Flag job

Report

DevSecOps Engineer

Min Experience

3 years

Location

Porto, Portugal, remote

JobType

Permanent

About the job

Info This job is sourced from a job board

About the role

ABOUT US 🚀Hostelworld Group, the global hostel-focussed online booking platform, inspires adventurous minds to meet the world and come back with life-changing stories to tell. Our customers are not your average tourists, they crave cultural connection and unique experiences that we make possible by providing an unbeatable selection of hostels in unmissable locations – all in the palm of their hand. The DevSecOps Engineer will help ensure that security is not an afterthought, but a critical element integrated into the SDLC and cloud infrastructure. By supporting teams removing technical debt, automating security processes, and managing compliance, this role directly contributes to reducing the risk of security breaches, ensuring regulatory compliance, and safeguarding the company's data and reputation. Continuous improvement initiatives will enhance the company's security posture, making the development process more efficient and secure. Role responsibilities include: Security Integration: Embed security throughout the software development lifecycle (SDLC) by working closely with development and operations teams. Technical Debt Removal: Identify, prioritize, and work with teams to remove technical debt, especially in relation to security vulnerabilities, legacy systems, and non-optimized configurations. Cloud Security (GCP): Manage and secure the GCP environment by implementing best practices in identity and access management (IAM), networking, and data protection. Infrastructure as Code (IaC): Develop and maintain secure IaC using tools like Terraform or Google Cloud Deployment Manager. Ensure that IaC meets security standards from the outset. Automation & CI/CD Pipelines: Collaborate with development teams to integrate security tools into CI/CD pipelines, automating tasks such as vulnerability scanning, compliance checks, and security testing. Monitoring & Incident Response: Set up and manage security monitoring tools, ensuring visibility into GCP resources and workloads. Develop and implement incident response protocols for handling security breaches. Compliance and Governance: Ensure compliance with industry regulations, data privacy standards, and internal policies (e.g., PCI-DSS, NIS2). Work with stakeholders to implement and maintain governance frameworks. Vulnerability Management: Conduct regular security assessments, including vulnerability scanning, penetration testing, and code reviews, to identify risks and ensure timely remediation. Collaboration & Education: Work closely with engineering, product, and operations teams to improve security posture while promoting a collaborative, security-first culture. Continuous Improvement: Stay updated on security trends, tools, and best practices to continually improve security processes and educate internal teams.

About the company

Hostelworld Group, the global hostel-focussed online booking platform, inspires adventurous minds to meet the world and come back with life-changing stories to tell. Our customers are not your average tourists, they crave cultural connection and unique experiences that we make possible by providing an unbeatable selection of hostels in unmissable locations – all in the palm of their hand.

Skills

Scripting
Terraform
CI/CD
Python
Google Cloud Platform
Kubernetes
Docker