DevSecOps & Infrastructure Security Engineer
NewMind AI Şişli, Marmara Region, Turkey
Software Development · 201-500 employees
About the role
The engineer will integrate security controls across CI/CD pipelines and perform security assessments for Kubernetes and OpenShift environments. They are also responsible for infrastructure hardening, managing IAM and secrets, and conducting threat modeling to ensure robust platform security.
What they look for
Requirements
Candidates must have 5+ years of professional experience in DevSecOps or infrastructure security with strong knowledge of Linux and network security. Proficiency in Kubernetes, CI/CD security practices, and vulnerability management is required, along with the ability to proactively identify and mitigate security risks.
Full description
I - Who We Are? New Mind AI is an innovative and pioneering company specializing in leveraging big data through a comprehensive and holistic approach. From data digitization and classification to deriving meaningful insights and extracting actionable outputs, we employ advanced taxonomies and ontologies to organize data in a structured and insightful manner, creating a semantic layer to better understand corporate data. Our mission extends beyond mere data structuring; we empower companies to transform their data into actionable insights, facilitating dynamic corporate governance. With over 300 task-oriented and domain-specific AI models, built using an orchestration of experts framework, we provide robust solutions for dynamic corporate governance. By implementing dynamic knowledge network structures, we develop advanced AI models that ensure effective management of corporate data in the business world. Our expertise spans AI-driven business solutions, including AI legal tech products, excelling in natural language processing, deep learning, machine learning, data analysis, and data visualization. Headquartered in YTÜ Teknopark, Maslak, Istanbul, and operating four specialized laboratories—Data Visualization Lab in India, Data Taxonomy Lab in Bomonti, and Big Data and Legal Tech Labs in Maslak—we are leaders in big data analysis in Türkiye and beyond. Our flagship dynamic knowledge management platforms, Mecellem, Malumat, and Mahfuz, empower professionals across various industries by streamlining complex tasks, optimizing decision-making, and managing business risks with precision. Through our cutting-edge AI tools, including Generative AI, LLMs, text-to-speech and speech-to-text, image recognition, voice recognition, function call, graphRAG, OCR, blockchain and RAG, we set new standards in business technology. We deliver smarter, more dynamic solutions for the business world, both in Türkiye and internationally.
II - Who We Are Looking For? We are looking for an experienced DevSecOps & Infrastructure Security Engineer to strengthen the security of our SaaS platforms, enterprise customer on-premises deployments, Kubernetes/OpenShift environments, CI/CD pipelines, and production infrastructure. The ideal candidate will have 5+ years of experience and go beyond operating security tools or merely forwarding vulnerability reports. We expect someone who can assess systems from a security perspective, proactively identify risks, propose practical solutions, and take end-to-end ownership of security initiatives. You must be comfortable challenging existing architectures when necessary, evaluating potential attack scenarios, and providing technically sound security guidance to engineering teams.
III - What Will Be Your Responsibilities? (i) DevSecOps & Secure SDLC: Integrate and continuously improve security controls across CI/CD pipelines, implement SAST, SCA, secret scanning, container/IaC scanning, and SBOM processes, and build automated security gates to prevent risks from reaching production. (ii) Kubernetes & OpenShift Security: Perform security assessments of Kubernetes/OpenShift environments, improve RBAC, Pod Security Standards, NetworkPolicy, and namespace isolation controls, and implement Policy-as-Code using tools like Kyverno or OPA Gatekeeper. (iii) Infrastructure & Network Security: Perform security hardening of Linux production systems, assess network segmentation, implement TLS/mTLS, PKI, and certificate lifecycle processes, and contribute to Zero Trust and Least Privilege architectures. (iv) IAM, PAM & Secrets: Review authentication and authorization mechanisms, integrate and operate secrets-management solutions (e.g., CyberArk, HashiCorp Vault), and implement secure secret distribution and rotation processes to prevent credential exposure. (v) SaaS & On-Premises Security: Assess SaaS environments for tenant isolation and data-access risks, evaluate blast radius and lateral-movement scenarios, and define security requirements for enterprise customer on-premises deployments. (vi) Vulnerability Management & Incident Response: Prioritize vulnerabilities based on exploitability, business impact, and compensating controls rather than just CVSS scores, investigate suspicious events, and actively participate in technical incident analysis and root-cause analysis. (vii) Security Architecture: Review new services and infrastructure designs, analyze attack surfaces and trust boundaries, participate in threat-modeling activities, and validate the actual effectiveness of implemented security controls.
