DevSecOps Engineer
Job Description
The Cloud, DevSecOps, and Platform & Security Engineering teams work with developers and the IT staff to oversee the code releases, combining an understanding of both engineering and coding. From creating and implementing systems software to analyzing data to improve existing ones, a DevSecOps Engineer increases productivity in the workplace. They understand the software development lifecycle, have a clear understanding of various automation tools for developing digital pipelines (CI/ CD pipelines), and a Shift-Left / Security as a day-0 requirement mentality to Security, integrating key tools and processes into the Secure Software Development Lifecycle (SSDLC). You will be a senior member of the Platform and Security Engineer team within our Enterprise Systems group. You will be responsible for supporting the foundational components for all development work that Geode undergoes. You will actively be working with technology leadership on evaluating and incorporating new development technologies and processes while helping to lead a team of Cloud, DevOps, and Security engineers to build fast, efficient applications and provide technical guidance on projects. The ideal candidate will bring a wide range of experiences and a proven track record of DevSecOps and leading DevSecOps teams and building a culture of excellence. The role reports to Geode’s Director of Platform & Security Engineering.
- Experience with major cloud vendors (AWS, Azure, GCP)
- Experience with Docker, Kubernetes, Terraform, and Ansible
- Experience with Container / Kubernetes security
- Experience with RabbitMQ, SQL, and NoSQL
- Experience with Datadog and/or the Prometheus stack
- Experience with Git and hosted providers such as GitLab, GitHub, or Bitbucket
- Experience working with Java and Python technology stacks
- Experience scripting with Bash, Python, and PowerShell
- Experience with various SAST, DAST, and IAST tools
- Strong foundation and experience working in a Linux operating system environment
- Familiarity with vulnerability management, reporting and remediation, including CVSS, CVE, CWE, SCAP and other standards. Engineers that have been through security certifications such as SOC2 or ISO27001 are preferred.
- Experience with cybersecurity risk, threat, and control mapping, including common issues such as the OWASP top 10 and MITRE ATT&CK frameworks
- Principles of Site Reliability Engineering including High Availability, Self-Healing, Rapid Elasticity/Autoscaling
- High attention to detail and quality
- Excellent verbal and written communication skills
- Building and setting up new development tools and infrastructure
- Ability to be a self-starter and solutions-oriented
- Experience with agile/scrum
- Experience with common penetration testing and vulnerability assessment tools
- Security certifications such as GCIA, GCIH, CEH, GIAC, CISSP, Security+
- Cloud provider certifications such as AWS Certified Solutions Architect Professional, AWS DevOps Engineer Professional, AWS Security Specialty, or Azure Security Engineer
- Experience with Identity and Access Management tools, including Certificates Management, Secrets Management (Hashicorp Vault, CyberArk, or AWS Secrets Manager) Privileged Access Management, SAML, and OAUTH2/OIDC
- Familiarity with Financial Services or other highly regulated industries
- Familiarity with GitOps
- Solid understanding of Layer-3 vs Layer-7 networking and impacts on application security
Date Posted
11/04/2022
Views
10
Similar Jobs
Android Engineer - Customer Engineering - Biofourmis
Views in the last 30 days - 6
Biofourmis is a rapidly growing digital health company that develops softwarebased therapeutics to improve patient outcomes The company has a global f...
View DetailsFresh Connect Product Manager - About Fresh
Views in the last 30 days - 6
About Fresh is a nonprofit organization that aims to expand access to fresh food empowering individuals to make healthy choices They are seeking a Pro...
View DetailsContracts Manager - Nimbus Therapeutics
Views in the last 30 days - 14
Nimbus Therapeutics is offering a Contracts Manager position with a unique opportunity to contribute to the companys growth and interact with internal...
View DetailsHead of Pharmacovigilance - Nimbus Therapeutics
Views in the last 30 days - 13
The text describes a Head of Pharmacovigilance position at Nimbus a private biotechnology company The role involves leading and developing the Pharmac...
View DetailsEmail Marketing Performance Analyst - 1-800-FLOWERS.COM, INC.
Views in the last 30 days - 5
The Email Marketing Performance Analyst is responsible for analyzing and reporting on email marketing campaigns helping to guide strategy The position...
View Details