that are eager to take on tough challenges under our mentorship toward a bright future.
What are we offering?
Annual Paid Leaves
Leave Encashment
Paid Certifications
Health, Life Insurance
Provident Fund
Child Education Program
Referral Bonus Program
Car & Bike Finance Program
Monthly Achievements
Public Holiday & Weekend Compensation
Responsibilities
- Lead and manage a team of six DevSecOps professionals, providing guidance and promoting best security practices within the team.
- Design, implement, and maintain secure cloud infrastructure using Infrastructure as Code (IaC) tools to ensure compliance and scalability.
- Integrate security policies and controls into continuous integration and continuous deployment (CI/CD) pipelines to automate security testing and vulnerability assessments.
- Develop and enforce container security strategies to protect containerized applications and environments from threats and breaches.
- Automate security tools and processes to detect, prevent, and remediate security incidents across cloud and application environments.
- Collaborate with development, operations, and security teams to identify security gaps and devise effective mitigation strategies.
- Monitor security alerts and perform risk assessments to proactively address potential vulnerabilities and threats.
- Maintain compliance with industry standards and regulatory requirements by implementing security frameworks and conducting regular audits.
- Conduct threat modeling and penetration testing to evaluate the effectiveness of security defenses and improve overall security posture.
- Provide ongoing training and mentorship to the team on new security technologies, best practices, and emerging threats.
- Document and communicate security processes, incident reports, and compliance statuses to stakeholders and management.
- Continuously research and evaluate new security tools and techniques to enhance automated security and infrastructure protections.
Experience
2 Years
Apply By
Required Skills
- Cloud Security
- Container Security
- Infrastructure as Code
- Security Automation
- CI/CD pipeline security
- Vulnerability Assessment
- Cloud Platforms (AWS, Azure, GCP)
Nice to Have Skills
- Penetration Testing
- Threat Modeling
- Compliance Management