> Markdown version of [/jobs/ext/3211825-devsecops](https://www.wearedevelopers.com/jobs/ext/3211825-devsecops). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DevSecOps - **Company:** Lepaya - **Location:** Amsterdam, Netherlands - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Flutter, Artificial Intelligence, Airflow, Amazon Web Services, Amazon Cloudfront, Amazon S3, Bash Shell, Burp Suite, Cloud Computing, Cloud Computing Security, Cloud Engineering, Encodings, Continuous Integration, DevOps, Amazon DynamoDB, Github, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, PostgreSQL, Nginx, Node.Js, OpenVPN, OpenID, Salesforce.Com, Session Manager SubSystems, SonarQube, Tripwire, TypeScript, Software Vulnerability Management, Policy as Code, Scripting, Data Storage Management, ReactJS, Grafana, Software Security, Amazon Virtual Private Cloud (VPC), Fastapi, Vue.js, Slack, Sentry, AWS Fargate, Route53, Cloudwatch, NestJS, Terraform, Devsecops, Docker, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 3, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=f9fc64461d0f149b ## About the Role * Minimum 4 years of experience in a DevOps, Platform, Cloud, or Security Engineering role in a fast-paced start-up or scale-up environment. * Hands-on experience working with AWS and Terraform. * Familiarity with CI/CD pipelines using GitHub Actions or similar tools. * Experience working with Docker and cloud native orchestration services. * A solid understanding of cloud security fundamentals such as IAM, hardening, encryption, network security, and secrets management * Hands-on experience with at least one area of security automation - vulnerability scanning, code security analysis (SAST/SCA), policy-as-code, or cloud security posture management - and the appetite to grow into the rest. * Scripting skills in Bash or Python. Experience with TypeScript is a plus. * Strong English communication skills. Nice to have * Experience with tech compliance (ISO 27001, SOC 2, GDPR). * Exposure to DAST tooling (e.g. OWASP ZAP) or offensive security basics. * Experience with software supply chain security. * Exposure to GCP alongside AWS. Our tech stack * Cloud: AWS (primary, multi-account Organizations), GCP * IaC: Terraform (tflint, terraform-docs, pre-commit), Packer * Compute: ECS on Fargate, Lambda, ECR * CI/CD: GitHub Actions with centralized reusable workflows, GitHub OIDC, self-hosted runners on AWS, Dependabot * Security: IAM Identity Center, GuardDuty, KMS, WAFv2, SSM Parameter Store, Trivy/Grype/Snyk, SonarQube * Observability: Grafana Cloud, Loki, OpenTelemetry, CloudWatch, Sentry, Slack alerting * Data & storage: Aurora/RDS PostgreSQL, DynamoDB, S3, Airflow (MWAA) * AI & ML: Amazon SageMaker * Networking & edge: CloudFront, ALB, Route53, VPC, nginx, OpenVPN/SSM Session Manager * Application stack: Node.js/TypeScript (NestJS, Fastify), Python (FastAPI), React, Vue, Flutter, Salesforce ## Description As a DevSecOps Engineer, you'll work closely with Yusuf, our Senior DevOps Engineer, and help build and secure the cloud platform that makes this possible. You'll ensure our products are secure, reliable, and scalable, while giving our Tech and Product teams the tools they need to deliver new features quickly and confidently. You'll sit at the intersection of DevOps, Security, and IT. Working closely with our Security Engineer, IT Manager, Software Engineers, and Product teams, you'll turn security policies into automated guardrails, built into the same pipelines, infrastructure modules, and developer experience that power our learning platform. For us, security isn't a gate at the end of the process; it's a feature of the platform itself. We are not able to provide relocation support for this role. We are only hiring for candidates who are able to work in the Netherlands. What you'll do * Building and improving our AWS infrastructure using Terraform, with security designed in from the start: least-privilege IAM, encryption, and network controls as defaults, not afterthoughts. * Embedding security into our CI/CD pipeline: dependency, container, and secrets scanning in every pipeline, and making the results actionable for engineers instead of noisy. * Introducing policy-as-code (e.g. Checkov, OPA) so infrastructure misconfigurations are caught before they're merged, not after they're deployed. * Developing secure-by-default infrastructure modules that enable engineering teams to launch new, secure services with ease. * Strengthening our cloud security posture across a multi-account AWS organization: identity management, threat detection, and vulnerability management as an ongoing program. * Automating compliance: working with our Security Engineer and IT Manager to turn security controls into automatically collected, audit-ready evidence, and supporting security audits. * Improving monitoring and observability using Grafana Cloud and OpenTelemetry, including security signals and alerting. * Finding opportunities to automate repetitive processes and continuously improve the developer experience. This role offers plenty of ownership while giving you the opportunity to learn, grow, and help shape the platform that powers Lepaya's mission to transform workplace learning. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Stack Overflow: Community and AI](https://www.wearedevelopers.com/videos/600-stack-overflow-community-and-ai) - [Post-Quantum Cryptography: Preparing for Q-Day](https://www.wearedevelopers.com/videos/100179-post-quantum-cryptography-preparing-for-q-day) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)