Sr DevSecOps Engineer - DevOps, GCP - Cleaveland,OH

Posted 2 Days Ago
2 Locations
In-Office or Remote
Senior level
Agency • Information Technology
The Role
Lead and mentor DevSecOps efforts across cloud environments: implement vulnerability scanning/remediation, certificate and key management, IAM, security monitoring analytics, automate secure CI/CD pipelines using IaC and tooling, and embed security into development lifecycle.
Summary Generated by Built In

Must have Skills:

Google KMS - Design, Engineering, Ops ; Cloud Security, Hands-on within GCP

Preferred Skills:

Venafi Certificate, Hashi Valut, Certificate management

IBM Guardium Monitoring, Thalys Database protection 

Pipelines, SPAWN creation, building out new Gitlab

Integrating Prisma scanning into the clusters

Have to be deployed through Terraform, IaaC, PaC


Job Description:

Provide leadership in the DevSecOps areas of cloud computing, including: vulnerability remediation and scanning, certificate management, identity and access management, data analysis of security monitoring outputs, and other daily security and compliance efforts. Additionally, you will assist in developing an automated security framework for robust deployment tools and processes, leveraging various scripting languages and open-source solutions.

Responsibilities

• Mentor and lead team members in security concepts

• Contribute to an atmosphere of cross-functional teamwork within the Agile project life-cycle and ability to act within an Agile environment working with user stories, iterative development, continuous integration, continuous delivery, continuous feedback, etc.

• Thorough knowledge of continuous integration, continuous delivery, continuous testing, and configuration management methodologies.

• Thorough knowledge of APM and telemetry tools such as Dynatrace, Elastic, etc.

• Familiarity with Google Cloud Platform, Microsoft Azure, and/or Amazon AWS policy, configuration, and security management tools.

• Experience with security automation and machine learning.

• Proficiency in Linux and scripting languages such as Bash, Python, etc.

• Adhere to technical standards and participate in standards evolution.

• Understand the importance of teamwork and coordinated activities.

• Demonstrate effective communications skills at all organizational levels.

• Thorough knowledge of analytical thinking concepts and techniques.


Required qualifications

• Bachelor's degree in Computer Science or related field or equivalent experience.

• Prior experience (3-5 years) in a production engineering or related position.

• Familiarity with DevOps automation tools such as Digital.ai , Ansible, Atlassian Bitbucket, Prisma Compute, Prisma Cloud

• CISM, CISSP, or other security certifications.

• Familiarity with API security, container security, cloud security

• Knowledge of PCI-DSS, HIPPA, SOX, GDPR, and CCPA standards and policies and the associated certification and audit processes

• Familiarity with information security frameworks/standards (for example, CIS, NIST, RFC2196, etc).

• Auditing and compliance certifications such as CISA, PCI-ISA, and PCIP. Preferred Skills

• Experience working with developers, DevOps, and engineering teams in a dynamic environment to promote/implement the DevSecOps program throughout the organization.

• Experience coordinating and performing vulnerability assessments through the use of automated and manual tools (Tenable, NMAP, etc).

• Ability to review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and application's and determine any reported vulnerabilities that are false positives.

• Capability to prepare security vulnerability and risk management reports for management.

• Leadership and teaming skills to coordinate remediation of vulnerabilities within established timeframes.

• Comprehension in the security areas of key management systems, certificate management, encryption, penetration testing, vulnerability remediation and scanning, security and monitoring tools, etc.

• Experience configuring, implementing, and leveraging computer security and networking diagnostic/monitoring tools.

• Knowledge of Windows and Linux patch management and related information security functions (authentication, encryption, iptables, SSL, ciphers, etc)

• Ability to work with APIs and plugins to integrate security tools into established CI/CD pipelines.

Skills Required

  • Bachelor's degree in Computer Science or related field or equivalent experience.
  • Prior production engineering experience (3-5 years).
  • Hands-on experience with Google KMS and cloud security within GCP.
  • Experience with Terraform and infrastructure-as-code (IaC) and policy-as-code (PaC).
  • Familiarity with DevOps automation tools: Digital.ai, Ansible, Atlassian Bitbucket, GitLab.
  • Experience with Prisma Compute / Prisma Cloud and integrating Prisma scanning into clusters.
  • Proficiency in Linux and scripting languages such as Bash and Python.
  • CISM, CISSP, or other security certifications.
  • Familiarity with API security, container security, and cloud security.
  • Knowledge of PCI-DSS, HIPAA, SOX, GDPR, and CCPA and associated audit/certification processes.
  • Familiarity with information security frameworks (CIS, NIST, RFC2196).
  • Knowledge of APM and telemetry tools such as Dynatrace and Elastic.
  • Experience with vulnerability remediation and scanning and ability to analyze vulnerability data.
  • Familiarity with Tenable and NMAP for vulnerability assessments.
  • Experience with certificate management solutions (Venafi) and key management (Hashi Vault).
  • Experience with IBM Guardium and Thalys Database protection.
  • Experience building pipelines, SPAWN creation, and building out new GitLab instances.
  • Experience working with developers and DevOps teams to implement DevSecOps practices.
  • Auditing and compliance certifications such as CISA, PCI-ISA, PCIP.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
5,017 Employees
Year Founded: 2007

What We Do

Photon.com has emerged as one of the world’s largest and fastest-growing Digital Agencies. We work with 40% of the Fortune 100 on their Digital initiatives and are known for our ability to integrate Strategy Consulting, Creative Design, and Technology at scale. Please visit www.photon.com to learn more about us, how we work, and our customer case studies. Digital Transformation Starts Here.

Similar Jobs

Zeely – AI Admaker Logo Zeely – AI Admaker

Senior Devops Engineer

AdTech • Artificial Intelligence • Marketing Tech
Remote
USA
60 Employees

Creyos Logo Creyos

Devops Engineer

Healthtech • Software
Remote
United States
81 Employees

Sardine Logo Sardine

Devops Engineer

Artificial Intelligence • Fintech • Machine Learning • Software • Financial Services
Remote
United States
130 Employees
160K-200K Annually

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account