Description

Key Responsibilities:
• Security Integration:
• Embed security controls and automation into CI/CD pipelines.
• Implement SAST, DAST, and SCA tools for continuous security assessment.
• Ensure secure coding practices and compliance with OWASP Top 10.
• Infrastructure & Cloud Security:
• Design and implement security for cloud-native architectures (AWS, Azure, GCP).
• Manage secrets, IAM policies, and network security configurations.
• Monitor and respond to infrastructure vulnerabilities and threats.
• Automation & Tooling:
• Develop and maintain scripts/tools for automated security checks.
• Integrate security tools like HashiCorp Vault, Aqua, Prisma Cloud, etc.
• Maintain IaC security using tools like Checkov, tfsec, or Conftest.
• Governance & Compliance:
• Ensure compliance with industry standards (ISO 27001, SOC 2, GDPR).
• Conduct regular audits and risk assessments.
• Collaborate with product teams to align security with business goals.
• Incident Response & Monitoring:

Education

Bachelor's or Master's degrees