DevSecOps Engineer
Leaf Space · Lomazzo, Italy · Hybrid
Posted Aug 4, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
DevSecOps Engineer
About Leaf Space
Leaf Space is a rapidly growing scale-up company and a leading provider of ground segment as-a-service (GSaaS) solutions. Our innovative and proprietary concept is focused on providing satellite and launch vehicle connectivity as-a-service, enabling clients to efficiently manage their assets and fully exploit data. Our GSaaS solutions have been recognized by the market for their efficiency, security, and effectiveness in supporting different applications, from remote sensing to IoT communications.
JOB OVERVIEW
We're building a satellite-based mesh network, and the software and infrastructure behind it — ground segment services, network orchestration, telemetry pipelines, and embedded flight/payload software tooling — need to be shipped fast and run securely. As DevSecOps Engineer you will design, implement and continuously improve the CI/CD, cloud and infrastructure environment , contribute directly to software development across the stack, and build security into every stage rather than bolting it on at the end. This is a hands-on role spanning development, operations, and security for systems that are both mission-critical and subject to strict regulatory obligations.
RESPONSIBILITIES
Design, build, and maintain CI/CD pipelines for ground-segment, network, and embedded software, with automated testing, security scanning, and controlled release gates.
Contribute to automation tooling and software development supporting the platform and infrastructure.
Collaborate with embedded software teams to support build toolchains, cross-compilation and integration workflows.
Manage cloud and on-prem infrastructure as code (Terraform, Ansible, or equivalent) with reproducible, auditable deployments.
Operate and secure containerized and orchestrated workloads (Docker, Kubernetes), including image hardening, registry scanning, and runtime security.
Implement observability — logging, metrics, tracing, and alerting — for reliable, debuggable production systems.
Harden systems and enforce access control, network segmentation, and least-privilege principles across environments.
Support compliance and audit readiness against frameworks relevant to critical infrastructure (e.g., NIS2 , ISO 27001), contributing to policies, controls, and evidence.
Contribute to incident response, patch management, and secure configuration baselines.
Partner with software, network, and mission teams
QUALIFICATIONS AND STUDIES
Degree in computer science, engineering, or equivalent practical experience.
Roughly 3–6 years in DevOps, SRE, platform, security, or software engineering roles.
REQUIREMENTS
Tech skills
Strong Linux knowledge (required) — administration, networking, and development on Linux systems.
Solid software development skills, with experience writing production code (Python, Go, C/C++, Rust or similar).
Familiarity with embedded software development environments is considered a plus.
…