Team Lead, Devsecops

Deel Deel · Enterprise · EMEA · R&D

Deel is seeking a Team Lead for DevSecOps to manage a team responsible for building and scaling a "Security-as-Code" ecosystem. The role involves defining strategy, implementing automated guardrails using tools like OPA/Kyverno, overseeing secure cloud architectures, managing security vendors, and driving operational excellence through KPIs and incident response. The ideal candidate will have experience in security, DevOps, or infrastructure, with leadership experience and proficiency in automation, IaC, cloud security, Kubernetes, SAST/DAST/SCA, secret management, and scripting languages like Python or Go.

What you'd actually do

  1. Team Growth: Lead, mentor, and coach a team of DevSecOps engineers. Conduct performance reviews, manage career development paths, and foster a culture of high performance.
  2. Roadmap Ownership: Define the DevSecOps strategy and multi-quarter roadmap, aligning security initiatives with broader business and engineering goals.
  3. Stakeholder Management: Act as the primary point of contact for Engineering and Product leads to ensure security requirements are baked into the Product Discovery phase.
  4. Policy-as-Code: Lead the implementation of organizational guardrails using tools like OPA (Open Policy Agent) or Kyverno to ensure compliance is automated across all environments.
  5. Secure Infrastructure: Oversee the design of secure cloud architectures (AWS/Azure/GCP) and Kubernetes clusters, focusing on Zero Trust networking and identity-driven access.

Skills

Required

  • 6+ years in Security, DevOps, or Infrastructure roles
  • 2+ years in a leadership capacity (Team Lead, Tech Lead, or Engineering Manager)
  • Expert knowledge of Terraform/OpenTofu, Ansible, and CI/CD platforms (GitHub Actions, GitLab CI)
  • Deep understanding of Kubernetes security (RBAC, Network Policies, Admission Controllers) and cloud provider security services
  • Experience implementing and tuning SAST, DAST, SCA, and Secret Management (HashiCorp Vault) at scale
  • Proficiency in Python, Go, or TypeScript to build custom internal security tooling and integrations
  • Pragmatism: Ability to balance "perfect security" with the "speed of business."
  • Communication: Exceptional ability to translate complex technical risks into business impact for executive stakeholders.

What the JD emphasized

  • Security-as-Code
  • automated guardrails
  • self-service security tools
  • expert architectural guidance
  • Policy-as-Code
  • OPA (Open Policy Agent)
  • Kyverno
  • Zero Trust networking
  • Mean Time to Remediate (MTTR)
  • SAST, DAST, SCA
  • Secret Management
  • HashiCorp Vault