Manager, DevSecOps Engineering
Team: DevOps
Location: Romania, Ukraine
Commitment: Contractor Full Time
Workplace Type: remote
Key Responsibilities
Security in the SDLC
-
Own and enforce DevSecOps practices across CI/CD pipelines (SAST, DAST, SCA, and other practices)
-
Integrate automated security tooling into development workflows; reduce manual security gates
-
Partner with development teams to perform secure code reviews and threat modeling
Vulnerability & Risk Management
-
Drive vulnerability identification, triage, and remediation across infrastructure and applications
-
Manage security tooling stack
-
Produce and maintain a risk register; track remediation SLAs
Penetration Testing, crowd testing & Incident Response
-
Lead or coordinate internal/external penetration testing cycles
-
Manage crowd testing campaigns
-
Develop and maintain an incident response playbook; support incident investigations
Compliance & Governance
-
Support compliance with SOC 2, ISO 27001, GDPR, and relevant data protection frameworks
-
Define and enforce security policies, standards, and developer security training
Leadership & Collaboration
-
Act as the primary security SME for the engineering organization
-
Mentor developers on secure coding practices; build a security-first engineering culture
-
Interface with external auditors, clients, and the executive team on security posture
Requirements
-
5+ years of experience in DevSecOps, application security, or security engineering
-
Demonstrated experience managing security in software development environments (not just ops/infrastructure)
-
Strong development background, proficiency in at least 1 language (eg: Python, Go, Java, C#)
-
Hands on experience with CI/CD security tooling (SAST/DAST/SCA integration, secrets management)
-
Experience with cloud security (AWS, Azure, or GCP) and container security (Docker, Kubernetes)
-
Familiarity with SOC 2 or ISO 27001 compliance frameworks
-
Excellent English communication skills (written and verbal)
Preferred/Nice to Have
-
Penetration testing experience or relevant certification (OSCP, CEH, GPEN)
-
Security certifications (CISSP, CSSLP, AWS Security Specialty, or similar)
-
Experience at a B2B SaaS or cybersecurity product company
-
Familiarity with insider threat, DLP, or endpoint security product domains
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
