Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Grupo Panvel

Senior DevSecOps Engineer

Grupo Panvel

. Define and evolve the technical DevSecOps and Secure SDLC strategy .

Posted 9/15/2026full-timeEldorado do Sul • BrazilSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in defining and implementing DevSecOps strategies, security automation, and secure software development lifecycle practices. Proficient in cloud security, container security, and application security, with a strong focus on compliance with industry standards.

Highest-signal resume keywords
DevSecOps Strategy DevelopmentCI/CD Pipeline Security ImplementationInfrastructure as Code (IaC) SecurityContainer and Kubernetes SecurityApplication Security Best Practices

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
SAST ImplementationDAST ImplementationInfrastructure as Code (IaC) using TerraformCloud Security (AWS, Azure, Google Cloud)API Security Standards (OAuth 2.0, OpenID Connect)Linux and Unix-like EnvironmentsNetworking Fundamentals (TCP/IP, DNS, HTTP)Automation Using PythonGit and Modern Development WorkflowsSecurity Controls for Cloud Environments
Soft Skills
Technical LeadershipCollaborationProblem SolvingCommunication
Tools & Technologies
GitHub ActionsGitLab CIJenkinsAzure DevOpsDockerKubernetesWeb Application Firewall (WAF)API GatewayObservability ToolsSecurity Monitoring Mechanisms
Industry Keywords
OWASP Top 10CIS BenchmarksNISTISO 27001PCIZero Trust ArchitectureSecrets ManagementIAMRBACVulnerability Analysis

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudDNSDockerJenkinsKubernetesLinuxPythonSDLCTCP/IPTerraformUnixGo

About the role

Key responsibilities & impact
  • Define and evolve the technical DevSecOps and Secure SDLC strategy
  • Design and implement security controls integrated into CI/CD pipelines
  • Define standards and architectures for security automation throughout the development lifecycle
  • Implement and enhance SAST, DAST, SCA, Secret Scanning, Container Scanning, and IaC Scanning solutions
  • Develop internal security tools, integrations, and automations
  • Define quality criteria and security gates for development pipelines
  • Provide technical leadership for vulnerability identification, prioritization, and remediation initiatives
  • Define Infrastructure as Code (IaC) and infrastructure security strategies
  • Implement and enhance security controls for containers and Kubernetes environments
  • Define and implement security controls for cloud environments
  • Design, implement, and enhance Web Application Firewall (WAF) architectures and policies
  • Design and enhance API Gateway architectures, ensuring API security, availability, observability, and governance
  • Enhance practices related to IAM, RBAC, least privilege, secrets management, and access segregation
  • Implement security-related observability and monitoring mechanisms
  • Support technical investigations and incident response processes
  • Participate in threat modeling processes and architecture reviews
  • Define technical standards, guidelines, and security best practices for Engineering teams
  • Assess technical risks and propose controls proportionate to the impact and criticality of systems
  • Serve as a technical reference in DevSecOps, supporting and guiding other professionals and teams
  • Evaluate new technologies and tools related to security, automation, and cloud-native security

Requirements

What you’ll need
  • Linux and Unix-like environments
  • Git and modern development workflows
  • CI/CD pipeline architecture and implementation
  • GitHub Actions, GitLab CI, Jenkins, Azure DevOps, or equivalent technologies
  • Docker and container security
  • Kubernetes and Kubernetes environment security
  • Infrastructure as Code using Terraform, Ansible, or similar tools
  • Cloud environments such as AWS, Azure, or Google Cloud
  • Application security, OWASP Top 10, and OWASP API Security Top 10
  • WAF architecture, configuration, and operation
  • API Gateway architecture and operation
  • REST API security and authentication and authorization standards such as OAuth 2.0, OpenID Connect, and JWT
  • Implementation and operation of SAST, DAST, and SCA tools
  • Dependency, vulnerability, and CVE analysis
  • Container image and registry security
  • Infrastructure as Code security
  • IAM, RBAC, and least-privilege principles
  • Secrets and credential management
  • Observability, logging, metrics, and tracing
  • Automation and development using Python, Go, Bash, or equivalent languages
  • Strong networking fundamentals, including TCP/IP, DNS, HTTP, TLS, and network security
  • Preferred: knowledge of Zero Trust architecture
  • Preferred: knowledge of CIS Benchmarks, NIST, OWASP SAMM, ISO 27001, PCI, or similar frameworks
  • Preferred: experience with bot management, API abuse protection, and DDoS attack mitigation

Benefits

Comp & perks
  • On-site cafeteria
  • TotalPass
  • Health and dental insurance (through the cooperative)
  • Company-provided transportation
  • Exclusive discounts at Panvel