IV - What Is Required from You? (i) Experience: 5+ years of professional experience in DevSecOps, Infrastructure Security, Platform Security, Cloud Security, or related fields. (ii) Technical Expertise: Strong Linux and network-security knowledge, accompanied by production experience with Kubernetes and/or OpenShift, as well as hands-on experience with CI/CD security and Secure SDLC practices. (iii) Security Knowledge: Practical experience with SAST, SCA, secret scanning, vulnerability-management processes, IAM, PAM, RBAC, TLS/mTLS, PKI, and a strong understanding of OWASP Top 10, CIS Controls, and CIS Benchmarks. (iv) Relevant Technologies: Proficiency with platforms (Kubernetes, OpenShift, Helm), DevSecOps tools (Trivy, SonarQube, Semgrep), Policy & Supply Chain (Kyverno, OPA Gatekeeper, Cosign), Runtime Security (Falco, Tetragon), IAM & Secrets (CyberArk, Vault), Automation (Ansible, Terraform), and Monitoring (Splunk/SIEM). (v) Skills: Ability to assess systems from both defensive and attacker perspectives, strong troubleshooting skills, and the capability to independently identify security risks, explain their potential impact (e.g., attack paths, affected systems), and recommend practical technical mitigations. (vi) Nice to Have: CISSP, CKS, CCSP, SSCP, Security+, or equivalent security certifications; experience with enterprise IAM/PAM, penetration-test remediation, Service Mesh / mTLS, multi-cluster Kubernetes security, or AI/ML and GPU infrastructure security.
V - Why Work at New Mind AI? New Mind AI offers a unique opportunity for ambitious young professionals seeking to make a real impact in the rapidly growing field of AI. As a company at the forefront of AI innovation, we are driven by a strong mission to empower businesses with actionable insights derived from data. This translates to a dynamic and stimulating work environment where you will be challenged to think critically, develop your skills, and contribute to groundbreaking projects. Here are some key reasons why New Mind is an ideal place for young talent: (i) be a part of something bigger: Our work goes beyond simply developing AI models. We are shaping the future of business and helping organizations navigate the complex world of data-driven decision-making; (ii) work with leading experts: You will be surrounded by a team of passionate and knowledgeable individuals who are experts in their fields. This collaborative environment fosters continuous learning and growth; (iii) gain valuable experience: You will have the opportunity to work on diverse projects, utilizing cutting-edge AI tools and technologies, including Generative AI, LLMs, and more; (iv) make a real difference: Your contributions will directly impact our company's growth and success, contributing to the advancement of AI technology and its positive impact on the world; (v) global reach: As a company with a global presence, you will be exposed to a diverse range of perspectives and opportunities to work with clients and partners from around the world; (vi) invest in your future: New Mind is committed to supporting its employees' professional development and offers opportunities for growth within the company.
Similar roles
-
Director Cybersecurity Operational Risk Oversight
Citizens Bank Johnston, Rhode Island, United States · $178K–$220K/yr
-
Senior Security Engineer, Detection & Response
Aircall.io, Inc. San Francisco, California, United States · $180K–$220K/yr
-
Senior Security Engineer (m/w/d)
Yoummday GmbH Munich, Bavaria, Germany
-
Senior Security Engineer, Cloud and Infrastructure Security
Weight Watchers United States · $210K–$225K/yr
-
Staff Security Engineer - AI Security
Qube Research & Technologies London, England, United Kingdom
-
Cybersecurity Engineer - CBO
INNOVIM United States · $90K–$107K/yr