We are excited to welcome an experienced and highly motivated DevSecOps Engineer to our team. In this role, you will play a pivotal part in designing, implementing, and maintaining secure, reliable, and scalable systems for our online websites. If you have a passion for cybersecurity and want to contribute to cutting-edge projects, we encourage you to apply!
Key Responsibilities:
Secure and Scalable Systems: Collaborate with development, operations, and security teams to design and implement systems that are both secure and scalable, ensuring the utmost reliability.
Automated Security Checks: Automate security and compliance checks into the software development and delivery process, adhering to industry standards and regulations.
Security Policies and Procedures: Establish and maintain security policies and procedures in line with best practices and compliance standards to safeguard our systems.
Vulnerability Management: Continuously enhance our system s security by identifying and promptly remediating vulnerabilities and weaknesses.
Proactive Threat Detection: Monitor security events to detect and respond to potential threats promptly, ensuring all incidents are recorded and resolved within agreed SLAs.
Incident Prevention: Implement preventive measures to reduce the overall number of security incidents.
Vulnerability Assessment: Maintain a comprehensive vulnerability management program to identify and address vulnerabilities within our systems.
Secure Code Development: Work closely with the development team to ensure all new code is developed with security in mind.
Cybersecurity Training: Provide guidance and training to team members on secure coding practices and cybersecurity.
Key Performance Indicators (KPIs):
Vulnerability Management:
Percentage of identified vulnerabilities remediated within defined timelines.
Number of critical vulnerabilities addressed per quarter.
Time taken to remediate vulnerabilities.
Incident Response:
Mean time to detect and respond to security incidents.
Number of incidents reported per quarter.
Percentage of incidents resolved within defined timelines.
Compliance:
Percentage of successful audits per year.
Number of compliance violations identified and resolved per quarter.
Time taken to address compliance violations.
Security Automation:
Percentage of security checks automated within the development pipeline.
Number of manual security checks reduced through automation.
Time taken to implement new security checks into the pipeline.
Collaboration:
Number of cross-functional security training sessions conducted per year.
Percentage of development teams using secure coding practices.
Number of completed cross-functional security initiatives per quarter.
Key Requirements:
Bachelor s degree in computer science, Engineering, or a related field.
Minimum of 5 years of experience in DevSecOps or a similar role.
Strong understanding of DevOps principles, tools, and practices.
Proficient in cloud computing platforms like AWS or Azure.
Experience with containerization technologies (e.g., Docker, Kubernetes).
Thorough understanding of security principles, including authentication, authorization, encryption, and network security.
Familiarity with security testing and vulnerability scanning tools.
Expertise in web application firewalls (WAF), intrusion detection and prevention systems (IDS/IPS), and security information and event management (SIEM) systems.