Epicareer Might not Working Properly
Learn More
T

Senior DevSecOps Engineer

Salary undisclosed

Apply on


Original
Simplified

Role: Senior DevSecOps Engineer
Location: Remote

Job Type: C2C

Overview:
The Senior DevSecOps Engineer will lead efforts to integrate security into every phase of the software development lifecycle, ensuring that applications and infrastructure are secure by design. This role focuses on the intersection of development, operations, and security, building and automating security solutions, ensuring compliance, and promoting a culture of security awareness within the development teams.

Responsibilities:

  • Security Integration: Implement and maintain security best practices in CI/CD pipelines, ensuring automated testing and code review include security checks.
  • Infrastructure as Code (IaC): Secure infrastructure deployment using IaC tools (e.g., Terraform, Ansible) with integrated security policies.
  • Vulnerability Management: Identify, mitigate, and monitor security vulnerabilities in applications, infrastructure, and networks.
  • Automation: Develop automation scripts for security tasks such as patch management, monitoring, and incident response using tools like Python or PowerShell.
  • Compliance & Audits: Ensure compliance with industry standards (e.g., ISO, SOC, GDPR) and maintain documentation for audits.
  • Collaboration: Work closely with DevOps, security, and development teams to ensure a unified approach to system security.
  • Monitoring & Response: Implement security monitoring solutions, conduct regular security assessments, and respond to incidents promptly.
  • Training & Mentorship: Foster security awareness through training and mentoring developers on secure coding practices.

Qualifications:

  • Experience: 7+ years in DevOps, with 3+ years in a DevSecOps or security-focused role.
  • Cloud Platforms: Expertise in AWS, Azure, or Google Cloud, with a focus on security and compliance.
  • CI/CD Tools: Experience securing CI/CD pipelines using tools like Jenkins, GitLab, or Azure DevOps.
  • Scripting/Automation: Proficiency in scripting languages (e.g., Python, Bash, PowerShell) for automation and security tasks.
  • Security Tools: Hands-on experience with security tools such as Docker Security, Vault, Aqua, or Twistlock for container security, and vulnerability scanning tools like Snyk or OWASP ZAP.
  • Infrastructure as Code (IaC): Deep knowledge of securing IaC with tools like Terraform, Ansible, or CloudFormation.
  • Certifications: Preferred certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or AWS Certified Security Specialty.
  • Soft Skills: Strong communication, problem-solving skills, and a collaborative mindset to drive a security-first culture.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Report this job