
HiQ · Stockholm
Du som vill väva in säkerhet i moderna utvecklingsflöden och se effekten hela vägen ut i produktion kommer att trivas här. Som DevSecOps Engineer på HiQ i Stock...
Du som vill väva in säkerhet i moderna utvecklingsflöden och se effekten hela vägen ut i produktion kommer att trivas här. Som
DevSecOps Engineer på HiQ i Stockholm får du kombinera webbutveckling, moln och säkerhet i uppdrag där din kompetens märks varje
dag.
Som DevSecOps Engineer hjälper du våra kunder att bygga säkra, robusta och moderna webblösningar från arkitektur till produktion.
Du arbetar med backendutveckling, CI/CD-flöden, molnplattformar, containers och ser till att säkerhet finns med i varje steg. Du
identifierar och analyserar säkerhetsrisker i webbapplikationer, genomför säkerhetsgranskningar, arkitekturanalyser och
hotmodellering och är ett naturligt bollplank för både utvecklare och beslutsfattare. I många uppdrag är du drivande i att
etablera eller stärka DevSecOps-arbetssätt så att snabba releaser och hög säkerhet går hand i hand.
säkerhet
svenska i tal och skrift, goda kunskaper i engelska samt svenskt medborgarskap
Meriterande är konsulterfarenhet och certifieringar som CSSLP, CKS, AWS eller Azure Security, CompTIA Security+ eller andra
relevanta IT säkerhetscertifieringar.
Hos oss möts säkerhet, utveckling och moderna arbetssätt i vardagen. Du arbetar i uppdrag där din kompetens gör tydlig skillnad,
tillsammans med kollegor inom utveckling, moln, arkitektur, test och säkerhet som gärna delar kodexempel, verktygstips och
erfarenheter. Vi uppmuntrar initiativ, oavsett om det handlar om att testa ett nytt verktyg i pipelinen, starta ett internt
säkerhetsnätverk eller hålla en kunskapsdelning, och du får goda möjligheter att växa genom certifieringar, kurser, konferenser
och interna forum.
Sedan 1995 har HiQ varit konsultbolaget som förenklar världen för både kunder och slutanvändare med hjälp av teknik, design och
kommunikation. Vi har alltid haft två tydliga fokus: att ha roligt på jobbet och att leverera lösningar som överträffar
förväntningarna – det är det som driver oss framåt. Som HiQare är vi stolta över en kultur som präglas av resultat, ansvar,
enkelhet och glädje. Vi tror på att arbeta tillsammans för att nå gemensamma mål och vi lägger stor vikt vid att hjälpa varandra
att växa och utvecklas. Hos oss får du inte bara möjlighet att bygga din egen kompetens, utan också chansen att lära, leda och
inspirera dina kollegor.
Just nu tankar vi energi på semestern och är därför lite långsammare på bollen än vanligt. Vi är tillbaka i början av augusti och
hör av oss då – tills dess hoppas vi att du njuter av en riktigt skön sommar! 🌞
Why Valtech? We’re the experience innovation company - a trusted partner to the world’s most recognized brands. To our people we offer growth opportunities, a values-driven culture, international careers and the chance to shape the future of experience. THE OPPORTUNITY At Valtech, you’ll find an environment designed for continuous learning, meaningful impact, and professional growth. Whether you're pioneering new digital solutions, challenging conventional thinking or building the next generation of customer experiences, your work will help transform industries. We are proud of: * The work we do and the innovation we drive * Our values of share, care and dare * A workplace culture that fosters creativity, diversity and autonomy * Our borderless, global framework, which enables seamless collaboration THE ROLE As a DevSecOps Engineer, you will be the link between development, operations, and security. You will work with delivery teams to embed security controls and best practices into pipelines, automate compliance, and ensure our platforms are reliable, resilient, and secure. You will participate in architecture discussions, help detect and remediate vulnerabilities, and continuously improve our DevSecOps practices. You will work in a multidisciplinary environment with engineers across the globe, ensuring that security does not block innovation but rather accelerates it. .You are someone with 5+ years of experience in Security Engineering, or DevSecOps, preferably in large-scale, customer-facing platforms. You have deep expertise in automation, cloud-native security, and CI/CD. You combine technical leadership with strong communication skills, and you are comfortable working in global and multicultural teams. You will thrive in this role if you are: * A curious problem solver who challenges the status quo * A collaborator who values teamwork and knowledge-sharing * Excited by the intersection of technology, creativity and data * Experienced in Agile methodologies and consulting (a plus) Role responsibilities * Define and implement enterprise-wide DevSecOps standards, patterns, and guardrails. * Design and build