DevOps Engineer (Security Focus)
Description
We're looking for a DevOps Engineer with a strong security orientation to join our DevOps team at Fiverr.
Fiverr's platform operates at a significant scale, and our DevOps team is at the heart of keeping it fast, reliable, and secure. As we grow, so does the scope of our security responsibilities โ and we need an engineer who can take ownership of that domain while being a full contributing member of the team.
In this role, you'll drive security-focused initiatives across our cloud infrastructure, Kubernetes environments, and CI/CD pipelines โ from IAM hardening and secrets management to supply chain security and cloud posture. At the same time, you'll take part in core DevOps work: building scalable systems, improving platform resilience, and supporting Fiverr's continued growth.
You'll work closely with our Security team and other engineering stakeholders, and be part of our on-call rotation โ meaning you'll have both the context and the accountability that comes with owning production.
This is a hands-on role for an engineer who takes security seriously, moves fast, and knows how to get things done in a complex, high-scale environment.
Fiverr's Technology Stack:
AWS, GCP, CLoudFlare ,Kubernetes, Terragrunt, Ansible, Jenkins, ArgoCD, Argo Workflows, Kong & Nginx, HashiCorp Vault, Kafka, RabbitMQ, Mongodb, Aurora Postgresql & Mysql, Prometheus, Grafana, VictoriaMetrics
Programming languages: Python, NodeJS, Go, Kotlin
What am I going to do?
-
Infrastructure & IaC Security: Define and implement security best practices for Infrastructure as Code (Terraform, Terragrunt, Ansible) โ including static analysis, misconfiguration detection, and compliance validation.
-
Container & Kubernetes Security: Implement and operate security controls for our containerized environments โ secure image management, runtime protection, and policy enforcement across our Kubernetes clusters.
-
CI/CD Security: Design and maintain secure CI/CD pipelines (CircleCI, ArgoCD) with automated security testing integrated across Fiverr's services and deployment workflows.
-
Secrets Management: Own the design and operation of secrets management practices across the platform โ including Vault administration, rotation policies, and dynamic secrets integration.
-
Security Automation: Automate vulnerability scanning, compliance auditing, configuration checks, and remediation workflows to keep our security posture proactive rather than reactive.
-
Cloud Infrastructure: Build and maintain large-scale, highly available cloud infrastructure on AWS with a focus on Kubernetes โ improving resiliency, reliability, and cost efficiency.
-
Collaboration: Partner with the Security team, development teams, and other stakeholders to embed security into the full development lifecycle and drive cross-team initiatives.
-
Incident Response: Own your on-call shifts as part of the DevOps rotation, maintaining Fiverr's platform availability and contributing to security incident investigations when needed.
-
Tooling & Innovation: Continuously evaluate and adopt tools โ security and otherwise โ that raise the bar on engineering efficiency and security posture at Fiverr.
Requirements
- 4+ years of experience as a DevOps Engineer with hands-on security responsibilities, or equivalent DevSecOps experience.
- Production experience with AWS and Kubernetes, including securing cloud-native environments at scale.
- AI tooling experience - Claude Code, Cursor, etc. Writing skills, agents.
- 2+ years of experience with CI/CD pipelines (CircleCI or equivalent), including integrating automated security testing.
- Experience with IaC tools (Terraform, Terragrunt) and securing IaC workflows.
- Experience with AWS security services and practices (IAM, KMS, GuardDuty, CloudTrail) โ experience with CSPM platforms an advantage.
- Strong knowledge of networking and network security concepts (Load Balancers, DNS, VPC, Security Groups, WAF).
- Experie