Standard/Senior DevSecOps Engineer

Sofiya, Bulgaria (Hybrid)

The world of global advisory, audit and tax compliance services for large multi-nationals is rapidly changing and heavily dependent on technology.    

The KPMG Delivery Network (KDN) is a KPMG special purpose member firm offering a way for clients to leverage KPMG top talent and technology platforms through regional teams of specialists, enabling economies of scale and a new way of working that expands beyond local capability

Together with KDN, KPMG member firms can drive the sales and delivery of global solutions at a competitive price and in a repeatable and consistent manner. As a member of KDN, you’ll be a part of the KPMG family working alongside some of our profession’s most skilled practitioners on rewarding programs and initiatives that are changing the way business operates, delivering value to our clients, and driving positive change in the communities we serve.

You’ll be enabling KDN accelerate new ways of working, using cutting-edge technology and working together with our member firms located in nearly 150 countries to help us achieve our ambition to be the most trusted and trustworthy professional services firm. 

And through your work, you’ll build a global network and unlock opportunities that you may not have thought possible with access to great support, vast resources, and an inclusive, supportive environment to help you reach your full potential.

Your Responsibilities

  • Manage and secure infrastructure, CI/CD pipelines, and cloud deployments.
  • Build and maintain automated, secure deployment pipelines using Terraform, Azure DevOps, and GitHub.
  • Integrate security checks—such as vulnerability scanning, policy enforcement, and compliance validation—into build and release workflows.
  • Collaborate with engineering and security teams to identify, fix, and prevent issues across applications and infrastructure.
  • Lead secure coding practices and provide hands-on guidance to developers using languages like C#, ASP.NET, TypeScript, and Angular.
  • Perform threat modeling and analyze vulnerabilities such as SQL Injection, XSS, and session mismanagement.
  • Design and run automated security testing using tools such as GitHub Advanced Security and Fortify On-Demand.
  • Conduct code reviews and provide architectural advice to improve application security and reliability.
  • Document processes and recommend improvements for security, performance, and maintainability.

What You Bring in

  • Proven experience in DevSecOps, DevOps, or Application Security roles.
  • Strong knowledge of Azure Cloud, Azure DevOps, and GitHub.
  • GitHub and Microsoft certifications preferred: GitHub Advanced Security and Microsoft SC path.
  • Practical experience with Terraform, CI/CD automation, and integrating security tools into pipelines.
  • Solid understanding of secure development practices and common vulnerabilities.
  • Experience with security scanning tools (Snyk, Trivy, Checkov, Fortify, Qualys, or similar).
  • Proficiency in scripting languages
  • Ability to work across teams and communicate clearly with developers, architects, and security professionals.
  • Bachelor’s degree in Computer Science or equivalent experience.
  • Fluent in English.


What we offer:

  • The chance to work in a top talent team
  • Attractive remuneration
  • Build knowledge in cutting-edge technologies
  • Opportunity for continuous training, learning and certification
  • Experience in an international and multicultural organization
  • Work on challenging projects with clients in various industries around the globe
  • Modern office environment
  • Additional health insurance
  • Life insurance
  • 50+ benefits and services to choose from
  • Hybrid working policy

Standard/Senior DevSecOps Engineer

Job description

Standard/Senior DevSecOps Engineer

Personal information
Details