security automation mechanisms such as secure CI/CD pipelines with integrated SAST, DAST, SCA, IaC scanning, and container security. * Design and Implement cloud-native security tooling and platforms. * Lead security reviews, audits and threat modeling for high-impact platforms and projects. * Guide teams and promote security awareness on secure coding, vulnerability remediation, and cloud security best practices, acting as a Security Subject Matter Expert. * Automate compliance and governance requirements at scale. * Participate in and lead security incident lifecycle, including RCA, remediation, postmortem analysis, and resilience improvements. * Mentor and coach DevOps/DevSecOps engineers across teams. * Advocate for and implement practices to reduce toil and scale security automation. * Define and/or conduct regular vulnerability assessments and manage remediation efforts * Ensure our clients' systems and applications meet regulatory and organizational security standards (e.g. NIST, ISO, SOC 2, PCI DSS, GDPR, etc.) * Help define and implement monitoring solutions and participate in incident response and remediation as needed * Work closely with development, ops, and security teams to ensure secure delivery of software MUST HAVE QUALIFICATIONS To be considered for this role, you must meet the following essential qualifications: * You have led DevSecOps initiatives in enterprise or high-traffic production environments. * You have strong experience with cloud security (Mostly Azure). * You are proficient in CI/CD tooling. * You have advanced knowledge of container security and orchestration (Docker, Kubernetes, AKS). * You have hands-on experience with security scanning tools (Snyk, SonarQube, Trivy, Aqua, Prisma, Checkov, etc.). * You have implemented monitoring and observability solutions with a security lens (New Relic, Prometheus, Grafana, ELK). * You are fluent in at least one scripting/programming language (Python, Go, Bash, etc.) for automation. * You are experienced in IAM, secrets management, and zero-trust principles. * You are a natural mentor, able to upskill and guide other engineers. NICE TO HAVE QUALIFICATIONS * Strong communication and presentation skills * Accountability, collaboration, and time-management skills * Strong desire to learn more about business every day If you do not meet all the listed qualifications or have gaps in your experience, we still encourage you to apply. At Valtech, we recognize that talent comes in many forms, and we value diverse perspectives and a willingness to learn. COMMITMENT TO REACHING ALL KINDS OF PEOPLE We design experiences that work for all kinds of people - and that starts with our own teams. At Valtech, we’re intentional about building an inclusive culture where everyone feels supported to grow, thrive and achieve their goals. No matter your background, you belong here. Explore our Diversity & Inclusion site to see how we’re creating a more equitable Valtech for all. THE BENEFITS This is a Full time position based in Buenos Aires Beyond a competitive compensation package, we offer: * Flexibility, with remote and hybrid work options (country-dependent) * Career advancement, with international mobility and professional development programs * Learning and development, with access to cutting-edge tools, training and industry experts Our benefits are tailored to each location. Your Talent Partner will provide full details during the hiring process. YOUR APPLICATION PROCESS Once you apply, our Talent Acquisition team will review your application. If your skills and experience align with the role, we’ll reach out for next steps. Your CV should cover key information on relevant experiences and expertise. We do not require information such as age, gender, marital status, or a headshot in your application. We review all candidates based on skills, experience, and potential. ⚠️ Beware of recruitment fraud: Only engage with official Valtech email addresses. We are committed to inclusion and accessibility. If you need reasonable accommodations during the interview process, please either indicate it in your application or let your Talent Partner know. ABOUT VALTECH Valtech is the experience innovation company that exists to unlock a better way to experience the world. By blending crafts, categories, and cultures, we help brands unlock new value in an increasingly digital world. At the intersection of data, AI, creativity, and technology, we drive transformation for leading organizations, including L’Oréal, Mars, Audi, P&G, Volkswagen Dolby, and more. At Valtech, we don’t just talk about transformation. We make it happen. Our people are the heart of our success, and we foster a workplace where everyone has the support to thrive, grow and innovate. Are you ready to create what’s next? Join us.
