The Senior DevSecOps Engineer will partner with platform teams to embed security into cloud infrastructure, CI/CD pipelines, and Kubernetes-based application platforms. They will design secure-by-default patterns, automate security checks, and mentor engineering teams on DevSecOps best practices.
Ciklum is looking for a Senior DevOps Engineer to join our team in Argentina or Brazil.
We are a custom product engineering company that supports both multinational organizations and scaling startups to solve their most complex business challenges. With a global team of over 4,000 highly skilled developers, consultants, analysts and product owners, we engineer technology that redefines industries and shapes the way people live.
About the role:
We're looking for a talented Senior DevSecOps Engineer to partner with our engineering and platform teams, with a strong focus on embedding security into the infrastructure and pipelines that get code from source to production — and keeping it safe once it's there. We need someone who understands software delivery, thinks in automation first, and enjoys working with developers to make secure defaults the path of least resistance rather than a checkpoint at the end.
Responsibilities:
- Partner closely with the DevOps and platform engineering teams to embed security into cloud infrastructure, CI/CD pipelines, Kubernetes-based application platforms, and developer self-service workflows
- Design and implement secure-by-default patterns for infrastructure as code, secrets management, identity and access controls, network security, and standardized application deployments across cloud environments
- Take ownership of security responsibilities transitioning into the DevOps organization by independently assessing the current-state landscape, identifying undocumented processes and operational gaps, and helping define a scalable future-state operating model
- Build documentation, runbooks, and automation for manual security and platform operations, partnering with team leadership to improve repeatability, reduce operational toil, and strengthen day-to-day security execution
- Improve the security posture of multi-cloud Kubernetes platforms and supporting infrastructure, including cluster configuration, ingress and traffic management, artifact integrity, and workload protection
- Build and operationalize automated security checks across source control, container build and release flows, infrastructure changes, and deployment pipelines so teams can ship safely without creating unnecessary friction
- Collaborate with software engineers and platform teams to identify, prioritize, and remediate vulnerabilities and misconfigurations across cloud resources, Kubernetes workloads, CI/CD systems, and shared developer tooling
- Support secure change management and incident response practices for infrastructure and release systems, including investigation, rollback readiness, operational runbooks, and on-call collaboration
- Partner with observability and security teams to improve actionable detection, alerting, and response workflows across monitoring and incident-management platforms
- Work with compliance, security, and infrastructure stakeholders to translate regulated- environment requirements into practical engineering controls and durable platform standards. Help define paved-road security standards for developer-facing platform capabilities, including secrets, deployment patterns, cluster access, runtime protections, and infrastructure ownership boundaries
- Mentor engineers and promote DevSecOps best practices through code reviews, design discussions, documentation, and hands-on technical leadership
Requirements:
- 5+ years of hands-on experience in DevOps, DevSecOps, Platform Engineering, Site Reliability Engineering, Security Engineering, or a closely related role
- Strong experience securing cloud-native infrastructure and delivery systems in at least one major public cloud, with practical exposure to multi-cloud environments
- A demonstrable habit of automating things that used to be manual
- Deep hands-on experience with Kubernetes and containerized workloads, including cluster security, workload isolation, ingress patterns, secrets management, and deployment controls
- Strong experience with infrastructure as code, reusable modules, and safe change management for shared platform resources
- Solid understanding of CI/CD and release engineering, including build pipelines, deployment orchestration, approval gates, rollback patterns, and production change controls
- Experience implementing automated security controls such as image scanning, secrets handling, policy enforcement, vulnerability management, and cloud or infrastructure configuration review
- Experience supporting regulated or audited environments and translating compliance obligations into practical engineering controls
- Working knowledge of security and compliance frameworks relevant to healthcare and consumer platforms, such as HIPAA, SOC 2, PCI DSS, HITRUST, and SOX
- Strong scripting or programming ability for automation, tooling, and operational problem solving
- Strong communication skills and the ability to balance security, reliability, developer experience, and delivery speed in a pragmatic way
Desirable:
- Experience with AWS and GCP cloud environments
- Experience with Kubernetes platforms such as EKS and GKE
- Experience with Terraform and Terraform Cloud for infrastructure provisioning, state management, and platform automation
- Experience with GitOps and deployment tooling such as ArgoCD, Harness, and Codefresh
- Experience with observability and incident-management tooling such as Groundcover, Datadog, and PagerDuty
- Experience with edge/network platforms such as Fastly and with modern ingress or traffic-management patterns
- Experience securing container and runtime environments using tools such as CrowdStrike and private container registries such as AWS ECR
- Familiarity with operational secrets patterns using tools such as AWS Secrets Manager and LastPass in CI/CD and platform environments
What`s in it for you?
- Care: your mental and physical health is our priority. We ensure comprehensive company-paid medical insurance and mental health programs, 5 undocumented sick leave days per year
- Tailored education path: boost your skills and knowledge with our regular internal events (meetups, conferences, workshops), Udemy license, language courses and company-paid certifications
- Growth environment: share your experience and level up your expertise with a community of skilled professionals, locally and globally
- Long-term employment with 20 working-days paid vacation and local bank holidays
- Flexibility: 100% remote work mode
- Opportunities: we value our specialists and always find the best options for them. Our Internal Mobility Program helps change a project if needed to help you grow, excel professionally and fulfill your potential
- Global impact: work on large-scale projects that redefine industries with international and fast-growing clients
- Welcoming environment: feel empowered with a friendly team, open-door policy, informal atmosphere within the company and regular team-building events
About us:
At Ciklum, we are always exploring innovations, empowering each other to achieve more, and engineering solutions that matter. With us, you’ll work with cutting-edge technologies, contribute to impactful projects, and be part of a One Team culture that values collaboration and progress.
As we expand into Latin America, every Ciklumer is helping to shape our story. Collaborate with seasoned experts and make a global impact backed by two decades of industry leadership.
Explore, empower, engineer with Ciklum!
Interested already? We would love to get to know you! Submit your application. We can’t wait to see you at Ciklum.
#LI-IK1