Senior DevSecOps Engineer

Job Overview

Location
Islamabad, Islamabad
Job Type
Full Time
Date Posted
4 hours ago

Additional Details

Job ID
2067
Job Views
14
Work Mode *
On-site

Job Description

Mountain Tech is a specialised technology firm driving high-performance to support e-commerce and logistics operations offered by Mountain Group in the UK, with technology and cybersecurity at the core of our business processes. Our Islamabad office supports UK operations by providing key technical, infrastructure, and cybersecurity capabilities.

We are looking for a Senior DevSecOps Engineer to be based in our Islamabad office, working closely with the Cyber Team Lead to secure, monitor, and enhance our systems, applications, and cloud infrastructure. This is a hands-on role focused on embedding security across all stages of our development and operational lifecycle.


Role Overview

The Senior DevSecOps Engineer will play a crucial role in bridging development, security, and operations ensuring that Mountain Group’s technology ecosystem remains secure, resilient, and compliant with UK cyber standards.

You will manage and improve security automation within CI/CD pipelines, manage cloud security posture, perform vulnerability and risk assessments, and respond to incidents in collaboration with the UK Cyber Team. You’ll also take ownership of security infrastructure in the Islamabad office, mentoring junior engineers and embedding a “security-first” culture across teams.


Key ResponsibilitiesCloud & Infrastructure Security
  • Review and secure CI/CD pipelines, integrating security controls at every stage (DevSecOps).

  • Manage secure infrastructure on Azure/GCP, implementing least-privilege IAM policies and network segmentation.

  • Review and maintain WAFs, firewalls, and VPNs to protect critical cloud workloads.



Application & Code Security

  • Review and suggest SAST, DAST, Solutions and Auto AI based Pentesting scanning into build pipelines (e.g., SonarQube, Snyk, OWASP ZAP, Burp Suite).

  • Work with developers/Support/Sysadmin teams to identify and remediate vulnerabilities early in the SDLC.

  • Implement secure secrets management (Vault, AWS Secrets Manager, or equivalent)



Security Monitoring & Incident Response

  • Review and manage SIEM and log management solutions with our MSP.

  • Investigate and respond to security incidents in collaboration with the Cyber Team Lead and Cyber Security Manager.

  • Conduct root cause analysis and implement preventive measures to strengthen incident response maturity.
  • Document and record the vulnerabilities on the Cyber Jira board following the Common Vulnerability Scoring System (CVSS v3.1)


Governance, Risk, and Compliance
  • Conduct regular vulnerability assessments and security posture reviews for systems and cloud environments.
  • Support audit and penetration testing activities with external partners.


Leadership & Collaboration
  • Mentor junior Cyber Security engineers within the Islamabad office on secure development and deployment practices.
  • Serve as the local cybersecurity focal point, coordinating with UK teams to align with corporate security strategy.
  • Promote DevSecOps culture across teams, integrating automation, visibility, and accountability into all operations.


Required Skills & Experience
  • 5+ years of experience in Cloud Infrastructure, or DevSecOps roles with a strong cybersecurity focus.
  • Proven experience with Azure, or GCP security services and compliance configurations.
  • Proficiency in Docker and Kubernetes, including security hardening and runtime protection.
  • Strong scripting and automation skills in Python, Bash, or PowerShell.
  • Hands-on experience with security tools such as Snyk, Trivy, SonarQube, OWASP ZAP, or Burp Suite.
  • Deep understanding of network security, firewall management, VPNs, and Zero Trust principles.


Preferred Qualifications
  • Professional certifications such as:
  • AWS Certified Security / DevOps Engineer
  • Microsoft Certified: DevOps Engineer Expert
  • Certified Kubernetes Security Specialist (CKS)
  • CompTIA Security+, CEH, or CISSP
  • Experience supporting distributed teams across multiple time zones.

Prior experience in e-commerce or logistics environments with high security and uptime requirements.


What We Offer
  • Competitive salary and performance-based growth opportunities.
  • Collaboration with a UK-based Cybersecurity & Infrastructure Team.
  • Opportunity to lead and shape security automation and cloud strategy.

Location

Similar Jobs

Dice Tech Recruitment Services

DevOps Engineer

Full Time

Dice Tech Recruitment Services

DevOps Engineer

Full Time

Dice Tech Recruitment Services

DevOps Engineer

Full Time

Dice Tech Recruitment Services

Junior DevOps Engineer

Full Time