آگهی‌های استخدامی

استخدام Senior DevSecOps Engineer (Application & Pipeline Security)

تپسی | TAPSI
تهران، تهران

شرح موقعیت شغلی

About the Role

TAPSI is looking for a Senior DevSecOps Engineer to take end-to-end ownership of the security of our engineering platform — our DevOps infrastructure, our CI/CD pipelines, and the code that flows through them. You will embed security controls directly into how we build and ship software, so that vulnerabilities are caught early, secrets never leak, and every artifact we deploy is trustworthy by default.

This role blends defensive engineering and offensive security. On the engineering side, you will design and operate the tooling that keeps our pipelines and infrastructure secure. On the offensive side, you will regularly put our systems to the test through hands-on penetration testing of our applications, APIs, and infrastructure. You will work closely with development, platform, and infrastructure teams to make the secure path the easy path.

 

Responsibilities

CI/CD & Pipeline Security:

  • Design, implement, and maintain security controls across our CI/CD pipelines, embedding a shift-left approach so issues are detected as early in the development lifecycle as possible.
  • Select, integrate, and operate security tooling in CI/CD, including SAST, DAST, software composition analysis (SCA), secret scanning, container image scanning, and Infrastructure-as-Code (IaC) scanning.
  • Automate security gates and policies in pipelines, defining risk-based thresholds that block or flag builds without unnecessarily slowing down delivery.
  • Own vulnerability management for pipeline-detected findings: triage, prioritize, track remediation, and report on trends and SLAs.
DevOps Infrastructure & Supply Chain Security:

  • Harden the DevOps toolchain and runtime infrastructure — source control, runners, container registries, Kubernetes clusters, and orchestration platforms.
  • Implement container and Kubernetes security controls, including image hardening, admission control, and runtime policies; apply policy-as-code (e.g. OPA/Gatekeeper) where appropriate.
  • Secure Infrastructure-as-Code (e.g. Terraform, Ansible) through automated scanning, guardrails, and secure baselines.
  • Strengthen software supply chain security through artifact signing, provenance/SBOM generation, dependency governance, and controls aligned to frameworks such as SLSA.
  • Partner with platform and infrastructure teams to bake secure-by-default configurations into the environments developers use every day.
Penetration Testing & Offensive Security:

  • Plan and perform regular penetration tests against web applications, APIs, internal and external network infrastructure, containers, and cloud environments.
  • Conduct manual and automated testing that goes beyond scanners — chaining findings, validating exploitability, and eliminating false positives.
  • Perform threat modeling of new and existing systems to identify design-level weaknesses before they reach production.
  • Produce clear, actionable findings reports with reproduction steps, risk ratings, and pragmatic remediation guidance; re-test to confirm fixes.
  • Stay current with emerging attack techniques, CVEs, and the evolving threat landscape, and translate them into concrete improvements for TAPSI.
Collaboration & Security Culture:

  • Act as a security partner and advisor to engineering teams, providing secure coding guidance and reviewing designs and code for security concerns.
  • Build and run a security champions program and deliver hands-on training to raise the security capability of the wider engineering organization.
  • Document standards, runbooks, and secure baselines, and contribute to compliance and audit efforts as needed.

Requirements

  • 5+ years of experience in DevSecOps, application security, security engineering, or a closely related field, with significant hands-on CI/CD work.
  • Strong practical experience securing CI/CD pipelines —including integrating SAST, DAST, SCA, and secret-scanning tooling.
  • Solid understanding of containerization and orchestration (Docker, Kubernetes) and how to secure them in production.
  • Hands-on penetration testing experience across web applications, APIs, and networks, with strong knowledge of the OWASP Top 10, OWASP API Security Top 10, and common exploitation techniques.
  • Proficiency in at least one scripting/programming language (e.g. Python, Bash, Go) for automation and tooling.
  • Strong grasp of secure SDLC practices, vulnerability management, and risk-based prioritization.
  • Excellent communication skills — able to explain security risks and trade-offs to both engineers and non-technical stakeholders.

Nice to Have

  • Experience with cloud-native and microservices architectures, message brokers (e.g. Kafka), and data stores (e.g. PostgreSQL, MongoDB).
  • Familiarity with monitoring and error-tracking tooling (e.g. Sentry) and integrating security signals into observability.
  • Experience running bug-bounty or responsible-disclosure processes.


مهارت‌های مورد نیاز

  • CI/CD
  • Python
  • Docker

حداقل سابقه کار

  • سه تا شش سال

جنسیت

  • مهم نیست

وضعیت نظام وظیفه

  • مهم‌ نیست

نوع همکاری:

تمام وقت

تاریخ انتشار آگهی:

۱۴۰۵/۰۶/۱۰
ارسال رزومه