We are looking for an individual contributor to join our security team. The ideal candidate will have hands-on experience integrating security into the CI/CD pipeline, securing cloud environments, automating security controls and fixing security issues. You will collaborate with DevOps and engineering teams to embed security into every phase of development and deployment, ensuring secure cloud infrastructure and application delivery.
Key Responsibilities
------------------------
DevSecOps & Secure Development
Integrate security testing tools into the CI/CD pipeline, including static analysis, dynamic analysis, and dependency scanning.
Enforce secure coding practices and conduct regular code reviews to identify security vulnerabilities.
Collaborate with DevOps teams to implement secure containerization practices (e.g., Docker, Kubernetes, and serverless architectures).
Ensure security throughout the software development lifecycle (SDLC), from development to production.
Cloud & Infrastructure Security
Secure cloud environments (AWS, Azure, GCP) using
best security practices
.
Implement and manage
identity and access management (IAM)
policies and RBAC.
Security Automation & Tooling
Develop and maintain automation scripts using Go, Python, Bash, or PowerShell to implement security controls and streamline security processes.
Automate security controls using
IaC (Terraform, CloudFormation, etc.)
Required Skills & Qualifications
-------------------------------------
Over 5 years of experience in Cloud Security and DevSecOps.
Proficient in scripting and automation using languages like Go, Python, Bash, PowerShell, etc.
In-depth understanding of zero-trust architecture and security best practices.
Familiar with security frameworks such as NIST, CIS, OWASP, and MITRE ATT&CK.
Excellent analytical and problem-solving abilities.