Sr. Devsecops Engineer- Reliability & Security (remote From Bulgaria)

Smartsheet Smartsheet · Seattle · Bulgaria · Engineering - Developers

Senior DevSecOps Engineer focused on engineering secure and resilient infrastructure, automating security processes, securing CI/CD pipelines, managing container security, leading incident response, and driving automated compliance in a multi-cloud environment.

What you'd actually do

  1. Design, build, maintain, and improve secure, scalable, and highly available infrastructure in our multi-cloud environment (primarily AWS) using Infrastructure as Code (IaC) principles with tools like Terraform, Kubernetes, and Helm.
  2. Engineer and automate threat detection, incident response, and vulnerability management processes. You will build the tools and workflows that allow us to respond to threats at machine speed.
  3. Architect and secure our CI/CD pipelines, integrating automated security tooling (SAST, DAST, SCA) to provide developers with fast, actionable feedback.
  4. Manage, operate, and secure our container orchestration platform (Kubernetes), implementing best practices for container security from the registry to runtime, including knowledge of hardening requirements such as CIS Benchmarks or DISA STIG.
  5. Act as a technical lead during security and reliability incidents, driving resolution and conducting blameless post-mortems to engineer preventative solutions.

Skills

Required

  • 8+ years of progressive experience in technology, with at least 5 years in a hands-on senior role such as Site Reliability Engineering, DevOps, or Security Engineering.
  • BS or MS in Computer Science, Engineering, or a related field, or equivalent industry experience.
  • Expert-level proficiency in at least one major cloud provider, preferably AWS, with deep knowledge of core infrastructure and security services.
  • Expert-level proficiency with Infrastructure as Code, particularly Terraform.
  • Expert-level proficiency in a scripting or programming language such as Python, Go, or Ruby, with a proven history of building automation and custom tooling.
  • Deep experience with containerization and orchestration technologies (Kubernetes), including securing containerized environments.
  • Proficiency with the modern security operations toolchain, including SIEM, EDR, and vulnerability scanning technologies.
  • Experience integrating security tools (SAST, DAST, SCA) into CI/CD pipelines.
  • A critical thinker with a proven ability to troubleshoot complex problems in high-pressure production environments.
  • Excellent verbal and written communication skills and a collaborative spirit.
  • Fluency in English is required
  • Legally eligible to work in Bulgaria on an ongoing basis

Nice to have

  • Advanced industry certifications such as CISSP, CISM, OSCP, or cloud-specific security certifications.
  • Experience with compliance frameworks like FedRAMP, ISO27001, SOC2.

What the JD emphasized

  • critical role
  • security and reliability posture
  • highly reliable, scalable, and defensible production environment
  • security and reliability incidents
  • continuous compliance