Security/ DevSecoOps Engineer
Role details
Job location
Tech stack
Job description
The client is revamping their DevOps practice and building a future state 3-5 year roadmap. Within this roadmap they will be migrating from Azure ADO to GitHub for CI/CD. During this maturity program they are hiring a DevSecOps Engineer to ensure a security first mindset. This resource will be working under the Security Team assisting to build the framework and self service model for DevOps Engineers. This includes but is not limited to: - Champion Secure-by-Design and Defense-in-Depth principles throughout the software development lifecycle - Apply OWASP (e.g., Top 10, ASVS) and MITRE ATT&CK/CWE frameworks to evaluate and communicate threats and control gaps - Code Review - SAST and SCA Auditing - CNAPP Auditing - Integration of Scanning Tools into CI/CD Pipeline - Act as SME in various cross-functional team calls - Prioritization of backlog and sprint selection for security items The Application Security Engineer plays a crucial role in overseeing the security of development operations (DevSecOps) for the organization. Reporting directly to the Deputy CISO and with key relationships to the Development Operations and IT Operations teams, this role provides engineering, analytical and operational expertise across a range of AWS and Azure services and other cloud-based security solutions. Primary Responsibilities (Securing the Software Development Life Cycle) Security oversight of the continuous delivery, continuous integration (CI/CD) pipeline Combination of static and dynamic application security testing (SAST/DAST), to identify code bugs and application issues. Software composition analysis (SCA) to track all open-source components in the developer's code base. Threat modelling to identify architectural design faults and potentially exposed targets of attack. Evaluate and advise on service deployment into a microservices architecture (Kubernetes), and operational functions relative to security best practices and compliance requirements Maintain security issue tracking and reporting using Azure DevOps (ADO) currently prior to moving to GitHub Develop and maintain documentation of target state designs and security roadmaps., Prefer experience in: Reading / reviewing .NET / C#, JavaScript / TypeScript Azure or AWS Cloud Azure DevOps or similar SCM / bug tracking SAST / SCA technologies CNAPP or other cloud posture tools (CSPM) Manual security testing (pen testing) of web applications (burp suite) Tooling: Which SAST/SCA tools are currently in use? Checkmarx (largely going through and auditing, not as much configuration) and while the Checkmarx tool is preferred, it's not an absolute mandate. What CNAPP or CSPM tools are in place (e.g., Wiz, Prisma Cloud, Orca)? Prisma What AAS services are most heavily used in the platform? EKS, any Kubernetes experience is certainly a bonus
Requirements
Application security, Penetration test
Benefits & conditions
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)