Senior DevSecOps Engineer at Heirs Insurance Ltd

Senior DevSecOps Engineer at Heirs Insurance Ltd

Senior DevSecOps Engineer at Heirs Insurance Ltd: Building the Future of Secure Insurance

Heirs Insurance Ltd is redefining the insurance landscape in Africa, challenging traditional models with innovative, accessible protection for vehicles, homes, businesses, and more. At the heart of this transformation is a robust, secure, and agile technology platform. We are seeking a highly skilled and passionate Senior DevSecOps Engineer to be a pivotal part of this journey, ensuring that every piece of code ships not just fast, but safely and reliably.

The Core of the Role: Builder, Operator, and Guardian

As our Senior DevSecOps Engineer, you are more than just an engineer; you are the architect and guardian of our development lifecycle. You will design, implement, and own the critical pipelines, tooling, and stringent security controls that empower every engineer on our platform to deliver value swiftly and securely. Your domain spans the entire journey from a developer's workstation to live production, encompassing:

  • CI/CD Pipeline Design & Ownership: You will own the full lifecycle of our CI/CD infrastructure, ensuring every service across all teams is deployed exclusively through automated, version-controlled pipelines. This includes building and maintaining pipelines across GitHub Actions, Azure DevOps Pipelines, GitLab CI, and Jenkins, with an unwavering commitment to reproducibility, auditability, and speed.
  • Pipeline Quality Gates: Embed security, quality, and performance validation into every stage. You will implement and operate mandatory, automated gates including SAST, DAST, SCA, and secrets detection for security; automated test coverage thresholds, integration, and end-to-end tests for quality; and load testing/performance benchmarks. Integrating AI-powered code review and testing agents will further enhance early detection and human review.
  • Container Build & Supply Chain Security: Take full ownership of the container build pipeline, from base image governance to final image publication. You will enforce the use of approved, minimal base images, integrate container image scanning (Trivy) and dependency vulnerability scanning (Snyk), and maintain a Software Bill of Materials (SBOM) for continuous supply chain integrity.
  • Infrastructure as Code (IaC) Pipeline Integration: Integrate all infrastructure provisioning workflows (Terraform, Ansible, Bash) into version-controlled, automated pipelines. This includes enforcing IaC security scanning and policy checks, ensuring no cloud or network configuration is provisioned outside of a pipeline-controlled workflow.
  • Environment Management & Dev Containers: Define and own the platform's environment strategy, ensuring dev, staging, and production environments are consistently defined, reproducible, and provisioned on demand via IaC. You will enforce the use of dev containers to standardize development environments, eliminating environment drift and snowflake configurations.
  • Secrets Management Integration: Integrate Azure Key Vault and AWS Secrets Manager (or equivalents) into all CI/CD pipelines and application deployment workflows. Enforce secret rotation schedules and ensure no sensitive data is ever hardcoded, triggering automated alerts and mandatory rotations upon violation.
  • Observability & DORA Metrics: Instrument all CI/CD pipelines to track, baseline, and continuously improve engineering performance. You will own the collection and reporting of DORA metrics (deployment frequency, lead time for changes, change failure rate, and MTTR), using this data to drive targeted pipeline improvements.
  • Developer Experience & Standards: Champion the developer experience by making the secure and correct way the easiest way. You will own developer tooling, onboarding documentation, and pipeline standards, reducing friction while upholding security and quality. Collaborating with the DevSecOps Evangelist, you will educate teams, flag anti-patterns, and ensure broad adoption of best practices.
  • Runtime Security: Implement and operate runtime security controls for containerized workloads, utilizing tools like Falco for threat detection and policy enforcement. You'll ensure anomalous behavior triggers automated alerts and work with the security team to continuously refine detection rules.
  • Incident & Rollback Support: Maintain robust, tested rollback and re-deployment capabilities. You will be a key technical resource during platform incidents, diagnosing failures, executing rollbacks, and restoring stability, ensuring all pipeline runbooks are documented, version-controlled, and regularly tested.

