DevSecOps Engineer

6 days ago


Cape Town, Western Cape, South Africa Digitas SA Full time R1 200 000 - R2 400 000 per year

Company Description
Digitas Liquorice is the Connected Marketing agency, built on the principle that there are better ways for brands to connect with people. We leverage comprehensive data, technology, creative, media and strategy capabilities to deliver Media-Fueled Creativity via connected Solutions that include Connected Campaigns, Social Marketing, Brand Experience, CRM & Loyalty, and Marketing Transformation. Digitas Liquorice South Africa has Head Offices in JHB and CT with over 220 Unicorns delivering connected end-to-end solutions for our clients across SSA. Visit for more about us and what we do. We are also connected to 6 600 Digitas Unicorns across over 30 countries and 50 offices around the world.

Overview
We are seeking a highly skilled DevSecOps Engineer to join our team in South Africa.

The ideal candidate will be responsible for integrating security best practices into the software development lifecycle (SDLC) across multi-cloud environments (Azure, GCP, AWS). They will work closely with development, operations, and security teams to ensure the secure, efficient, and continuous delivery of applications.

This role requires strong expertise in Infrastructure as Code (IaC), automation, orchestration tools, and golden image management.

The successful candidate will enhance security-by-design principles within CI/CD pipelines, implement OWASP Top 10 security measures, and enforce cloud-native security best practices within fintech regulatory frameworks in South Africa.

Responsibilities

  • Cloud Security & Compliance
  • Secure multi-cloud environments (Azure, AWS, GCP) by implementing security automation and monitoring tools.
  • Ensure compliance with financial security regulations (POPIA, PCI-DSS, ISO 27001, SOC 2).
  • Conduct cloud security risk assessments and enforce security guardrails to prevent misconfigurations.
  • Implement Zero Trust Security principles for IAM, RBAC, and secure access controls.
  • CI/CD Security & Automation
  • Design and integrate secure CI/CD pipelines, incorporating automated security testing (SAST, DAST, IAST).
  • Implement secrets management, artifact integrity validation, and secure containerization strategies.
  • Automate security scans for vulnerabilities, dependencies, and misconfigurations in Terraform, CloudFormation, and Kubernetes manifests.
  • Infrastructure as Code (IaC) & Orchestration
  • Implement and manage IaC frameworks using Terraform, Ansible, Puppet, and CloudFormation.
  • Automate provisioning of Kubernetes clusters (EKS, AKS, GKE) and containerized workloads.
  • Manage Docker, ECS, and Kubernetes (EKS, GKE, AKS) security, ensuring adherence to best practices.
  • Enforce immutable infrastructure principles through golden image management and automated patching strategies.
  • Golden Image Management & Compliance
  • Develop, maintain, and enforce golden images for VMs, containers, and cloud workloads.
  • Automate image hardening using tools like Packer, CIS Benchmarks, and OSSEC.
  • Ensure compliance of golden images with security baselines and regulatory standards.
  • Threat Detection & Response
  • Implement SIEM/SOAR solutions for cloud-native security monitoring and automated response.
  • Identify, assess, and remediate vulnerabilities using OWASP Top 10 and SANS 25 methodologies.
  • Secure APIs using OAuth, JWT, OpenID Connect, and enforce WAF security rules.
  • Collaboration & Training
  • Work closely with DevOps, Security, and Engineering teams to embed security within the SDLC.
  • Conduct secure coding and DevSecOps best practices training for developers and engineers.
  • Advocate for "Shift Left Security" by integrating security from the earliest stages of development
  • Daily Duties
  • Automate security hardening for cloud, infrastructure, and applications.
  • Monitor and maintain secure multi-cloud environments (Azure, AWS, GCP).
  • Enhance and secure CI/CD pipelines by integrating automated security testing tools.
  • Perform vulnerability scanning, penetration testing, and security incident analysis.
  • Develop and maintain golden images for infrastructure and applications.
  • Optimize Kubernetes security using RBAC, Pod Security Policies (PSP), Network Policies.
  • Automate patch management and enforce container image scanning in Docker, EKS, and ECS.
  • Stay updated with emerging threats, security trends, and DevSecOps innovations.

Qualifications
Must-Have:

  • 5-6+ years of experience in DevSecOps, Cloud Security, or DevOps with a security focus.
  • Expertise in Azure, AWS, and GCP security services (e.g., AWS Security Hub, Azure Security Center, GCP Security Command Center).
  • Strong knowledge of CI/CD tools (Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps).
  • Proficiency in Infrastructure as Code (IaC) (Terraform, CloudFormation, Puppet, Ansible).
  • Hands-on experience with containerization and orchestration (Docker, Kubernetes, EKS, ECS, GKE, AKS).
  • Strong understanding of OWASP Top 10, SAST, DAST, IAST, API security best practices.
  • Experience implementing secrets management (Vault, AWS Secrets Manager, Azure Key Vault).
  • Proficiency in SIEM/SOAR platforms for security monitoring and incident response.
  • Knowledge of Zero Trust security models, IAM, RBAC, and secure networking.

