Senior DevSecOps Engineer (Cloud Security & Infrastructure)
- Onsite
- All infrastructure & security jobs
- FullTime
- Tech
About the role
At Too Good To Go, we have an ambitious goal: to inspire and empower everyone to fight food waste together. 40% of all food produced in the world is wasted, contributing to 10% of global greenhouse gas emissions. We’re more than an app, we are a certified B Corporation working across 19 countries to drive change through our marketplace app, educational tools, legislative work, and logistics initiatives.
We’re growing fast: Our community of 118 million registered users and 246,000 active partners across 19 countries, have together already prevented 443+ million meals from going to waste - avoiding over 1.198.000 tonnes of CO2e!
Too Good To Go is looking for a new Senior DevOps Engineer to build and further enhance our highly scalable infrastructure by creating tooling, automating and improving reliability. You will be part of the infrastructure team working in our Copenhagen office.
Your mission will be building a secure and globally scalable infrastructure. What you help build will be used daily by our millions of users, our partners, and our internal business stakeholders.
We are looking for a new Senior DevSecOps Engineer to join our infrastructure team in Copenhagen. In this role, you will bridge cloud engineering and information security, owning our AWS security posture, driving compliance automation, and embedding shift-left security directly into our global deployment pipelines.
The role
Cloud Security Leadership: Own and optimize AWS Security Hub, GuardDuty, IAM, and WAF configurations to maintain a robust defense posture across multi-region environments.
Shift-Left Security Pipelines: Integrate automated vulnerability scanning, container image checking, dependency auditing, and Policy-as-Code directly into GitHub Actions and ArgoCD pipelines.
Infrastructure as Code (IaC): Maintain and evolve our OpenTofu codebase with embedded security guardrails, ensuring least-privilege access patterns and encryption standards are enforced at build time.
Threat & Vulnerability Remediation: Work alongside software engineering teams to prioritize, triage, and remediate reachability-based vulnerabilities and infrastructure misconfigurations without slowing down delivery velocity.
Compliance & Framework Alignment: Partner with our Security team to map our infrastructure controls against industry benchmark frameworks (NIST CSF, CIS AWS Benchmarks) and support ongoing audit readiness.
Tech Stack
Cloud & Compute: AWS (EKS, RDS Aurora, OpenSearch, Lambda, Redshift)
IaC & Automation: OpenTofu, Docker, Kubernetes
CI/CD & GitOps: GitHub Actions, ArgoCD, Jenkins
Security & Governance: AWS Security Hub, GuardDuty, IAM, WAF, Container/Dependency Scanning (Aikido)
Observability: Grafana, Prometheus, Mimir, Graylog
Requirements
Proven DevSecOps/Cloud Security Focus: 4+ years of hands-on experience in cloud infrastructure with a heavy specialization in AWS cloud security, container security, and DevSecOps tooling.
AWS Security Expertise: In-depth working knowledge of AWS security architecture, multi-account governance (AWS Organizations/Control Tower), IAM complex policies, KMS key management, and AWS Security Hub prioritization.
IaC & Policy-as-Code: Strong proficiency in OpenTofu/Terraform and experience implementing static analysis/security scanners (e.g., Checkov, tfsec, OPA) within CI/CD pipelines.
Security Framework Knowledge: Practical experience implementing controls aligned with CIS AWS Benchmarks, NIST CSF, or SOC 2 Type II Trust Services Criteria.
Engineering Background: Solid proficiency in Go or Python for automation, custom tooling, and security API integrations.
Kubernetes & Network Security: Experience securing EKS clusters, network policies, secrets management, and ingress controls for high-traffic mobile/web applications.
Our values
We fight together: food waste is a big beast to fight. We can do it if we fight together as Waste Warriors with no ego. We believe in a #oneteam.
We raise the bar: we always push for more. We work smart, smash barriers and elevate one another.
We keep it simple: our ambitions are bold but our solutions are simple
We build a legacy: we’re proud of the change we’re driving.
We care: we always look out for each other. Caring is also about the way we do business. We do the right thing.
What We Have To Offer
An opportunity to work in a global social-impact company and certified B Corporation! where you can see a real and tangible impact in your role.
To be an integral member of our defined product teams. We are eager for you to make an impact and contribute to the product scope and development; Your insights are valuable, and we are here to listen.
Work-life balance is important to us! Focus on the job to be done, not the hours spent, there is no need for overtime.On-call duty is not part of the job, but can be additionally agreed upon should you and your manager both wish it. We believe happy environments create happy employees.
We trust in our employees and encourage an autonomous environment that provides several opportunities for employees to contribute, develop and take ownership of their work in a way that works for them.
To be part of an international company, with over 1,200+ colleagues across 17 countries that are on the same important mission.
An informal environment, working alongside a tech team of over 90 passionate people, we celebrate our differences and our successes and have a strong values-driven team culture.
How to apply
We take recruitment very seriously, so please carefully read everything we have written above.
Please also check our website and international media in order to get a good overview of Too Good To Go.
Please submit your CV in English.
Please note that we only accept applications coming through our platform. No CV or Cover Letter will be accepted by email or LinkedIn direct messaging.
Job Ref: #LI-CT1