DevSecOps Engineer
Warsaw or Remote
â ïž We'll shut down after Aug 1st - try foođŠ for all jobs in tech â ïž
SwingDev
Top-notch developers, designers and business leaders modernizing home insurance industry. We do the software the best possible way.How do we want to get there? We need a top-notch talent, just like you!Â
Putting a lot of effort into hiring top-tier professionals is a proof that we care a lot about tech experience, the attitude, human approach, and what we could call âculture fitâ.
âSwingDev is all about peopleâ - yes, it may sound a bit cliche. But whether we're writing code or just hanging out, we know that people are at the heart of everything we do. We like to have a good time and keep things light, even when we're tackling big projects. We could brag about whatâs making us special, but weâve boiled it down to two key ingredients: mature, companionable people who, rather than compete, prefer to inspire and have each otherâs backs; a culture of trust, empathy, and positivity that keeps us together, lets us interact as teammates and friends, and truly enjoy the ride.
So if you're a DevOps Engineer with a knack for security and looking to shake things up while having a good time, you've come to the right place. đ
About the role:
At Hippo, we're tackling complex challenges in engineering, data, and operations that are transforming an outdated insurance industry. As a DevSecOps Engineer, you'll play a key role in expanding our suite of products, supporting both mature offerings and new MVPs. In this role, youâll use your understanding of cybersecurity and risk management to drive security projects from concept to completion. Youâll collaborate with stakeholders to create effective security designs and protocols while securing microservices and monitoring for threats.
If youâre passionate about crafting clear security designs and protocols, driving security projects from start to finish, securing microservices, and identifying vulnerabilities in distributed systems while analyzing logs and security signals, weâd love to hear from you!
What will you do?
- In this role, youâll collaborate closely with various stakeholders, including Security Engineers, Engineering Managers, and developers to create effective security designs and protocols while securing microservices and monitoring threats. Thatâs why this position requires not just strong technical skills, but also great communication abilities, a knack for mentoring, and knowledge-sharing. Â
- Youâll be responsible for building a world-class, scalable, and resilient security infrastructure that keeps the Hippo platform safe and sound.Â
- Youâll boost developer productivity by integrating security tools and processes into our CI/CD pipelines, as well as monitoring systems and cloud environments to ensure everything runs smoothly.Â
- Youâll be using Golang, Python, and other scripting languages like Bash on a daily basis to automate security operations, build secure APIs, and develop serverless security functions.
- Youâll get to work with various cloud providers, databases, open-source tools like Terraform, Kubernetes, and Docker, and a range of security tools like CSPM, DSPM, WAF, ZTN, DAST, SAST, Vault, and more, giving you a chance to explore and enhance our security setup.Â
- Youâll be the advocate for a security-first mindset within the DevOps team and across the organization, promoting awareness and best practices related to infrastructure security.Â
- You'll be able to put your mark on the project, and you will take ownership and responsibility for what you do. This isnât a âjust keep the lights onâ role â youâll shape how things are done from the ground up.Â
- Youâll work closely with other Senior DevOps Engineers, sharing responsibility for on-call rotations and keeping the platform healthy.Â
We might be a match if youâŠ
- Have 3+ years of hands-on DevOps experience and security is an area that you understand, have skills in and are passionate about.Â
- Are skilled in Golang or Python.
- Have hands-on experience with tools like AWS, Kubernetes, Terraform, Docker, and modern CI/CD systems.Â
- Understand AWS VPC or GCP networking, including key concepts like network separation, security groups, and ACLs.Â
- Have worked with security frameworks such as OWASP, NIST, or SANS and know your way around Intrusion Detection and Prevention Systems (IDPS).Â
- Have experience securing CDN configurations and can integrate them into a broader security strategy.Â
- Can recognize and defend against common CDN attack vectors like DDoS attacks, cache poisoning, and content hijacking.Â
- Know about authentication protocols like SAML, OIDC, OAuth or similar.Â
- Are comfortable working with security logging and metrics systems to keep things running smoothly.Â
- Enjoy working in a small, focused, and highly efficient team.Â
- Have a great command of English (written & spoken). Â
- Are available in the afternoons â you'll join a Polish-American team, so you can expect afternoon meetings. Rest assured, we prioritize work-life fit, respect everyone's private lives, and donât work at night but we still must ensure that communication between the time zones is effective.
- Relevant Certifications (CCSP, CSSLP, AWS certifications, etc.)
- Experience with SOX 404(b), SOC2.Â
You will get extra points for:
Recruitment process:
- Send us your CV â it's the best way for us to get to know you.
- Meet Gabi, one of our Recruiters.
- Join PaweĆ, our Sr. DevOps Engineer, for a 60-minute technical interview.
- Have a conversation with Eli (Sr. Manager, DevOps & SRE) and Shaun (Sr. Manager, Cybersecurity).
- Catch-up with Tomek (Security & Technology Director).
- Meet on the final stage with Marcin and Alicja.
- and... welcome aboard! đ
Salary23.000 â 26.000 PLN + VAT on B2B or equivalent on the contract of employment
Basics đ Form of employment of your choosingđ Remote work & flexible working hours đ€Â Paid sick leaveđïžÂ Paid holidays
Health & Safetyđ Private medical care with dentists & orthodontists package for you and your family â€ïžÂ Group life insuranceđ§Â Psychotherapists support â free online sessions with psychologists and psychotherapists.đ€žÂ Home physiotherapyđ Multisport card & meditation apps reimbursed 50%
Working conditions & Developmentđ»Â Gear with Apple Logo and monitorđ±Â 50% reimbursement for courses, conferences, books & certificatesđșđžÂ Free access to private language lessonsđ 6 Personal Development Days & 4 Voluntary Days OffÂ
Extras you may likeđ«Â Cafeteria platform â extra âstĂłwkaâevery month to spend on whatever you want tođ§Â Nanny services for parents đŠÂ Concierge services â a personal assistant to help you to deal with your everyday mattersđź Chill room with table football & PlayStation 5đŠ Free snacks, and ice cream in the office (every day, all year round!)đ± Free Friday Lunch in the officeđ Team building events â we party together several times a year during the annual Offsite & Christmas Parties, beer after work, or our #WinterEscapeMonth workation in Cyprus
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: APIs AWS Bash CCSP CDN CI/CD Cloud CSPM CSSLP DAST DDoS DevOps DevSecOps Docker DSPM GCP Golang Intrusion detection IoT Kubernetes Microservices Monitoring NIST OWASP Python Risk management SAML SANS SAST Scripting Security strategy SOC 2 SOX Strategy Terraform Vulnerabilities
Perks/benefits: Conferences Flex hours Flex vacation Health care Home office stipend Lunch / meals Medical leave Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.