Devsecops Engineer
3 weeks ago
Digitas Liquorice is the Connected Marketing agency, built on the principle that there are better ways for brands to connect with people. We leverage comprehensive data, technology, creative, media and strategy capabilities to deliver Media‑Fueled Creativity via connected Solutions that include Connected Campaigns, Social Marketing, Brand Experience, CRM & Loyalty, and Marketing Transformation. Digitas Liquorice South Africa has Head Offices in JHB and CT with over Unicorns delivering connected end‑to‑end solutions for our clients across SSA. Visit for more about us and what we do. We are also connected to Digitas Unicorns across over 30 countries and 50 offices around the world. Overview We are seeking a highly skilled DevSecOps Engineer to join our team in South Africa. The ideal candidate will be responsible for integrating security best practices into the software development lifecycle (SDLC) across multi‑cloud environments (Azure, GCP, AWS). They will work closely with development, operations, and security teams to ensure the secure, efficient, and continuous delivery of applications. This role requires strong expertise in Infrastructure as Code (IaC), automation, orchestration tools, and golden image management. The successful candidate will enhance security‑by‑design principles within CI / CD pipelines, implement OWASP Top 10 security measures, and enforce cloud‑native security best practices within fintech regulatory frameworks in South Africa. Responsibilities Cloud Security & Compliance Secure multi‑cloud environments (Azure, AWS, GCP) by implementing security automation and monitoring tools. Ensure compliance with financial security regulations (POPIA, PCI‑DSS, ISO, SOC 2). Conduct cloud security risk assessments and enforce security guardrails to prevent misconfigurations. Implement Zero Trust Security principles for IAM, RBAC, and secure access controls. CI / CD Security & Automation Design and integrate secure CI / CD pipelines, incorporating automated security testing (SAST, DAST, IAST). Implement secrets management, artifact integrity validation, and secure containerisation strategies. Automate security scans for vulnerabilities, dependencies and misconfigurations in Terraform, CloudFormation and Kubernetes manifests. Infrastructure as Code (IaC) & Orchestration Implement and manage IaC frameworks using Terraform, Ansible, Puppet and CloudFormation. Automate provisioning of Kubernetes clusters (EKS, AKS, GKE) and containerised workloads. Manage Docker, ECS and Kubernetes (EKS, GKE, AKS) security, ensuring adherence to best practices. Enforce immutable infrastructure principles through golden image management and automated patching strategies. Golden Image Management & Compliance Develop, maintain and enforce golden images for VMs, containers and cloud workloads. Automate image hardening using tools like Packer, CIS Benchmarks and OSSEC. Ensure compliance of golden images with security baselines and regulatory standards. Threat Detection & Response Implement SIEM / SOAR solutions for cloud‑native security monitoring and automated response. Identify, assess and remediate vulnerabilities using OWASP Top 10 and SANS 25 methodologies. Secure APIs using OAuth, JWT, OpenID Connect and enforce WAF security rules. Collaboration & Training Work closely with DevOps, Security and Engineering teams to embed security within the SDLC. Conduct secure coding and DevSecOps best practices training for developers and engineers. Advocate for "Shift Left Security" by integrating security from the earliest stages of development. Daily Duties Automate security hardening for cloud, infrastructure and applications. Monitor and maintain secure multi‑cloud environments (Azure, AWS, GCP). Enhance and secure CI / CD pipelines by integrating automated security testing tools. Perform vulnerability scanning, penetration testing and security incident analysis. Develop and maintain golden images for infrastructure and applications. Optimize Kubernetes security using RBAC, Pod Security Policies (PSP), Network Policies. Automate patch management and enforce container image scanning in Docker, EKS and ECS. Stay updated with emerging threats, security trends and DevSecOps innovations. Qualifications Must‑Have : 5-6+ years of experience in DevSecOps, Cloud Security or DevOps with a security focus. Expertise in Azure, AWS and GCP security services (e.g., AWS Security Hub, Azure Security Centre, GCP Security Command Centre). Strong knowledge of CI / CD tools (Jenkins, GitLab CI / CD, GitHub Actions, Azure DevOps). Proficiency in Infrastructure as Code (IaC) (Terraform, CloudFormation, Puppet, Ansible). Hands‑on experience with containerisation and orchestration (Docker, Kubernetes, EKS, ECS, GKE, AKS). Strong understanding of OWASP Top 10, SAST, DAST, IAST, API security best practices. Experience implementing secrets management (Vault, AWS Secrets Manager, Azure Key Vault). Proficiency in SIEM / SOAR platforms for security monitoring and incident response. Knowledge of Zero Trust security models, IAM, RBAC and secure networking. Nice‑to‑Have : Certifications such as AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, CISSP, CISM, CEH. Experience in fintech security regulations (PCI‑DSS, SOC 2, ISO, POPIA). Familiarity with DevSecOps frameworks (NIST, CSA Cloud Controls Matrix, MITRE ATT&CK). Knowledge of blockchain security or smart contract security is a plus. Additional information Why Join Us? Work in a high impact fintech company shaping the future of digital finance in South Africa. Cutting‑edge technology stack leveraging cloud‑native security automation. Career growth opportunities with training, certifications and mentorship. Competitive salary & benefits tailored for top security professionals. Flexible work arrangements (remote / hybrid options available). #J-18808-Ljbffr
-
Specialist: Devsecops
2 weeks ago
Johannesburg, South Africa Vodafone Full time**When it comes to putting people first, we're number 1.** The number 1 Top Employer in South Africa. Certified by the Top Employer Institute 2025. **Role Purpose/Business Unit**: The primary purpose of the role is the implementation and continuous improvement of the DevSecOps programme within Vodacom South Africa, ensuring alignment with the Cyber Health...
