DevSecOps Engineer
Leaf Space is looking for a DevSecOps Engineer. You'll design, implement and continuously improve our CI/CD pipelines, cloud and infrastructure environment, embedding security at every stage.
DevSecOps Engineer
About Leaf Space
Leaf Space is a rapidly growing scale-up company and a leading provider of ground segment as-a-service (GSaaS) solutions. Our innovative and proprietary concept is focused on providing satellite and launch vehicle connectivity as-a-service, enabling clients to efficiently manage their assets and fully exploit data. Our GSaaS solutions have been recognized by the market for their efficiency, security, and effectiveness in supporting different applications, from remote sensing to IoT communications.
JOB OVERVIEW
We're building a satellite-based mesh network, and the software and infrastructure behind it — ground segment services, network orchestration, telemetry pipelines, and embedded flight/payload software tooling — need to be shipped fast and run securely. As DevSecOps Engineer you will design, implement and continuously improve the CI/CD, cloud and infrastructure environment, contribute directly to software development across the stack, and build security into every stage rather than bolting it on at the end. This is a hands-on role spanning development, operations, and security for systems that are both mission-critical and subject to strict regulatory obligations.
RESPONSIBILITIES
Design, build, and maintain CI/CD pipelines for ground-segment, network, and embedded software, with automated testing, security scanning, and controlled release gates.
Contribute to automation tooling and software development supporting the platform and infrastructure.
Collaborate with embedded software teams to support build toolchains, cross-compilation and integration workflows.
Manage cloud and on-prem infrastructure as code (Terraform, Ansible, or equivalent) with reproducible, auditable deployments.
Operate and secure containerized and orchestrated workloads (Docker, Kubernetes), including image hardening, registry scanning, and runtime security.
Implement observability — logging, metrics, tracing, and alerting — for reliable, debuggable production systems.
Harden systems and enforce access control, network segmentation, and least-privilege principles across environments.
Support compliance and audit readiness against frameworks relevant to critical infrastructure (e.g., NIS2, ISO 27001), contributing to policies, controls, and evidence.
Contribute to incident response, patch management, and secure configuration baselines.
Partner with software, network, and mission teams
QUALIFICATIONS AND STUDIES
Degree in computer science, engineering, or equivalent practical experience.
Roughly 3–6 years in DevOps, SRE, platform, security, or software engineering roles.
REQUIREMENTS
Tech skills
Strong Linux knowledge (required) — administration, networking, and development on Linux systems.
Solid software development skills, with experience writing production code (Python, Go, C/C++, Rust or similar).
Familiarity with embedded software development environments is considered a plus.
Strong hands-on skills with CI/CD tooling (GitLab CI, GitHub Actions, Jenkins, or similar) and infrastructure as code.
Solid networking and cloud fundamentals (AWS, GCP, or Azure).
Practical experience integrating security tooling into pipelines and a genuine security mindset.
Clear communicator who can work across development, operations, and security.
Soft skills
Excellent cross-functional communication skills to interface effectively with engineering teams, suppliers and management.
Ability to translate ambiguous or evolving requirements into concrete, actionable specifications.
Rigorous, detail-oriented approach, with a preference for measured/verified data over assumptions, and transparency when prior estimates need correction.
Comfortable working in a fast-moving, still-maturing product environment, iterating on both architecture and hands-on implementation.
Fluent English (written and spoken) required, given interaction with external international partners.
WHAT WE OFFER
A flat and collaborative organizational structure
A fast‑paced and professional environment within a rapidly growing space scale‑up
Challenging projects with real impact on the global space ecosystem
An international and diverse workplace
Comprehensive benefits package, including a welfare platform, meal vouchers, a hybrid work policy supporting work-life balance, and training opportunities
COMPENSATION & TRANSPARENCY:
Reports to: Head of Engineering
Career level: P4 – Senior Professional
Job location: Lomazzo (Como), Italy | Hybrid work model
Salary range: 45-70K
Variable compensation: 10% of annual gross salary
Benefits: Competitive benefits package, including a welfare platform and meal vouchers in Italy, with equivalent local benefits provided where applicable
Expected start date: 1.10.2026
- Department
- Engineering
- Locations
- Leaf Space
- Remote status
- Hybrid
- Yearly salary
- 45,000 - 70,000
- Employment type
- Full-time
About Leaf Space
Leaf Space operates a fully owned, globally distributed network of ground stations, empowering satellite operators to communicate with their spacecraft in the simplest and most flexible way. Leaf Space enables TT&C (Telemetry, Tracking, and Command) and payload data transmissions via an easy-to-use interface, a proprietary autonomous scheduling software, and its network’s global coverage. Founded in 2014, Leaf Space has offices in Lomazzo (Italy) and in Delaware (US).