Sofia Stars is a fast-growing global service provider that guides high-growth businesses to success. Our range of tailored solutions includes R&D, Customer Support, Sales, KYC, Risk, and Anti-Fraud services. We make every connection shine with fresh tech and cultural understanding. We invite a DevSecOps Engineer to join our team. Responsibilities: ✔️ Develop direction, create a roadmap and improve the DevSecOps culture in the company. ✔️ Help DevOps with secure Istio and ServiceMesh setup, Kubernetes (EKS) security setup. ✔️ Interaction with DevOps, transfer of services for their support and training in security principles. ✔️ Implementation of OPA and virtualisation configuration security analysers. ✔️ Setting up CI/CD security and improving the security of solutions that use DevOps - Terraform, Ansible, etc. ✔️ Implementing Security Scanners in Pipelines. ✔️ Automation of security processes. Requirements: ✔️ Knowledge of the basic principles of DevOps approaches (CI /CD). ✔️ Experience with Kubernetes or other orchestration tools. ✔️ Experience with Ansible/Terraform/Chef configuration management systems, etc. ✔️ Experience in web server and database administration. ✔️ Knowledge of the TCP/IP protocol stack and understanding of the OSI model. ✔️ Understanding the principles of microservice application architecture. ✔️ Experience with version control systems. ✔️ Cloud experience (AWS, GCP) Security. ✔️ Experience in infrastructure analysis for information security risks and their elimination / mitigation. ✔️ Experience in automating management processes and access control. ✔️ Experience in implementing Vault management systems and privileged user control systems. ✔️ Experience with Security scanners and implementation of their pipelines. ✔️ Understanding SSDLC (OSAMMv2) principles. Our Excellent Benefits: * Up to 25 vacation days * 6 undocumented sick leaves * Medical insurance and dental coverage * Sport card 70% coverage (Multisport and/or CoolFit) * Food vouchers (102 EUR) * Appreciation gifts (birthday, wedding, newborn, etc.) * Office massages * Breakfast, lunch & snacks in the office * Education budget * Monthly team events * Great office location Working Model: * This is an office-based position in Sofia, Bulgaria. Grow fast, shine globally! By submitting your application, you agree to our Privacy Policy.
ThinkMarkets is a global financial technology company, specializing in providing multi-asset trading solutions to thousands of clients around the world. With our flagship ThinkTrader platform, we make it available for our clients to trade the world 24-hours a day. Our mission is to bridge the gap between traders, investors, and platforms by allowing access to global markets and thousands of products thus providing our clients the ability to trade the world in the palm of their hand. We use the latest technologies to give traders seamless access to our proprietary trading platforms. We are looking for a hands-on DevSecOps Engineer to own, secure, and scale our infrastructure and deployment pipelines. You will work directly with our engineering team to embed security into our CI/CD workflows, manage vulnerabilities, and ensure our financial trading systems are resilient, compliant, and highly available. Key Responsibilities Pipeline Security & Automation * Design, maintain, and harden CI/CD pipelines across our delivery lifecycle. * Integrate automated security testing tools, including SAST, DAST, dependency scanning, and container scanning, directly into development workflows. * Proactively suggest automation improvements to reduce manual overhead and accelerate secure software delivery. Vulnerability & Risk Management * Lead end-to-end vulnerability management, including triage, remediation tracking, and cross-team reporting. * Audit existing infrastructure and deployment workflows to identify gaps, risks, or inefficiencies. * Contribute to disaster recovery (DR), business continuity (BC), and robust change management processes to guarantee platform resilience. Compliance & Data Protection * Support the secure handling of sensitive and regulated financial data across all environments. * Work closely with the Compliance team to implement security controls and collect evidence for external audits. * Document all security architecture, pipeline logic, and automated rules for team handoff and future maintenance. * Promote a security-aware engineering culture through modern tooling, clear documentation, and proactive knowledge sharing. Requirements * 3+ years of demonstrable experience in a DevOps, SRE, or DevSecOps role within a production environment for financial services. * Proven experience building, maintaining, and hardening CI/CD tooling and infrastructure as code. * Deep understanding of relevant security frameworks and standards (e.g., ISO 27001, PCI DSS, SOC 2). * Practical exposure to database high availability tooling and managed datastore operations. * Strong understanding of modern data models, containerization, and cloud security architecture. * Excellent English communication skills — you will work closely with global teams and document critical infrastructure logic. * Relevant industry certifications (e.g., AWS Certified Security, Certified DevSecOps Professional, CISSP, or equivalent) are highly preferred. * Background in financial technology, SaaS environments, or secure cloud-native infrastructure best practices.