DevSecOps
Build your career on Magnet.me
Create a profile and receive smart job recommendations based on your liked jobs.
Join Lepaya!
At Lepaya, we believe that people are every organisation's greatest asset. Our mission is to help professionals develop the skills they need to thrive, and technology enables us to deliver that learning experience to thousands of learners around the world.
As a DevSecOps Engineer, you'll work closely with Yusuf, our Senior DevOps Engineer, and help build and secure the cloud platform that makes this possible. You'll ensure our products are secure, reliable, and scalable, while giving our Tech and Product teams the tools they need to deliver new features quickly and confidently.
You'll sit at the intersection of DevOps, Security, and IT. Working closely with our Security Engineer, IT Manager, Software Engineers, and Product teams, you'll turn security policies into automated guardrails, built into the same pipelines, infrastructure modules, and developer experience that power our learning platform. For us, security isn't a gate at the end of the process; it's a feature of the platform itself.
- Amsterdam
- Full-time
- Permanent employee
- We are not able to provide relocation support for this role. We are only hiring for candidates who are able to work in the Netherlands.
This role offers plenty of ownership while giving you the opportunity to learn, grow, and help shape the platform that powers Lepaya's mission to transform workplace learning.
What you’ll do
- Building and improving our AWS infrastructure using Terraform, with security designed in from the start: least-privilege IAM, encryption, and network controls as defaults, not afterthoughts.
- Embedding security into our CI/CD pipeline: dependency, container, and secrets scanning in every pipeline, and making the results actionable for engineers instead of noisy.
- Introducing policy-as-code (e.g. Checkov, OPA) so infrastructure misconfigurations are caught before they're merged, not after they're deployed.
- Developing secure-by-default infrastructure modules that enable engineering teams to launch new, secure services with ease.
- Strengthening our cloud security posture across a multi-account AWS organization: identity management, threat detection, and vulnerability management as an ongoing program.
- Automating compliance: working with our Security Engineer and IT Manager to turn security controls into automatically collected, audit-ready evidence, and supporting security audits.
- Improving monitoring and observability using Grafana Cloud and OpenTelemetry, including security signals and alerting.
- Finding opportunities to automate repetitive processes and continuously improve the developer experience.
What you’ll bring
- Minimum 4 years of experience in a DevOps, Platform, Cloud, or Security Engineering role in a fast-paced start-up or scale-up environment.
- Hands-on experience working with AWS and Terraform.
- Familiarity with CI/CD pipelines using GitHub Actions or similar tools.
- Experience working with Docker and cloud native orchestration services.
- A solid understanding of cloud security fundamentals such as IAM, hardening, encryption, network security, and secrets management
- Hands-on experience with at least one area of security automation - vulnerability scanning, code security analysis (SAST/SCA), policy-as-code, or cloud security posture management - and the appetite to grow into the rest.
- Scripting skills in Bash or Python. Experience with TypeScript is a plus.
- Strong English communication skills.
Nice to have
- Experience with tech compliance (ISO 27001, SOC 2, GDPR).
- Exposure to DAST tooling (e.g. OWASP ZAP) or offensive security basics.
- Experience with software supply chain security.
- Exposure to GCP alongside AWS.
Our tech stack
- Cloud: AWS (primary, multi-account Organizations), GCP
- IaC: Terraform (tflint, terraform-docs, pre-commit), Packer
- Compute: ECS on Fargate, Lambda, ECR
- CI/CD: GitHub Actions with centralized reusable workflows, GitHub OIDC, self-hosted runners on AWS, Dependabot
- Security: IAM Identity Center, GuardDuty, KMS, WAFv2, SSM Parameter Store, Trivy/Grype/Snyk, SonarQube
- Observability: Grafana Cloud, Loki, OpenTelemetry, CloudWatch, Sentry, Slack alerting
- Data & storage: Aurora/RDS PostgreSQL, DynamoDB, S3, Airflow (MWAA)
- AI & ML: Amazon SageMaker
- Networking & edge: CloudFront, ALB, Route53, VPC, nginx, OpenVPN/SSM Session Manager
- Application stack: Node.js/TypeScript (NestJS, Fastify), Python (FastAPI), React, Vue, Flutter, Salesforce
Why you’ll love this journey at Lepaya
- A challenging role in a vibrant international scale-up
- Our work-to-live scheme, which prioritizes health and wellbeing
- Unlimited holidays and Lepaya Fridays, every other Friday, a day for yourself
- Flexible hours and a hybrid working arrangement, we expect you to work from our office at least 3 days a week. Tuesday and Thursday are anchor days
- Work from anywhere for 8 weeks/year
- Access to Empowr, our well-being partner
- Lots of opportunities to learn and grow, including internal career development
- Access to our Lepaya Academy to help you upskill
- An internal hiring program to help you advance
We help organizations to upskill their people. We focus on Power Skills: a unique set of future-proof competencies we defined based on market needs. We combine high impact training with digital tooling - empowering professionals to learn and grow when, where, and how it suits them best. Since 2018 we have been growing fast, and we are excited for further…
We help organizations to upskill their people. We focus on Power Skills: a unique set of future-proof competencies we defined based on market needs. We combine high impact training with digital tooling - empowering professionals to learn and grow when, where, and how it suits them best. Since 2018 we have been growing fast, and we are excited for further international expansion - supported by a 35M€ series B investment. Now is the perfect time to join us and become part of our growth story.