Uberall
Posted 1mo ago

DevSecOps Engineer

Uberall
Brazil
RemoteContract
Responsibilities
  • integrating security
  • maintaining infrastructure
  • monitoring incidents
Requirements
  • 5+ years DevSecOps/DevOps experience
  • Strong AWS and Kubernetes skills
  • Terraform
  • CI/CD and security-as-code experience
  • Familiarity with compliance (SOC2/HIPAA/GDPR)
Technical tools mentioned
SASTDASTTerraformAWSIAMEC2RDSOpenSearchEKSKubernetesHelmKustomizeFluxCDGitOpsCI/CDGitLab CIGitLabBashIstioDrataVanta

Job description

About the Role

We are looking for a proactive and skilled DevSecOps Engineer with 5+ years of hands-on experience to join our growing engineering team. You'll be working closely with a small team of five DevOps engineers to build, maintain, and scale secure cloud infrastructure, CI/CD pipelines, and observability stacks. We value a security-first engineering mindset where you will integrate security-as-code practices throughout the entire development lifecycle. If your background is in DevOps, that is a great fit, provided you have always focused on and enjoyed the security aspects of your work, and are now ready to fully commit to a dedicated security role.

We value collaboration, strong communication, and a growth mindset: you'll be expected to contribute ideas, give and receive feedback, and work independently to ensure our platform is as secure as it is performant.

 
 

Your Responsibilities

  • Integrate automated security scanning (SAST, DAST, container scanning) into CI/CD pipelines to ensure early detection of vulnerabilities.

  • Maintain and audit cloud infrastructure compliance (e.g., SOC2, HIPAA, GDPR) through automated policies.

  • Implement security best practices within Terraform/IaC to ensure "security-as-code" consistency.

  • Monitor and respond to cloud security incidents, collaborating closely with security and compliance teams.

  • Design, implement, and maintain cloud infrastructure primarily on AWS, with strong focus on EC2, RDS, OpenSearch, and EKS.

  • Help to manage the Kubernetes clusters running our microservices (we have over a hundred in production) as well as the legacy EC2-based platform.

  • Hardening Kubernetes clusters by implementing network policies, RBAC, and secure pod security standards to protect our microservices environment.

  • Collaborate on maintaining our Infrastructure as Code (IaC) maintenance using Terraform.

  • Identify opportunities for automation and optimization in deployment and infrastructure management.

  • Document processes, infrastructure, and decisions clearly and effectively.

  • Partner closely with our Information Security Lead on compliance audits, control evidence, and security roadmap prioritization, while reporting into the Head of DevOps for day-to-day work.

 
 

Your Profile

Experience with our stack:

  • Proven experience in a DevSecOps or security-focused engineering role.

  • Familiarity with modern security tooling (vulnerability management, secrets management etc.).

  • Strong understanding of "shift-left" security principles.

  • 3+ years of experience in a DevOps or similar role.

  • Deep experience with AWS services, especially IAM, EC2, RDS, EKS, and OpenSearch.

  • Solid understanding and hands-on experience with Kubernetes and related tooling (we use Helm, Kustomize and FluxCD but we value knowing and adhering to the GitOps practices more than the specific tools).

  • Strong proficiency in Terraform for infrastructure automation.

  • Experience in CI/CD tools.

  • Bash or other shell scripting knowledge

Soft Skills & Mindset:

  • Highly proactive and self-motivated; able to identify and address issues before they escalate.

  • Strong communication skills, both verbal and written. We are a remote and distributed team so we focus on effective and async communication.

  • Comfortable working collaboratively within a distributed team but also capable of driving tasks independently.

  • Open to giving and receiving feedback, and eager to grow with the team.

  • Analytical mindset with attention to detail and commitment to high-quality work.

 
 

Nice-to-Have

  • Experience with GitLab CI and GitLab in general.

  • Familiarity with the JVM.

  • Experience in cost optimization on AWS.

  • Having worked with Istio or other service meshes.

  • Exposure to GRC/compliance automation tooling (Drata, Vanta, or similar)

  • Experience with Vulnerability/dependency scanning tools

About Uberall

Multi-location marketing platform managing local online presence and reputation.

Year founded
2013
Employees
467
Organization type
Private
Latest investment
Raised $115.00M Series C (2021) — led by Bregal Milestone, Level Equity
Subsidiaries
Headquarters
DE

Similar jobs

DevSecOps Engineer roles
2w
Save
Mark Applied
Hide
Senior DevSecOps Engineer
Brazil
RemoteFull Time
Encora
EncoraNSE: COFORGE: Provides global digital engineering and software product development services.
Experience in DevOps/Infrastructure engineering, Jenkins, Terraform, Ansible, Groovy, Kubernetes/OpenShift, Rust or Python, security scanning and vulnerability management in CI/CD pipelines.
Jenkins, Groovy, Python, Rust, Terraform, Ansible, Kubernetes, OpenShift, CMake, SAST, DAST, Software Composition Analysis (SCA)
6mo
Save
Mark Applied
Hide
Senior DevSecOps Engineer - São Paulo Based
Belo Horizonte, State of Minas Gerais, Brazil
HybridFull Time
1GLOBAL
1GLOBAL: Provides international mobile connectivity and eSIM services to enterprises.
3+ YOE3+ years cloud security/DevSecOps, AWS security, Kubernetes security, IaC (Terraform), scripting (Python/Go/Bash), vulnerabilities, network security, WAFs, traffic analysis.
AWS, Kubernetes, Terraform, Python, Go, Bash, Git, WAF, Suricata, tcpdump, Wireshark