Senior DevSecOps Engineer
*Level:* Senior (7+ years)
*Location:* Konecta MEA HQ in Cairo (Hyprid Model), with travel to client locations as required
*Engagement:* Client-facing, embedded with Customer delivery teams
## Role Summary
We want to hire a Senior DevSecOps Engineer to design, build and operate end-to-end delivery pipelines for one of our our Customer engagement. This is not a heads-down build role. It is a client-facing role, which requires you to walk senior technical and non-technical stakeholders through what you have built, and defend your design decisions against industry best practice.
The successful candidate combines deep hands-on capability — GitLab CI/CD, Kubernetes, containerisation, security-in-pipeline — with the communication skill to explain why an implementation looks the way it does, in clear, confident English, to an audience that may not share your technical depth.
## What You'll Do
### Pipeline engineering (GitLab CI/CD)
-
Design, build and maintain GitLab CI/CD pipelines covering the full path to production: build → test → scan → package → deploy → verify.
-
Author reusable pipeline components, templates and shared libraries so patterns scale across teams rather than being rebuilt per repo.
-
Manage GitLab Runners (Kubernetes executor), caching, artefact strategy and pipeline performance — keep feedback loops short.
-
Implement quality and security gates: SAST, DAST, dependency/SCA scanning, container image scanning, secret detection, licence compliance.
### Kubernetes & deployment
-
Own deployment into Kubernetes clusters end to end — not just handing off an artefact.
-
Package and deploy workloads using Helm and/or Kustomize; implement GitOps delivery (ArgoCD or Flux) where appropriate.
-
Configure the operational surface of a workload properly: resource requests/limits, probes, HPA, PodDisruptionBudgets, RBAC, NetworkPolicies, securityContext and Pod Security Standards.
-
Implement progressive delivery — blue/green, canary, rollback strategy — and be able to explain the trade-offs of each.
-
Troubleshoot cluster and workload issues: CrashLoopBackOff, scheduling failures, image pull problems, resource pressure, ingress/DNS/service-mesh issues.
### Containerisation
-
Build secure, efficient container images: multi-stage builds, minimal/distroless base images, non-root users, correct layer caching, small attack surface.
-
Establish and enforce image standards — base image governance, tagging and versioning strategy, registry hygiene, vulnerability remediation SLAs.
-
Generate and manage SBOMs; drive image signing and provenance (Cosign / Sigstore, SLSA-aligned) where the client requires supply-chain assurance.
### Security integrated into delivery
-
Shift security left: make the secure path the easy path, embedded in the pipeline rather than bolted on at the end.
-
Implement secrets management (HashiCorp Vault, External Secrets Operator, or cloud-native equivalents) — no secrets in repos, images or CI variables where avoidable.
-
Apply policy-as-code (OPA/Gatekeeper, Kyverno) and infrastructure scanning (Checkov, Trivy, tfsec).
-
Work within regulated-industry controls: separation of duties, auditability, change evidence, least privilege.
### Client-facing communication (core to this role)
-
Present designs, options and trade-offs to all stakeholders — engineers, architects, security teams and management — with clarity and confidence.
-
Justify every implementation decision against recognised best practice: explain what you chose, what you rejected, and why.
-
Run walkthroughs, demos, working sessions and knowledge-transfer with client teams.
-
Translate between technical detail and business impact — cost, risk, delivery velocity, compliance posture.
-
Handle challenge and pushback constructively; adapt the design when the client raises a valid constraint, and hold the line with evidence when they don't.
### Documentation & delivery governance
-
Produce and maintain high-quality documentation in Confluence: architecture decision records (ADRs), runbooks, onboarding guides, pipeline reference docs, troubleshooting playbooks.
-
Treat documentation as a first-class deliverable — accurate, current, and written for the reader who wasn't in the room.
-
Manage work transparently in Jira: well-formed stories, clear acceptance criteria, accurate status, useful updates for stakeholders.
-
Contribute to sprint ceremonies, estimation and delivery reporting.
## Essential Requirements
*Experience*
-
6–10 years in DevOps / Platform / DevSecOps engineering, with meaningful time spent owning production delivery pipelines.
-
Demonstrable experience in a client-facing or consulting-style role.
*Technical*
-
*GitLab CI/CD* — expert level. Pipeline architecture, templates, runners, optimisation. (Strong Jenkins/GitHub Actions/Azure DevOps background with willingness to go deep on GitLab may be considered.)
-
*Kubernetes* — strong practical depth, beyond "I've applied a manifest". Comfortable debugging a live cluster.
-
*Containerisation* — Docker/OCI, image security and optimisation, registry management.
-
*Helm* and templating/packaging of workloads.
-
*Infrastructure as Code* — Terraform (or equivalent).
-
*Scripting* — Bash plus one of Python / Go.
-
*Git* — branching strategy, merge/release workflows, code review discipline.
-
*Cloud* — hands-on with at least one major provider (AWS / Azure / GCP), including IAM, networking and managed Kubernetes.
-
*Security tooling in CI* — SAST/DAST/SCA, container scanning, secrets management.
*Communication*
-
Excellent spoken and written English — this is a hard requirement, not a nice-to-have.
-
Able to present to and hold a room with senior stakeholders.
-
Structured, evidence-based reasoning; can articulate the rationale behind a design and defend it under scrutiny.
*Ways of working*
-
Confluence and Jira as daily tools, used well.
-
Self-directed, comfortable with remote-first delivery and asynchronous collaboration.
-
Willing and able to travel to client locations when required.
## Desirable
-
*Agentic / AI-assisted development* — practical use of GitHub Copilot CLI, Claude Code or similar agentic tooling to accelerate engineering work, with sound judgement about where AI assistance is and isn't appropriate.
-
GitOps at scale — ArgoCD or Flux.
-
Observability — Prometheus, Grafana, OpenTelemetry, ELK/Loki; defining SLOs and meaningful alerting.
-
Service mesh (Istio, Linkerd) and advanced ingress/traffic management.
-
Financial services, capital markets or other regulated-industry experience; familiarity with the control expectations that come with it.
-
Supply-chain security — SLSA, SBOM, artefact signing and provenance.
-
Certifications — CKA / CKAD / CKS, cloud architect or security certifications, GitLab certifications.
-
Experience running platform enablement or internal developer platform (IDP) initiatives — Backstage or similar.
-
FinOps awareness — cost-conscious pipeline and cluster design.
-
DR/BCP, backup and restore design for stateful workloads on Kubernetes.