The DevSecOps Engineer will own and secure infrastructure and deployment pipelines by embedding security into CI/CD workflows. They are responsible for managing vulnerabilities, ensuring system resilience, and supporting compliance with financial data regulations.
This is a remote position.
- Location: Remote – UAE
- Requirement: A Valid UAE work permit/employment visa is mandatory.
- Employment type: Independent Contractor
We are looking for a hands-on DevSecOps Engineer to own, secure, and scale our infrastructure and deployment pipelines. You will work directly with our engineering team to embed security into our CI/CD workflows, manage vulnerabilities, and ensure our financial trading systems are resilient, compliant, and highly available.
Key Responsibilities
Pipeline Security & Automation
- Design, maintain, and harden CI/CD pipelines across our delivery lifecycle.
- Integrate automated security testing tools, including SAST, DAST, dependency scanning, and container scanning, directly into development workflows.
- Proactively suggest automation improvements to reduce manual overhead and accelerate secure software delivery.
Vulnerability & Risk Management
- Lead end-to-end vulnerability management, including triage, remediation tracking, and cross-team reporting.
- Audit existing infrastructure and deployment workflows to identify gaps, risks, or inefficiencies.
- Contribute to disaster recovery (DR), business continuity (BC), and robust change management processes to guarantee platform resilience.
Compliance & Data Protection
- Support the secure handling of sensitive and regulated financial data across all environments.
- Work closely with the Compliance team to implement security controls and collect evidence for external audits.
- Document all security architecture, pipeline logic, and automated rules for team handoff and future maintenance.
- Promote a security-aware engineering culture through modern tooling, clear documentation, and proactive knowledge sharing.
Requirements
- 5 years of demonstrable experience in a DevOps, SRE, or DevSecOps role within a production environment for financial services.
- Proven experience building, maintaining, and hardening CI/CD tooling and infrastructure as code.
- Deep understanding of relevant security frameworks and standards (e.g., ISO 27001, PCI DSS, SOC 2).
- Practical exposure to database high availability tooling and managed datastore operations.
- Strong understanding of modern data models, containerization, and cloud security architecture.
- Excellent English communication skills — you will work closely with global teams and document critical infrastructure logic.
- Relevant industry certifications (e.g., AWS Certified Security, Certified DevSecOps Professional, CISSP, or equivalent) are highly preferred.
- Background in financial technology, SaaS environments, or secure cloud-native infrastructure best practices.