DevSecOps Engineer

Job Description

Role Overview

Division Information Security
Reporting Line Chief Information Security Officer (CISO)
Functional Coordination Software Engineering, IT Infrastructure, Quality Assurance, and Release Teams
Location Karachi (with frequent travel to Government of Sindh departments across Sindh)
Employment Type Full-time

The DevSecOps Engineer is a highly collaborative, technical role bridging the gap between Software Development, Security, and IT Operations. The primary focus of this position is to champion and implement “Shift Left” security initiatives, successfully embedding automated security controls, checks, and policies directly within SITC’s continuous integration and continuous deployment (CI/CD) pipelines.

As SITC accelerates the delivery of modern, digital products to Government of Sindh departments, this role guarantees that security does not slow down development. By designing automated guardrails, automating secrets management, hardening containerized deployments, and managing threat monitoring, the DevSecOps Engineer builds a seamless, resilient, and highly secure software delivery lifecycle (SSDLC).

Key Responsibilities

  • Design, implement, and manage automated security workflows within the company’s CI/CD pipelines, ensuring all builds undergo automatic SAST, DAST, and Software Composition Analysis (SCA).
  • Configure, tune, and maintain modern automated security tools to minimize false positives, enabling rapid development feedback loops without compromising security standards.
  • Enforce secure secrets management and credential storage policies across automated pipelines, using robust tools (e.g., HashiCorp Vault, cloud secrets managers) to eradicate hardcoded credentials.
  • Architect, secure, and monitor containerized ecosystems (Docker, Kubernetes), defining strict network policies, container image signing, and runtime threat detection parameters.
  • Implement infrastructure-as-code (IaC) security scanning to analyze cloud templates and deployment scripts (e.g., Terraform, Ansible) for security misconfigurations before deployment.
  • Establish centralized security logging, continuous monitoring, and real-time alerting mechanisms to spot anomalies and operational bottlenecks in development, staging, and production environments.
  • Work hand-in-hand with software developers to interpret pipeline-generated security alerts, providing direct technical guidance on remediation strategies.
  • Standardize secure base operating system images, base container images, and runtime execution environments across all engineering departments.

Required Skills & Competencies

  • Hands-on experience building and securing CI/CD pipelines (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps).
  • Deep proficiency with container technology and orchestration platforms, with a strong focus on Kubernetes and Docker security.
  • Expertise in integrating automated security scanners (e.g., SonarQube, Trivy, Snyk, OWASP Dependency-Check, OWASP ZAP) into active deployment pipelines.
  • Strong foundation in Infrastructure-as-Code (IaC) templates and configuration management tools (Terraform, Ansible, CloudFormation).
  • Excellent interpersonal skills, demonstrating a patient, collaborative mindset capable of teaching security concepts to software developers.
  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related technical discipline from an HEC-recognized institution.
  • Experience: Minimum of 4-6+ years of professional experience, with at least 2 years in a dedicated DevOps or DevSecOps engineering role within a modern software delivery setup.
  • Certifications: Professional certifications such as AWS Certified DevOps Engineer, Certified Kubernetes Administrator/Security Specialist (CKA/CKS), DevSecOps Professional (CDP), or similar certifications are highly desirable.

Qualification & Experience

  • Education: Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related technical discipline from an HEC-recognized institution.
  • Experience: Minimum of 4-6+ years of professional experience, with at least 2 years in a dedicated DevOps or DevSecOps engineering role within a modern software delivery setup.
  • Certifications: Professional certifications such as AWS Certified DevOps Engineer, Certified Kubernetes Administrator/Security Specialist (CKA/CKS), DevSecOps Professional (CDP), or similar certifications are highly desirable.

Note:
Only PDF resumes are accepted.
Your CV must include an email ID, mobile number, LinkedIn URL, and current city.

Drop your file here or click here to upload You can upload up to 1 files.