What We're Looking For in Our Next DevSecOps Leader

Must-Have Qualifications:

  • Experience: 4+ years of hands-on DevSecOps or DevOps engineering experience, with a proven track record of owning CI/CD pipelines in a production, cloud-native environment.
  • CI/CD Expertise: Expert-level experience with GitHub Actions, Azure DevOps Pipelines, GitLab CI, or Jenkins, including the ability to design, debug, and optimize complex pipeline workflows.
  • Security Tooling Integration: Hands-on experience integrating security tooling into CI/CD pipelines (SAST, DAST, SCA, secrets detection), with a deep understanding of each gate's purpose.
  • Container Security: Strong knowledge of Docker image builds, base image governance, image scanning (Trivy or equivalent), and supply chain security (Snyk or equivalent).
  • Infrastructure as Code: Solid experience with Terraform, Ansible, and Bash, emphasizing automated, version-controlled infrastructure provisioning.
  • Container Orchestration: Hands-on experience with Kubernetes on managed services (AKS, EKS) or serverless container platforms (Azure Container Apps, AWS App Runner / ECS Fargate).
  • Secrets Management: Working knowledge of Azure Key Vault, AWS Secrets Manager, or equivalent, and experience integrating them into CI/CD workflows.

Nice-to-Have Qualifications:

  • Experience with runtime security tooling, particularly Falco for container threat detection.
  • Familiarity with DORA metrics tooling and using performance data to drive pipeline improvements.
  • Experience with serverless compute platforms (Azure Functions and/or AWS Lambda) for event-driven triggers or automation.
  • AWS and/or Microsoft Azure certification (Developer, DevOps, or Solutions Architect tracks).
  • Experience in fintech, banking, or other regulated environments, with knowledge of PCI DSS pipeline security requirements or CBN guidelines.
  • Familiarity with Software Bill of Materials (SBOM) tooling and supply chain security frameworks (e.g., SLSA, NIST SSDF).

If you are a proactive problem-solver with a passion for building secure, efficient, and scalable development environments, and you thrive in a challenging, fast-paced atmosphere, we encourage you to apply. Join Heirs Insurance Ltd and help us build the next generation of secure financial services!

Method of Application: Interested and qualified? Go to Heirs Insurance Ltd on heirs-technologies.breezy.hr to apply

Similar Opportunities

Channel Account Executive at Sophos
Tech

Channel Account Executive at Sophos

Empowering Cybersecurity Through Simplicity: Join Sophos as a Channel Account ExecutiveIT security p...

7/27/2026
Compression Machine Operator at Shalina Healthcare
Tech

Compression Machine Operator at Shalina Healthcare

Build a Rewarding Career with Shalina Healthcare as a Compression Machine OperatorShalina Healthcare...

7/27/2026
Sales Representative at SellOkay
Tech

Sales Representative at SellOkay

Unlock Your Sales Potential with SellOkay in Port Harcourt!Are you a driven, customer-focused profes...

7/26/2026
AI Engineer at Tezza Business Solutions Ltd
Tech

AI Engineer at Tezza Business Solutions Ltd

Unlock Your Potential as an AI Engineer at Tezza Business Solutions Ltd Tezza (derived from the Ital...

7/26/2026
Mid-Level NetSuite Developer at Tezza Business Solutions Ltd
Tech

Mid-Level NetSuite Developer at Tezza Business Solutions Ltd

Empower Your Career with Tezza Business Solutions LtdTezza (derived from the Italian word 'Completez...

7/26/2026
Graphic Designer at Tezza Business Solutions Ltd
Tech

Graphic Designer at Tezza Business Solutions Ltd

Unlock Your Creative Potential as a Graphic Designer at Tezza Business Solutions LtdAre you a passio...

7/26/2026
Frontend Developer (Angular / React) at Tezza Business Solutions Ltd
Tech

Frontend Developer (Angular / React) at Tezza Business Solutions Ltd

Build the Future of Digital Solutions: Frontend Developer at Tezza Business Solutions LtdTezza (te-z...

7/26/2026
Backend Developer (Node.js / Java) at Tezza Business Solutions Ltd
Tech

Backend Developer (Node.js / Java) at Tezza Business Solutions Ltd

Unlock Your Potential as a Backend Developer at Tezza Business Solutions Ltd At Tezza Business Solut...

7/26/2026
HR Officer (Generalist) at Nicole Sinclair Consulting
Tech

HR Officer (Generalist) at Nicole Sinclair Consulting

Unlock Your Career Potential as an HR Officer (Generalist) at Nicole Sinclair ConsultingAre you an e...

7/26/2026
Robotics Instructor at Kindercrest School
Tech

Robotics Instructor at Kindercrest School

Inspiring Young Minds: Become a Robotics Instructor at Kindercrest SchoolAre you passionate about te...

7/26/2026