DevSecOps Engineer – Remote Work Type
Directio Sp. z o.o. · Warsaw, Poland · Remote
Posted Sep 11, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Directio is a global IT services company. We consult, code, test, deploy, and manage mainly cloud-based and mobile applications, providing around-the-clock support from our offices in Poland, the Philippines, Mexico, and the USA. We prepare our FMCG, retail, automotive, and SaaS clients for the future by accelerating their digital transformation. Operating under the “We Code Success” principle, we prioritize the success of our clients, consultants, and partners.
About project
We are looking for a DevSecOps Engineer to join a project for our client, an international company operating across multiple markets.
You will be joining a small platform team responsible for Azure, Kubernetes, deployments, Microsoft 365, and on-call support. This is a hands-on role combining platform engineering and DevOps responsibilities with ownership of security engineering practices.
You will be supporting our client’s migration from a monolithic architecture to services, building the required infrastructure, environments, CI/CD pipelines, and observability while ensuring the stability of the existing platform.
At the same time, you will be responsible for strengthening security practices across the organization and supporting the technical side of the ISO 27001 certification journey.
Responsibilities
You will be running and maintaining the platform together with the team, working with Azure, AKS, deployments, upgrades, incident response, and on-call support;
You will be building and operating infrastructure required for the migration from a monolithic architecture to services, including environments, CI/CD pipelines in Azure DevOps, Infrastructure as Code, monitoring, and alerting;
You will be managing the external attack surface, maintaining an inventory of internet-facing assets, monitoring potential exposures, and ensuring vulnerabilities are addressed effectively;
You will be integrating security into Azure DevOps and Kubernetes delivery pipelines, including code, dependency, secrets, container, and Infrastructure as Code scanning;
You will be establishing and maintaining the Azure and Microsoft 365 security baseline, including identity and access management, MFA, cloud security posture, Microsoft Defender, and access management processes;
You will be managing the vulnerability management process end-to-end, from identifying vulnerabilities and coordinating fixes to verifying their resolution and maintaining appropriate evidence;
You will be responsible for the technical security controls supporting the ISO 27001 certification programme, working closely with the compliance lead;
You will be providing technical input for customer security questionnaires and audits and participating in discussions with customers and auditors when deeper technical expertise is required;
You will be supporting penetration testing activities performed by an external partner, including defining the scope, coordinating testing activities, and ensuring…