-
Specialist : Devsecops
2 weeks ago
Johannesburg, South Africa Vodacom Full timeRole Purpose / Business Unit The primary purpose of the role is the implementation and continuous improvement of the DevSecOps programme within Vodacom South Africa, ensuring alignment with the Cyber Health and Adaptive Risk Method (CHARM) control. Responsibilities Implement, operate and continuously improve the DevSecOps Security Chapter and Champions model...
-
Devsecops
7 days ago
Johannesburg, South Africa DotModus Full time**Your Position**: We’re looking for a talented DevSecOps engineer to help us build out our customers’ products and solutions on multiple hyper scalers (GCP/AWS/Azure). The role is not just about being able to write the code, but also being able to architect, integrate and institute best practices to the DevSecOps competency at DotModus. We value a...
-
Devsecops Lead
1 day ago
Johannesburg, South Africa GoldenRule Full time**The Role** We are currently looking for a DevSecOps Lead in Johannesburg and Cape Town to implement and maintain a comprehensive DevSecOps Security Program. This is a 1st line of defence role and will report to the Chief Information Security Officer. **Skills and Experience** - Bachelor's or Master's degree in Technology related field. Information Systems...
-
DevSecOps Engineer
1 week ago
City of Johannesburg Metropolitan Municipality, South Africa GMI Advisory Full time• Implement scalable, resilient, and secure solutions in the public cloud, especially in AWS. • Participate in automation initiatives to streamline processes, improve efficiencies, and reduce hosting cost. • Work closely with Product Owner, Platform Team, Solution Architects, and development teams for continuous improvement • Enhance and drive...
-
DevSecOps Engineer
1 week ago
City of Johannesburg Metropolitan Municipality, South Africa GMI Advisory Full time• Implement scalable, resilient, and secure solutions in the public cloud, especially in AWS. • Participate in automation initiatives to streamline processes, improve efficiencies, and reduce hosting cost. • Work closely with Product Owner, Platform Team, Solution Architects, and development teams for continuous improvement • Enhance and drive...
-
DevOps Engineer
2 weeks ago
Johannesburg, South Africa Empire Recruitment Full timeKey Responsibilities:Building and hardening Kubernetes clusters and Docker containersDesigning secure infrastructure automation using Nutanix Calm and Prism CentralEmbedding DevSecOps principles into CI/CD pipelines (GitLab CI, Azure DevOps, Jenkins)Automating security controls with tools like Snyk, Trivy, or AquaManaging Windows Server, Active Directory,...
-
Devsecops - Manager
7 days ago
Johannesburg, South Africa Mikyle Consulting Full time**Job Role: Manager - Information Security (DEVSECOPS)** **Introduction**: **Description**: We are looking for a **Manager The above is related to software development practices relating to the SDLC (Software development lifecycle), Agile and DEVSECOPS practices and principles. **Start Date**:As soon as possible **Responsibilities**: - Develop a...
-
Senior Devsecops Architect
1 week ago
Johannesburg, South Africa NTT Ltd. Full timeNTT is a leading global IT solutions and services organisation that brings together people, data and things to create a better and more sustainable future. In today’s ‘iNTTerconnected’ world, connections matter more now than ever. By bringing together talented people, world-class technology partners and emerging innovators, we help our clients solve...
-
DevOps Engineer
3 weeks ago
Johannesburg, South Africa The Legends Agency Full timeDevOps Engineer Own resilient infrastructure at the heart of digital security! On-site | Irene, Gauteng, South Africa R900,000 per annum Secure platforms | Scalable systems | High-impact role Are you a DevOps expert with a passion for automation, reliability, and infrastructure that never sleeps? Step into a mission-critical role where your expertise...