Devoteam Cyber Trust | DevSecOps - Platform Engineer (SonarQube / Vault) - Senior/Lead (Remote)
Devoteam Cyber Trust | Dev
Sec
Ops - Platform Engineer (Sonar
Qube / Vault) - Senior/Lead (Remote)
Full-time
Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located across EMEA, we aim to establish cybersecurity as an enabler of business success rather than a gatekeeper. We leverage an
-
- end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and
- sized companies from all sectors and industries.
Since 2009, previously known as INTEGRITY, our team based in Portugal is specialised in providing
- edge Managed Security Services that combine its expertise and proprietary technology to consistently and effectively reduce the cyber risk of our clients. The comprehensive service range includes Persistent Intrusion Testing, ISO 27001, PCI-DSS, GRC Consulting and Solutions, and Third-Party Risk Management. ISO 27001 (Information Security) and ISO 9001 (Quality) certified, PCI-QSA, and member of CREST and CIS - Centre for Internet Security, we provide services to a considerable number of clients, operating in more than 20 countries.
Responsibilities:
- Design and implement infrastructure solutions, ensuring alignment with application requirements and cybersecurity best practices, with a focus on
- premises infrastructures. - Design, implement, and maintain containerised solutions on Open
Shift, Docker and Kubernetes, including the use of Kubernetes Operators, with a focus on
- premises infrastructures. - Design, develop, and maintain infrastructure as code (Ia
C), with a focus on
- premises infrastructures, primarily using Terraform / Terragrunt and Ansible, to manage infrastructure with a strong focus on Open
Shift and Kubernetes environments. - Develop, implement, and maintain CI/CD pipelines specifically tailored for
- premises Open
Shift and Kubernetes deployments, automating build, test, and deployment processes, with a focus on Jenkins and integrating with artefact repositories such as Artifactory, JFrog Xray, and Nexus. - Collaborate with infrastructure and development teams to integrate cybersecurity practices (Sec
Ops) throughout the infrastructure and software development lifecycle, ensuring documentation and cybersecurity within the Open
Shift and Kubernetes context. - Develop and optimise Dev
Sec
Ops practices and tools on the environments, contributing to continuous improvement by leveraging testing automation frameworks, code analysis tools such as Sonar
Qube, and other cybersecurity scanning tools. - Implement and manage comprehensive logging, monitoring, and alerting solutions, such as Prometheus, Grafana, Loki, and Alertmanager to ensure system operation, performance, and proactive incident detection within the Open
Shift and Kubernetes ecosystem. - Respond quickly and effectively to incidents related to infrastructure, applications, and deployments, with a specific focus on Open
Shift and Kubernetes
- premises environments. - Document processes, including installation protocols, technical specifications (BSDS), and Gx
P relevant documentation, to ensure knowledge management and compliance. - Keep up to date with the latest technologies and trends in Dev
Sec
Ops, with a strong emphasis on
- premises Open
Shift and Kubernetes.
Minimum Requirements:
- Degree in Computer Engineering, Information Technology or a related field.
- Proven experience (+5 years) as a Dev
Sec
Ops Engineer or similar role, with significant experience in
- premises environments. - Strong understanding of Dev
Ops, Sec
Ops and Git
Ops principles and practices, with a focus on
- premises infrastructures. - Extensive experience with
- premises infrastructure management, including Linux systems and provisioning through Ia
C. - Deep experience with containerisation technologies, specifically Open
Shift, Docker, and Kubernetes, including the use of Kubernetes Operators. - Experience with Open
Shift specific tools such as Harbor, ACS (Advanced Cluster cybersecurity), Argo CD (Git
Ops), and ACM (Advanced Cluster Management). - Proven experience with Ia
C tools such as Terraform / Terragrunt and Ansible for infrastructure automation, with a focus on
- premises infrastructures. - Proven experience implementing and managing CI/CD pipelines with Jenkins / Cloud
Bees, Azure Dev
Ops for containerised applications on Open
Shift and Kubernetes. - Experience with artefact repositories such as Artifactory and XRay from JFrog, and Nexus from Sonatype.
- Experience with additional Hashi
Corp tools such as Vault, Consul, Nomad and Packer. - Experience with testing automation frameworks, code analysis and cybersecurity scanning tools such as Sonar
Qube. - Proven experience as an administrator, manager, and operator of Vault (Hashi
Corp) and Sonar
Qube, including creating pipelines to build and deploy it across multiple environments, managing its CI/CD pipelines, configurations, and security controls. - Hands-on experience with infrastructure logging, monitoring, and alerting tools relevant to Open
Shift and Kubernetes such as Prometheus, Grafana, Loki and Alertmanager. - Proficient in scripting languages such as Python and Bash.
- Familiarity with Scrum or Agile methodologies.
- Experience with the Atlassian suite of tools (Jira, Confluence, Bitbucket).
- Experience working in Gx
P regulated environments and understanding Gx
P requirements. - Excellent organisational, analytical, and
- solving skills. - Strong sense of ethics, integrity, and responsibility, particularly in regulated environments.
- Excellent communication and teamwork skills, including the ability to collaborate effectively with development and infrastructure teams.
- Fluency in Portuguese and a moderate to high level of proficiency in English.
Nice to Have:
- Relevant certifications, such as ITIL v4 Foundation or higher, are highly valued.
- Relevant Open
Shift/Kubernetes certifications, such as CKA, CKS, Red Hat Certified Specialist in Open
Shift, are highly valued. - Proficiency in information cybersecurity principles, cybersecurity best practices, and frameworks such as ISO 27001, NIST Cybersecurity Framework and CIS Top Critical cybersecurity Controls.
- Knowledge of Artificial Intelligence and Machine Learning concepts, and their application in Dev
Sec
Ops within
- premises environments, including infrastructure, CI/CD, cybersecurity, and code analysis.
What we offer:
- Professional development and monitoring talent;
- Commitment to our employees' development;
- Collaboration in a company that is constantly growing and evolving;
- Strong organisational culture: collaboration, sharing, flexibility, integrity and low ego.
Would you like to join our team? Then send your CV.
#J-18808-Ljbffr- Informações detalhadas sobre a oferta de emprego
Empresa: Integrity Localização: Lisboa
Lisboa, Lisboa, PortugalPublicado: 13. 5. 2025
Vaga de emprego atual
Seja o primeiro a candidar-se à vaga de emprego oferecida!