JJobsSonar

Lead DevSecOps Engineer

Liquid Thought · Cape Town, Western Cape, South Africa

DevOpsHybrid

About this role

The Lead DevSecOps Engineer will own the security infrastructure and drive a proactive security culture across the business. This role involves transforming the SIEM platform into a Security Nerve Centre, building automated threat response systems, implementing rate-limiting strategies, and integrating security insights into CI/CD pipelines. The role also includes mentoring junior SecOps team members and evolving their practices toward proactive security. The individual will work within a lean, high-performing fintech team that combines the agility of a startup with the rigour of a regulated financial services environment.

Skills & technologies

Must have

  • AWS
  • Heroku
  • IaC
  • VPCs
  • EC2
  • Auto Scaling
  • Load Balancers
  • CloudFront
  • ECS
  • Sumo Logic
  • CrowdStrike
  • Snyk
  • Dependabot
  • AWS WAF
  • Cloudflare
  • CI/CD
  • DevSecOps
  • Cloud Security
  • Systems Engineering

Nice to have

  • Angular
  • React
  • Ruby on Rails

Read full description

About the job Location: Cape Town (Hybrid) Our client is a well-established and fast-growing fintech company operating in the payments space. With a lean, high-performing team of just over 50 people, they punch well above their weight, combining the agility of a startup with the rigour of a regulated financial services environment. They are looking for a hands-on Lead DevSecOps Engineer to own their security infrastructure and drive a proactive security culture across the business. The Role This is a builder's role, not a vendor management position. You will serve as the primary security architect, unifying a defence-in-depth strategy and moving the organisation away from reactive compliance toward genuine system resilience. The split is approximately 80% deep technical architecture and 20% team leadership, with dedicated mentorship support for your growth in people management. Key Responsibilities Transform the SIEM platform into a true Security Nerve Centre, moving beyond log ingestion into Detection Engineering, with intelligent dashboards that baseline normal API behaviour Build automated threat response systems that trigger on unusual payloads or IOCs, rather than relying on manual next-day alerts Implement a standardised rate-limiting strategy across all endpoints and lead Chaos Engineering exercises to simulate DDoS and heavy load scenarios Shift security left by integrating vulnerability and intrusion detection insights directly into CI/CD pipelines using Policy-as-Code Security Gates, if a vulnerable configuration or dependency is introduced, the build fails automatically Mentor junior SecOps team members, evolving them beyond manual PCI audits toward proactive, technically deep security practice What You Bring A degree in Computer Science, Engineering, or a related technical field 10+ years of hands-on experience in DevSecOps, Cloud Security, or Systems Engineering Deep expertise in AWS and Heroku, with strong IaC experience Solid knowledge of AWS networking and compute: VPCs, EC2, Auto Scaling, Load Balancers, CloudFront, ECS Hands-on experience with security tooling such as Sumo Logic, CrowdStrike, Snyk, Dependabot, AWS WAF, or Cloudflare A startup mindset, comfortable working across the stack and making decisions in ambiguity Familiarity with Angular/React and Ruby on Rails is a bonus What's On Offer Competitive salary + discretionary annual bonus 30 days annual leave + 3 mental health days Medical aid contribution of up to R2,000/month Apple MacBook and necessary equipment Flexible hybrid working, you choose office or remote based on what makes sense Paid parking when in office A genuinely great team and culture
Ready to apply?Apply now

Similar DevOps jobs

All DevOps jobs