As a DevSecOps Engineer you should be responsible for ensuring the security of software, and deploying security scan plugins as part of CI/CD pipeline through automation (Terraform).
Designing, implementing, maintaining, and optimizing security tools (examples: App vuln management, Vault-Secrets management) needed to protect organizations’ data, systems, and infrastructure.
Expert knowledge of niche computer security software’s, such as Burp Suite, Nessus, SAST tools-Static Application Security Testing, CWPP (Container Workload Protection Platform)
Qualifications:
Required:
- Experience or formal education in any combination of the following areas: Software development, application administration, scripting/coding, security analysis and threat detection
- Experience with complex application troubleshooting and performance tuning
- Experience in Software development and support
- Experience providing Security services (For example; application/Infrastructure vulnerability management, firewalls, Cloud security, security testing and authentication services)
- Knowledgeable in Integration services (CI/CD platforms, configuration management, cloud services).
Accountabilities:
- Develops, tests, deploys, and iteratively improves product capabilities and features in collaboration with product managers, and other engineers on the product team
- Develops high quality applications that are secure, easy to operate, difficult to break, and extremely observable with measurable results.
- Responsible for all technical aspects of the product application lifecycle including, code, infrastructure, data, security, and CICD
- Contributes to product engineering and software standards.
- Continuously develops self and supports the development of others.
Education/Experience:
- Bachelor's degree in computer science or equivalent training required.
- 10+ years related experience required
- Security certification: AWS, CISSP/CCSP/Security+ -- Desirable
- Programming: Python, NodeJS, Java, Terraform. — Required