Devsecops Team Lead

17 ore fa

Bolzano, Trentino-Alto Adige/South Tyrol, Italia Deel Tempo pieno
Overview

As DevSecOps Team Lead, you bridge Security, Operations and Engineering to scale a Security-as-Code ecosystem. You’ll lead a team of engineers, drive multi-quarter security roadmaps, and embed security into product discovery with automated guardrails. You’ll design secure cloud architectures and manage third-party tools, enabling faster, safer software delivery at scale. This is a chance to shape security practices in a fast-growing global SaaS platform.

Retribuzione / Benefits
  • Stock grant opportunities
  • Optional flexible working office membership with IWG
  • Additional perks and benefits based on country
  • Competitive total rewards programs
Responsabilità
  • Lead, mentor and coach a team of DevSecOps engineers; conduct performance reviews and foster high performance
  • Own the DevSecOps roadmap, aligning security with business and engineering goals
  • Serve as primary security liaison for Engineering and Product during Product Discovery; ensure security requirements are baked in
  • Lead policy-as-code initiatives (OPA, Kyverno) for automated compliance across environments
  • Oversee secure cloud architectures (AWS/Azure/GCP) and Kubernetes with Zero Trust and identity-driven access
  • Evaluate and manage third-party security vendors/tools (e.g., Snyk, Wiz, Cloudflare) for ROI and fit
  • Define and monitor security KPIs (MTTR, vulnerability burn-down, false positives)
  • Act as technical escalation point for high-severity incidents and drive blameless post-mortems
Requisiti fondamentali
  • 6+ years in Security, DevOps, or Infrastructure roles
  • 2+ years in a leadership capacity (Team Lead, Tech Lead, or Engineering Manager)
  • Proven track record of scaling security in a cloud-native, high-growth environment
  • Terraform/OpenTofu, Ansible, and CI/CD platforms (GitHub Actions, GitLab CI) proficiency
  • Deep Kubernetes security knowledge (RBAC, Network Policies, Admission Controllers) and cloud security services
  • Experience implementing and tuning SAST, DAST, SCA, and Secret Management (HashiCorp Vault) at scale
  • Programming skills in Python, Go, or TypeScript for internal tooling
  • Pragmatism: balance security with speed of business
  • Strong communication: translate risk to executive stakeholders
  • Cross-functional collaboration and stakeholder management
  • Terraform/OpenTofu
  • Ansible
  • GitHub Actions