Your mission
Well, we keep the world of machinery moving.
How? By connecting supply chains and harnessing the power of data in a never seen way. We believe that the flow of goods depends on the flow of data, which is why we connect thousands of machine manufacturers and dealers and bazillions of machines on our platform, centralize their aftersales relevant data and make sure parts and services are available whenever, and wherever they're needed.
ClearOps is looking for a DevSecOps Engineer to strengthen our growing team. You’ll work closely with DevOps, development, and compliance to ensure that our platform remains secure, reliable, and compliant as we scale. In this role, you’ll drive security initiatives across infrastructure, applications, and culture — building trust with clients and empowering teams to deliver safely.
Responsibilities:
ISO 27001 & Compliance
- Operate and maintain our Information Security Management System (ISMS)
- Own and update security documentation: policies, risk register, SoA, incident reports, audits
- Coordinate audits, risk assessments, and corrective actions
- Support Sales, HR, and Ops with client assessments and security-related processes
- Collaborate with engineers to design and ship secure applications (Java/Kotlin/Spring Boot, React/TypeScript)
- Perform design and code reviews to identify security risks
- Champion best practices for authentication, authorization, and data protection
- Secure our AWS environment (IAM, S3, RDS, EC2, logging, alerting, AI-driven systems)
- Improve and maintain security in CI/CD pipelines
- Review and harden infrastructure as code (Terraform, Ansible)
- Operate SecOps and compliance tools (Drata, Aikido, ElasticSearch SIEM, AWS Security Hub, AWS Inspector, AWS CloudTrail, and more)
Culture & Training
- Lead security awareness training across the company
- Educate developers to integrate security without slowing them down
- Represent ClearOps security in client and internal discussions