DevSecOps Engineer
Job Description
Description
- Responsibilities:* Organize and prioritize security operations requests through internal and external channels
* Conduct annual security assessments for the division and complete prescribed remediation post-assessment to improve the division's security maturation in line with corporate expectations and timelines
* Resolve or manage the divisional resolution of security issues escalated from corporate security
* Analyze and assess vulnerabilities in our on-prem, hybrid, and cloud-hosted solutions in addition to the pipelines supporting the development of mission-critical PS applications
* Collaborate with corporate security and engineering teams to assign appropriate risk scores to discovered vulnerabilities
* Investigate available tools and countermeasures to remedy detected vulnerabilities. An investigation may require cross-divisional or corporate collaboration
* Implement and maintain on-prem, hybrid, and cloud-hosted security solutions and configurations. Foster an environment that supports the continued management and usage of these solutions
* Provide technical guidance and hands-on engineering to ensure security tools are implemented to support security objectives
* Conduct randomized tests for compliance with security policies and procedures
* Work with divisional leadership in developing security strategies and guidance documentation that drives the vision
* Collaborate with engineering in developing automated security testing to validate adherence to secure coding best practices
* Communicate to business customers, technical teams, and leadership consistently, making complex topics, issues, and solutions clear, simple, and understandable
* Serve as a technical resource for all cybersecurity solutions. Stay up to date on Cybersecurity trends and advances
* Manage vulnerability remediation and adhere to timelines based on corporate security policies
* Manage working groups, communication, and assigned action items during product-related security incidents
* Work with architecture and engineering teams to incorporate cloud-security best practices
* Support CloudOps in instituting Red Blue testing at a frequency
* Provide off-hour, on-call support for security incidents, assembling divisional support teams to provide up to 24/7 remediation, as required by the severity of the incidents
- Qualifications
* Superior verbal and written communication skills, with the ability to communicate complex technical solutions to non-technical audiences
* Deadline-driven, team-oriented, be a self-starter, have great people skills, a strong work ethic, and be enthusiastic, ambitious, as well as highly organized
* Flexible. Able to independently manage multiple efforts at once while maintaining professionalism under pressure
* A passion for improving the customer experience and a track record of successful interactions with internal/external clients
* Excellent troubleshooting skills
* A technical leader with an ability to inspire and support peers
* Strong organization and prioritization skills. A proven ability to react positively and decisively to change
* 3-5 years of technical experience
* Experience or willingness to learn Azure Security Center and AWS Security Tools such as Amazon GuardDuty, Amazon Inspector, Amazon Macie, AWS Identity and Access Management (IAM) Access Analyzer, AWS Systems Manager, and AWS Firewall Manager. Experience with OWASP and Dynamic and Static testing tools
* Strong scripting skills
* Experience with Virtualization with VMWare or similar technology
* Knowledge of OS Platform (Windows) Security, IIS, Services, Cert Management and General Configuration. Understanding of network and Information Security best practices
* Expertise in collaboration and prioritization using Confluence, Jira, and Slack
* Working experience in Agile Scrum and SAFe software development methodologies
* Experience with application data security, threat intelligence, cloud security configurations, risk assessment; third party vendor management
* Experience securing cloud environments with an understanding of cloud security infrastructure and cloud security principles
* Experience supporting security solutions on-premise and in the cloud
* Bachelor degree in Computer Science, Engineering, Mathematics, Information Systems or related field preferred
* Valued Certifications: CompTIA Security+, CompTIA Cybersecurity Analyst (CySA+), AWS Professional, AWS Security
Date Posted
03/02/2023
Views
1
Positive
Subjectivity Score: 0.9
Similar Jobs
Regional Marketing Executive, Great Lakes - Blueprint Medicines, a Sanofi company
Views in the last 30 days - 0
View Details