Senior DevSecOps Engineer
Listed on 2026-09-27
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Help Us Build The Future of Travel
At Airalo, we’re making it easier for people to stay connected wherever they travel. As the world’s first eSIM store, we help millions of travelers access affordable mobile data in 200+ countries and regions around the world.
Today, we’re a team of 400+ people across 60+ countries, building a product used by travelers every day. We’ve grown quickly, but we’ve worked hard to keep what matters: trust, ownership, and the freedom for people to do great work without unnecessary layers or bureaucracy.
We’re fully remote by design, genuinely global, and united by a shared mission to make travel simpler for everyone.
Your Next Destination- Location: Remote, anywhere in Spain or the UK.
- Contract: Spain:
Full-time, permanent contrato indefinido via Deel (our employer of record in Spain), UK:
Full-time, permanent - Benefits: Learn more about our benefits here in this link - (Use the "Apply for this Job" box below).?pvs=74
- Languages: English is our main working language day to day, so you’ll need to be comfortable communicating in it both in meetings and async.
As our Senior Dev Sec Ops Engineer, you will be the guardian of Airalo’s global infrastructure and applications. This isn’t just about maintaining compliance, it’s a hands‑on opportunity to spearhead our shift‑left security strategy, centralise AWS governance, and proactively outsmart malicious attacks. If you are excited to design robust defences that slash attack vectors by 50% while scaling a secure ecosystem for millions of travellers, this is your chance to take true technical ownership.
Responsibilities:
- Design, implement, and manage security solutions across the entire software development lifecycle (SDLC), with a focus on automation and continuous integration/continuous delivery (CI/CD) pipelines, including robust API security measures and authentication protocols.
- Champion security best practices within engineering, Dev Ops, SRE, and IT teams, fostering a culture of shared responsibility for security.
- Proactively identify and remediate security vulnerabilities in applications, mitigating OWASP Top 10 vulnerabilities, infrastructure, and cloud services through threat modelling, vulnerability assessments, and penetration testing.
- Develop and maintain security monitoring and alerting solutions to detect and respond to potential security incidents in real‑time and prevent common cyber attacks such as DDoS, injection attacks, and credential stuffing.
- Define and enforce secure coding standards and provide training and mentorship to development teams on Dev Sec Ops principles.
- Lead compliance initiatives by contributing to security policies, controls, and audit readiness for SOC 2, ISO 27001, GDPR, and other relevant regulations.
Must-haves:
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 5+ years of experience in Dev Sec Ops , Security Engineering, or a similar role with a strong focus on cloud security.
- 3+ years of hands‑on experience with AWS services, including expertise in container orchestration, IAM, and security best practices.
- 2+ years of experience with Kubernetes, including securing Kubernetes clusters and deployments.
- Deep understanding of SAST, DAST, and container security solutions, and API security testing tools, along with experience implementing and managing these tools.
- Proven experience in vulnerability assessment, threat modelling, and remediation techniques.
- Experience with security incident response, including developing incident response plans and conducting post‑mortems.
- Proficiency in at least one programming language (Python, Go, Java, etc.) for automation and tooling.
- Proficiency in infrastructure‑as‑code tools (e.g., Terraform) and CI/CD platforms (e.g., Git Hub…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).