Nice-to-Have
Additional information

  • Certifications such as AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, CISSP, CISM, CEH.
  • Experience in fintech security regulations (PCI-DSS, SOC 2, ISO 27001, POPIA).
  • Familiarity with DevSecOps frameworks (NIST 800-53, CSA Cloud Controls Matrix, MITRE ATT&CK).
  • Knowledge of blockchain security or smart contract security is a plus.

Why Join Us?

  • Work in a high-impact fintech company shaping the future of digital finance in South Africa.
  • Cutting-edge technology stack leveraging cloud-native security automation.
  • Career growth opportunities with training, certifications, and mentorship.
  • Competitive salary & benefits tailored for top security professionals.
  • Flexible work arrangements (remote/hybrid options available).

NB: This job description presented provides a succinct outline of the typical functions inherent to the role, rather than an exhaustive list of all conceivable responsibilities, tasks, and duties. Moreover, we recognise that the specific responsibilities, tasks, and duties assigned to the role may vary from those outlined in the job description, with potential for additional duties that align with your capabilities being assigned as required.


  • DevSecOps Engineer

    1 week ago


    Cape Town, Western Cape, South Africa Mukuru Full time R180 000 - R250 000 per year

    Mukuru is one of Africa's leading fintech companies, empowering millions across borders through accessible and secure financial services. We're growing fast — and with that comes the responsibility to safeguard our systems, our people, and our customers.We're looking for aDevSecOps Engineerwho's passionate aboutcloud security, automation, and innovation—...

  • DevSecOps Engineer

    1 week ago


    Cape Town, Western Cape, South Africa Mukuru Full time R450 000 - R900 000 per year

    Mukuru is one of Africa's leading fintech companies, empowering millions across borders through accessible and secure financial services. We're growing fast — and with that comes the responsibility to safeguard our systems, our people, and our customers.We're looking for a DevSecOps Engineer who's passionate about cloud security, automation, and innovation...

  • DevSecOps Engineer

    6 days ago


    Cape Town, Western Cape, South Africa Publicis Groupe Holdings B.V Full time R80 000 - R120 000 per year

    Company descriptionDigitas Liquorice is the Connected Marketing agency, built on the principle that there are better ways for brands to connect with people. We leverage comprehensive data, technology, creative, media and strategy capabilities to deliver Media-Fueled Creativity via connected Solutions that include Connected Campaigns, Social Marketing, Brand...

  • DevSecOps Engineer

    4 days ago


    Cape Town, Western Cape, South Africa Boardroom Appointments Full time R600 000 - R1 200 000 per year

    Minimum Requirements:Background & Experience: Originating from an open-source operating system background, candidates should possess a minimum of 5 years in IT, with 3 years focused on DevSecOps roles.Cloud Expertise: Demonstrated experience working in cloud environments, with a deep understanding of cloud architectures, services, and best...

  • DevSecOps Engineer

    4 days ago


    Cape Town, Western Cape, South Africa Boardroom Appointments Full time R1 000 000 - R2 500 000 per year

    Responsibilities:Daily focus on improving our security and working to resolve any issues highlighted by external partners in delivery or support of software we supply.Daily management, optimisation and troubleshooting of security in our CICD pipelines.Improve and manage security in our Kubernetes environment.Assist with any Kubernetes requirements where...


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time R2 000 000 - R2 500 000 per year

    Cloud DevOps EngineerKey Responsibilities:Design, implement, and maintain CI/CD pipelines for cloud applications.Provision and manage cloud infrastructure using Infrastructure as Code (IaC).Build, deploy, and manage containerized applications using Docker and Kubernetes.Integrate security practices into DevOps pipelines (DevSecOps).Implement logging,...

  • Cloud Engineer

    1 week ago


    Cape Town, Western Cape, South Africa RAY AI Full time R1 800 000 - R2 500 000 per year

    A Message from Our CEO:We are seeking a highly skilled Cloud Engineer & Infrastructure Security professional to design, build, and secure our hybrid infrastructure (cloud + on-prem). The ideal candidate will have deep experience with Kubernetes, Terraform, Helm, and a strong background in infrastructure security, DevSecOps, and on-prem deployments. This role...

  • Software Engineer

    4 days ago


    Cape Town, Western Cape, South Africa AiR Full time R800 000 - R1 200 000 per year

    Software Engineer We're looking for a Software Engineer to join our clients growing Business Systems team. Youll play a key role in building and enhancing their customer portal and internal systems, with the chance to shape user experience, design, and delivery in an agile environment.What You'll DoDesign, build, and test high-quality software...


  • Cape Town, Western Cape, South Africa Old Mutual Limited Full time R600 000 - R1 000 000 per year

    Let's Write Africa's Story TogetherOld Mutual is a firm believer in the African opportunity and our diverse talent reflects this. Job DescriptionThe Head of Software Engineering reports into the Head of Engineering and is responsible for the development of high-quality designs and solutions and the integration of these at an Enterprise level across Old...


  • Cape Town, Western Cape, South Africa Boardroom Appointments Full time R300 000 - R600 000 per year

    Key purpose:The main focus of this role will be to shift left with security and to aid in the empowerment of engineers in becoming application security champions. This includes using a specialised skill set to design and automate continuous security testing at all pre-deployment stages (where applicable), enable the measurement (and performance) of threat...