Dev SecOps Engineer at AP MAX INC
, , Portugal -
Full Time


Start Date

Immediate

Expiry Date

19 Jun, 26

Salary

0.0

Posted On

21 Mar, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

CI/CD Security Controls, SAST, DAST, SCA, Container Scanning, Secrets Management, Terraform, Infrastructure as Code, Vulnerability Scanning, Compliance Workflows, Application Security, Container Security, GitHub Actions, Google Cloud Platform (GCP), GRC Alignment, Change Management Evidence

Industry

Retail Pharmacies

Description
Company Overview At Allia Health Group, the umbrella organization for Southend Pharmacy, Brello Health, and Woven, we don’t just follow industry trends—we redefine them. Our mission is to commoditize anti-aging solutions, making them affordable and accessible to the average consumer—not just the wealthy. By offering customized and cost-effective wellness products that follow cost-containment models, we aim to improve people’s quality of life and meet them wherever they are on their health journey. Job Summary The DevSecOps Engineer is responsible for integrating security into CI/CD pipelines and cloud infrastructure to ensure secure, scalable, and compliant systems. This role focuses on implementing security controls, managing secrets, and automating compliance processes across environments. The ideal candidate is highly technical, security-focused, and experienced in cloud-native environments with a strong understanding of modern DevSecOps practices. Key Responsibilities * Implement CI/CD security controls including SAST, DAST, SCA, and container scanning * Manage secrets lifecycle using cloud-native tools * Build and maintain infrastructure security controls using Terraform * Generate audit-ready change management evidenceIntegrate vulnerability scanning into compliance workflows * Enforce secure development practices and pipeline protections * Collaborate with GRC teams to align technical controls with compliance requirements What We Require * Minimum 3+ years of experience in DevOps, DevSecOps, or platform engineering * Experience with cloud platforms such as Google Cloud Platform (GCP) * Strong experience with CI/CD tools such as GitHub Actions * Hands-on experience with Terraform and infrastructure as code * Knowledge of application security and container security tools * Familiarity with SOC 2 or similar compliance frameworks Preferred Requirement * Experience with compliance platforms such as Drata or similar tools * Knowledge of HIPAA technical safeguards * Experience with policy-as-code tools * Relevant cloud or security certifications What We Offer * Full benefits package including medical, vision, dental, 401(k) with company match, PTO, Flex days, holidays, and more * Working in Madeira in a shared office space, remote in Portugal, or remote in a Portuguese timezone-friendly location * Opportunity to build security-first infrastructure and systems * High-impact role within a growing technology organization * Benefits package designed to meet local market standards and legal requirements. This may include health coverage, paid time off, holidays, and retirement contributions, depending on your location. Equal Opportunity Employer Statement Allia Health Group is proud to be an Equal Opportunity Employer where we are committed to fostering a diverse and inclusive workplace. We are committed to cultivating a culture where all team members feel valued & respected. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetic information, disability, age, veteran status, or any other characteristics protected by applicable law. If you have any questions or require immediate assistance or accommodations during the application or interview process, please contact us at recruiting@alliahealth.co.
Responsibilities
The DevSecOps Engineer will be responsible for integrating security into CI/CD pipelines and cloud infrastructure to ensure systems are secure, scalable, and compliant. This involves implementing security controls, managing secrets, and automating compliance processes across various environments.
Loading...