Senior DevSecOps Engineer
Checkmarx
Office
Braga, Braga, PT
Full Time
Description
Who are we?
Checkmarx is the enterprise application security leader and the host of Checkmarx One™ — the industry -leading cloud-native AppSec platform that helps enterprises build #DevSecTrust. Powered by the intelligence from our industry-leading AppSec security research team, and our AI-driven technology and services, our platform is designed to enable CISOs, AppSec and development leaders to prioritize their teams’ focus on what impacts their business. Our offerings secure every phase of development for every application, from the very first line of code through production, while simultaneously balancing the dynamic needs of security and development teams.
We are honored to serve more than 1,800 customers, which includes 60 percent of all Fortune 100 organizations. We are committed to moving forward with the unwavering dedication to the safety and security of our customers, and the applications that power our day-to-day lives.
What are we looking for?
Checkmarx is seeking a talented Senior DevSecOps Engineer to join our growing Checkmarx One™ Platform Engineering DevOps group. Checkmarx One™ is our flagship unified Application Security Platform, developed with the most cutting-edge cloud native technologies, and deployed in multi-cloud and on-premises environments.
How will you make an impact?
- Design, implement, and automate secure, scalable infrastructure for Checkmarx One™ environments, ensuring scale, high availability and compliance with FedRAMP requirements.
- Develop and maintain CI/CD pipelines with a focus on secure software supply chain practices (e.g., SBOMs, signing, verification).
- Harden Kubernetes-based deployments by building and enforcing security controls using Kubernetes Operator Framework, Network Policies, and Pod Security Standards.
- Integrate and manage observability and security monitoring tools, such as Fluent Bit, ELK, Grafana, Prometheus, and cloud-native security tooling (e.g., AWS GuardDuty, Inspector).
- Collaborate with application security, product engineering, and compliance teams to define and enforce DevSecOps best practices.
- Conduct threat modeling and risk assessments of infrastructure changes and implement remediation strategies as needed.
- Lead the adoption of secure-by-default templates infrastructure-as-code (AWS CDK, Terraform, etc.) reusable automation.
- Assist in evidence collection and environment preparation for FedRAMP audits and continuous monitoring.
Requirements
What is needed to succeed?
- 5+ years of experience as a DevOps, Site Reliability, or Platform Engineer with a strong focus on security (DevSecOps).
- In-depth experience securing production environments on AWS (or other major clouds) using least privilege, identity federation, VPC security, etc.
- Proven expertise with Kubernetes and the Operator Framework, including workload security hardening, admission controllers, and custom operators.
- Strong knowledge of CI/CD and infrastructure-as-code tools such as Jenkins, GitHub Actions, CircleCI, AWS CDK, or Terraform.
- Experience building and managing secure containerized environments using Docker, Helm, and Argo CD.
- Proficiency in at least one programming or scripting language (Python, Bash, or Go) with emphasis on automation and secure coding.
- Familiarity with compliance frameworks such as FedRAMP, SOC 2, or ISO 27001, and how they apply to cloud-native architectures.
- Experience integrating security observability and logging systems (e.g., Fluent Bit, ELK, Prometheus, AWS CloudTrail).
- Strong analytical and problem-solving skills with a security-first mindset.
What we have to offer
Checkmarx offers a great work environment, professional development, challenging careers, competitive compensation, great work-life balance, as well as great benefits and perks throughout the year.
Checkmarx is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, or other characteristics protected by law.
Senior DevSecOps Engineer
Office
Braga, Braga, PT
Full Time
August 6, 2025