STSY - DevSecOps Engineer

Yulista Holding, Llc
Huntsville, AL, United States
16 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Adobe InDesign Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 JIRA Build Automation Microsoft Azure Bash Shell Static Program Analysis Code Review Continuous Delivery
+31 more
Continuous Integration Github Issue Tracking Systems Cisco Nexus Switches PCI Data Security Standards Windows PowerShell Ansible Fortify (Software) Security Information and Event Management Amazon Simple Notification Service (SNS) Software Engineering SonarQube Systems Integration Scripting Cloud Platform System Software Security Gitlab Git Cloudformation Infrastructure Automation Frameworks Information Technology Deployment Automation Functional Programming Puppet Amazon Simple Queue Service (SQS) Terraform Prisma Cloud Platform Software Version Control Devsecops Jenkins Artifactory

Job description

StraitSys is looking for a DevSecOps Engineer with AWS experience to support the Federal Bureau of Investigation (FBI). The DevSecOps Engineer will meet the needs of our software development lifecycle. This role will use technical skills for the design and implementation of various CI/CD patterns while abiding by industry standards and policies. Often taking part in design and code reviews and offering direction to ensure project scoping activities match architectural goals and specifications. When new applications are introduced or current ones undergo changes, the DevSecOps Engineer will frequently work with partners in other divisions to provide build solutions. Other responsibilities include documenting DevSecOps processes and ensuring that the DevSecOps platforms are up to date and properly maintained. The DevSecOps Engineer will have a significant impact on the team as a member in charge of the enterprise’s engineering and maintenance., * Create, develop, and implement solutions to address infrastructure and security requirements.

  • Identify the needs for build automation, designing, and implementing CI/CD solutions.
  • Consult on DevSecOps requirements from diverse application/line of business partners.
  • Create plug-and-play/reusable solutions and patterns for CI/CD pipelines.
  • Create, develop, and implement automation and system integration for various build platforms.
  • Publish and disseminate CI/CD best practices, patterns, and solutions.
  • Ensure that the service’s uptime and response time SLAs/OLAs are met or surpassed.
  • Build or maintain CI/CD building blocks and shared libraries proactively for app and development teams to enable quicker build and deployment.
  • Design action plans to address CICD platform/tools/solutions’ shortcomings and difficulties.
  • Actively participate with team members and contractors/vendors to prevent or quickly address problems.
  • Troubleshoot, identify, and fix problems in the DevSecOps domain.
  • Ensure incident tracking tools are updated in accordance with established norms and processes, gather all essential data and document any discoveries and concerns.
  • Identify management concerns and problems, assess them, and offer prompt solutions and/or escalation.
  • Align with technological Systems/Software Development Life Cycle (SDLC) processes and industry-standard service management principles (such as ITIL).
  • Create and publish engineering platforms and solutions.

Requirements

  • Comprehensive technical expertise in a variety of DevSecOps toolkits, including Ansible, Jenkins, Artifactory, Jira, Black Duck, Terraform, Git/Version Control Software, or comparable technologies.
  • Familiarity with information security frameworks and standards.
  • Knowledge of DevOps Automation (TerraFrom, GitLab, GitHub, GitHub Actions).
  • Knowledge of Prisma cloud, SIEM, SOC, Nesus, Crowd strike or similar services.
  • Familiarity with API Security, Container Security, AWS Cloud Security.
  • Familiarity with Amazon AWS policy, configuration, and security management tools.
  • Proven capacity for thinking leadership and a highly creative problem-solver.
  • Excellent analytical and interpersonal skills.
  • Ability to express technical information clearly at different organizational levels.
  • Knowledge of PCI-DSS, HIPPA, SOX, GDPR, and CCPA Standards and Policies and the associated certification and audit processes.
  • CISM, CISSP or other Security Certifications.
  • Auditing and Compliance Certifications such as CISA, PCI-ISA, and PCIP.
  • Experience with infrastructure as code (IaC) tools (Puppet, Ansible, AWS CloudFormation or equivalent).
  • Strong understanding of cloud computing platforms (AWS, Azure) and infrastructure services.
  • Demonstrated experience using AWS to include S3, EC2, SNS, SQS, and Lambda.
  • Experience with PowerShell or other scripting languages like Bash.
  • Experience with aws-cli (and other container images) as it relates to automation within CI/CD pipelines.
  • Experience with industry standard Static Code Analysis (SCA) tools such as SonarQube, Nexus IQ Server, Fortify, JFrog Artifactory., * Active Top Secret Clearance.
  • Bachelor’s degree in Engineering, Computer Science, Management Information Systems or related discipline.
  • 5+ years of related job experience.
  • Must be a US Citizen.
  • Ability to successfully pass a pre-employment drug test.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all