تپسی | TAPSI

تاسیس در ۱۳۹۵ کامپیوتر، فناوری اطلاعات و اینترنت بیش از ۱۰۰۰ نفر tapsi.ir

استخدام Senior DevSecOps Engineer (Application & Pipeline Security)

  • دسته‌بندی شغلی

    وب،‌ برنامه‌نویسی و نرم‌افزار
  • موقعیت مکانی

    تهران ، تهران
  • نوع همکاری

    تمام وقت
  • حداقل سابقه کار

    سه تا شش سال
  • حقوق

    توافقی

شرح موقعیت شغلی

About the Role

TAPSI is looking for a Senior DevSecOps Engineer to take end-to-end ownership of the security of our engineering platform — our DevOps infrastructure, our CI/CD pipelines, and the code that flows through them. You will embed security controls directly into how we build and ship software, so that vulnerabilities are caught early, secrets never leak, and every artifact we deploy is trustworthy by default.

This role blends defensive engineering and offensive security. On the engineering side, you will design and operate the tooling that keeps our pipelines and infrastructure secure. On the offensive side, you will regularly put our systems to the test through hands-on penetration testing of our applications, APIs, and infrastructure. You will work closely with development, platform, and infrastructure teams to make the secure path the easy path.

 

Responsibilities

CI/CD & Pipeline Security:

  • Design, implement, and maintain security controls across our CI/CD pipelines, embedding a shift-left approach so issues are detected as early in the development lifecycle as possible.
  • Select, integrate, and operate security tooling in CI/CD, including SAST, DAST, software composition analysis (SCA), secret scanning, container image scanning, and Infrastructure-as-Code (IaC) scanning.
  • Automate security gates and policies in pipelines, defining risk-based thresholds that block or flag builds without unnecessarily slowing down delivery.
  • Own vulnerability management for pipeline-detected findings: triage, prioritize, track remediation, and report on trends and SLAs.
DevOps Infrastructure & Supply Chain Security:

  • Harden the DevOps toolchain and runtime infrastructure — source control, runners, container registries, Kubernetes clusters, and orchestration platforms.
  • Implement container and Kubernetes security controls, including image hardening, admission control, and runtime policies; apply policy-as-code (e.g. OPA/Gatekeeper) where appropriate.
  • Secure Infrastructure-as-Code (e.g. Terraform, Ansible) through automated scanning, guardrails, and secure baselines.
  • Strengthen software supply chain security through artifact signing, provenance/SBOM generation, dependency governance, and controls aligned to frameworks such as SLSA.
  • Partner with platform and infrastructure teams to bake secure-by-default configurations into the environments developers use every day.
Penetration Testing & Offensive Security:

  • Plan and perform regular penetration tests against web applications, APIs, internal and external network infrastructure, containers, and cloud environments.
  • Conduct manual and automated testing that goes beyond scanners — chaining findings, validating exploitability, and eliminating false positives.
  • Perform threat modeling of new and existing systems to identify design-level weaknesses before they reach production.
  • Produce clear, actionable findings reports with reproduction steps, risk ratings, and pragmatic remediation guidance; re-test to confirm fixes.
  • Stay current with emerging attack techniques, CVEs, and the evolving threat landscape, and translate them into concrete improvements for TAPSI.
Collaboration & Security Culture:

  • Act as a security partner and advisor to engineering teams, providing secure coding guidance and reviewing designs and code for security concerns.
  • Build and run a security champions program and deliver hands-on training to raise the security capability of the wider engineering organization.
  • Document standards, runbooks, and secure baselines, and contribute to compliance and audit efforts as needed.

Requirements

  • 5+ years of experience in DevSecOps, application security, security engineering, or a closely related field, with significant hands-on CI/CD work.
  • Strong practical experience securing CI/CD pipelines —including integrating SAST, DAST, SCA, and secret-scanning tooling.
  • Solid understanding of containerization and orchestration (Docker, Kubernetes) and how to secure them in production.
  • Hands-on penetration testing experience across web applications, APIs, and networks, with strong knowledge of the OWASP Top 10, OWASP API Security Top 10, and common exploitation techniques.
  • Proficiency in at least one scripting/programming language (e.g. Python, Bash, Go) for automation and tooling.
  • Strong grasp of secure SDLC practices, vulnerability management, and risk-based prioritization.
  • Excellent communication skills — able to explain security risks and trade-offs to both engineers and non-technical stakeholders.

Nice to Have

  • Experience with cloud-native and microservices architectures, message brokers (e.g. Kafka), and data stores (e.g. PostgreSQL, MongoDB).
  • Familiarity with monitoring and error-tracking tooling (e.g. Sentry) and integrating security signals into observability.
  • Experience running bug-bounty or responsible-disclosure processes.


معرفی شرکت

تپسی در خرداد ۱۳۹۵ با یک تیم ۱۰ نفره از متخصصان ایرانی در حوزه برنامه‌نویسی، طراحی و توسعه محصول فعالیتش رو آغاز کرد و اولین نسخه اپلیکیشن رو به کاربران ارائه داد. امروز تپسی به‌عنوان یک سوپر اپلیکیشن، علاوه بر خدمات سفرهای آنلاین درون و برون شهری و ارسال فوری مرسولات، خدمات متنوعی از جمله تپسی‌فود، تپسی‌شاپ، تپسی گاراژ و... رو در دل خودش جا داده و همچنان در حال گسترش و توسعه فعالیت‌هاشه.
تپسی با ۲۰ میلیون کاربر در بیش از ۲۸ شهر ایران و تیمی متشکل از بیش از ۱۰۰۰ نفر در سراسر کشور، هر روز در حال رشد و پیشرفته. اعضای تیم ما با تخصص‌های منحصربه‌فردشون، رضایت کاربران و ایجاد تغییرات مثبت در زندگی افراد جامعه رو به‌عنوان منبع انگیزه و انرژی برای مواجهه با کارهای چالش‌برانگیز روزانه می‌دونن. ما همیشه به دنبال فرصت‌های جدید برای بهبود و پیشرفت هستیم و تمام تلاشمون اینه که از مسیر یادگیری خارج نشیم. تپسی همون جاییه که می‌تونی از خودت سبقت بگیری!
  • مهارت‌های مورد نیاز

    CI/CD Python Docker
  • جنسیت

    مهم نیست
  • وضعیت نظام وظیفه

    مهم‌ نیست
  • حداقل مدرک تحصیلی

    کارشناسی

مشاغل مشابه

چه موردی را می‌خواهید گزارش کنید؟

از اینجا شروع کنید

در شغل بهتری استخدام شوید! رایگان!

  • جستجو و ارسال رزومه به آگهی‌های استخدام بیش از ۱۰۰,۰۰۰ شرکت ایرانی
  • رزومه‌ساز رایگان
  • دریافت فرصت‌های شغلی جدید مرتبط از طریق ایمیل (Job Alert)
  • شناخت محیط کار و فرهنگ سازمانی شرکت‌های در حال استخدام
image/svg+xml