Senior DevSecOps Engineer
Your journey matters – start it with us
This is us
At Avenga, we believe that human creativity empowers technology that matters. Operating globally, our 6000+ specialists provide a full spectrum of services, including business and tech advisory, enterprise solutions, CX, UX and Ul design, managed services, product development, and software development.
This is the job
We are looking for a DevSecOps Engineer to lead security-by-design practices across GitLab CI/CD. You will help enforce application security, compliance, and delivery reliability through automation, vulnerability management, and secure SDLC standards. This role includes transitioning legacy security tools to GitLab-native capabilities and working closely with InfoSec, Cloud Platform, and Product teams.
This is you
Proven experience with GitLab Ultimate security features and CI/CD administration
Hands-on with SAST, DAST, SCA, container scanning, and secret detection in automated pipelines
Practical experience with SCA tools like BlackDuck, Nexus Lifecycle, Snyk
Familiar with SonarQube for code quality
Strong scripting/automation skills in Python, Bash, YAML
Solid fundamentals in container and cloud security (Docker, Kubernetes, image scanning, registry hardening)
Experience with threat modeling, risk assessment, and remediation planning
Nice-to-have skills:
Relevant certifications: DevSecOps Professional, CKS, Security+, or equivalent
IaC security tooling experience (Terraform + OPA, Conftest, Checkov)
Knowledge of software supply chain security, including SBOM, Cosign, and SLSA
Familiarity with DORA metrics and security KPI reporting
This is your role
Drive secure-by-design guardrails across GitLab CI/CD
Implement and maintain automated security scanning: SAST, DAST, SCA, container, and secret detection
Enforce policy-as-code (branch protection, MR approvals, vulnerability gates, artifact signing)
Manage vulnerability lifecycle: periodic assessments, triage, remediation planning, and tracking to closure
Collaborate with engineering and product stakeholders to prioritize security fixes
Align controls with CIS, NIST, and (if applicable) GDPR
Enable audit-ready reporting, SBOM generation, and security KPIs in observability dashboards
Implement secure IaC using Terraform/Ansible and apply least-privilege and zero-trust patterns
Harden CI/CD infrastructure: build runners, container images, registries, and deployment targets
Champion shift-left security via training, playbooks, and standardized toolchains
Document security runbooks and contribute to SDLC harmonization standards
What awaits you at Avenga?
At Avenga, everyone matters. We provide equal opportunities in recruitment, career development, and leadership, regardless of race, ethnicity, gender identity, sexual orientation, disability, age, religion, or any other characteristic. We are committed to fostering a work environment where our diverse community of employees, candidates, and business partners actively shapes our growth. By bringing together people from different backgrounds and experiences, we build a workplace where everyone feels free to be themselves while honoring the boundaries of others.
- Department
- Engineering
- Locations
- Ukraine
- Technology
- DevOps
- Seniority
- Senior-level
Your way in starts here
APPLICATION
Send us your application, we are ready to hear your story and explore how we can grow together.
REVIEW
Our team carefully reviews every application with curiosity and care. If your profile isn’t the right fit today, we will keep it in mind for future opportunities that match your skills and ambitions.
TALENT ACQUISITION INTERVIEW
You will meet our Talent team to talk about your goals and learn more about who we are, what we offer, and how we support our people.
TECHNICAL INTERVIEW
Our tech interview is all about diving deeper into your expertise and understanding your strengths, how you solve problems, and how you think – no trick questions, just a meaningful conversation.
CUSTOMER INTERVIEW
For some roles, especially when our clients are closely involved, you might also have a conversation with them – it’s a chance for everyone to align and get to know each other better.
JOB OFFER
If we both feel it’s the right match, we will send you an offer to join us. And even if it’s not the time just yet, you’ll always hear back from us.
WELCOME!
Your new team is excited to meet you, support you, and build something great together. Let’s make your first day the start of a journey that shapes a career that matters.
Already working at Avenga?
Let’s recruit together and find your next colleague.