Role Description
As the DevSecOps Team Lead, you will be the bridge between Security, Operations, and Engineering. You will lead a team of specialized engineers to build, scale, and maintain a "Security-as-Code" ecosystem. Your mission is to empower development teams to ship software faster and more securely by providing them with automated guardrails, self-service security tools, and expert architectural guidance.
Key Responsibilities
-
Strategic Leadership & Team Management
-
Team Growth:
Lead, mentor, and coach a team of DevSecOps engineers. Conduct performance reviews, manage career development paths, and foster a culture of high performance.
-
Roadmap Ownership:
Define the DevSecOps strategy and multi-quarter roadmap, aligning security initiatives with broader business and engineering goals.
-
Stakeholder Management:
Act as the primary point of contact for Engineering and Product leads to ensure security requirements are baked into the Product Discovery phase.
-
Security Architecture & Governance
-
Policy-as-Code:
Lead the implementation of organizational guardrails using tools like OPA (Open Policy Agent) or Kyverno to ensure compliance is automated across all environments.
-
Secure Infrastructure:
Oversee the design of secure cloud architectures (AWS/Azure/GCP) and Kubernetes clusters, focusing on Zero Trust networking and identity-driven access.
-
Vendor & Budget Management:
Evaluate, procure, and manage third-party security vendors and tools (e.g., Snyk, Wiz, Cloudflare), ensuring maximum ROI and technical fit.
-
Operational Excellence
-
Metric-Driven Security:
Define and track key performance indicators (KPIs) such as Mean Time to Remediate (MTTR), vulnerability burn-down rates, and false-positive ratios.
-
Incident Response:
Serve as a technical escalation point for high-severity security incidents and lead the "Blameless Post-Mortem" process to drive systemic improvements.
Qualifications
-
6+ years in Security, DevOps, or Infrastructure roles.
-
2+ years in a leadership capacity (Team Lead, Tech Lead, or Engineering Manager).
-
Proven track record of scaling security practices in a cloud-native, high-growth environment.
Requirements
-
Technical Proficiency
-
Automation & IaC:
Expert knowledge of Terraform/OpenTofu, Ansible, and CI/CD platforms (GitHub Actions, GitLab CI).
-
Cloud & Containers:
Deep understanding of Kubernetes security (RBAC, Network Policies, Admission Controllers) and cloud provider security services.
-
Tooling:
Experience implementing and tuning SAST, DAST, SCA, and Secret Management (HashiCorp Vault) at scale.
-
Development:
Proficiency in Python, Go, or TypeScript to build custom internal security tooling and integrations.
-
Soft Skills
-
Pragmatism:
Ability to balance "perfect security" with the "speed of business."
-
Communication:
Exceptional ability to translate complex technical risks into business impact for executive stakeholders.
Benefits
-
Stock grant opportunities dependent on your role, employment status, and location.
-
Additional perks and benefits based on your employment status and country.
-
The flexibility of remote work, including optional WeWork access.