Job Description
This person is the security guard embedded in the DevOps process. Instead of bolting security on at the end, they build it into every step — scanning code for vulnerabilities, locking down containers, managing digital certificates/secrets, and making sure the company can prove it's meeting compliance requirements. Their job is to stop security problems before they ship, not clean them up after.
\n
Responsibilities
\n
- \n
- Define and enforce application deployment security design across Kubernetes, Service Fabric, and legacy systems.
- Implement NeuVector for container runtime security and vulnerability detection.
- Neuvector is a security platform built specially for containerized environments
- Manage JFrog code scanning for artifact integrity and compliance.
- Core product is Artifactory
- Oversee PKI lifecycle management using OpenBoa for secure secrets distribution.
- Openboa is opensource secrets management system
- Harden DevOps tooling (TerraKube, AWX) and IaC templates for secure deployments.
- Develop mitigation strategies for vulnerabilities in containers, VMs, and supporting infrastructure.
- Automate compliance reporting and policy enforcement (Policy as Code).
- Conduct threat modeling and risk assessments.
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Required Skills
\n
- \n
- Kubernetes security (network policies, RBAC, container hardening).
- DevSecOps tools: SonarQube (for code quality and security analysis – catches problems early in development), Snyk (developer first security platform that finds/fixes vulnerabilities across the whole software stack), OWASP ZAP (Opensource tool for finding security vulnerabilities), Trivy (opensource vulnerability scanner), NeuVector.
- Compliance automation and reporting frameworks.
- Secrets management and secure artifact handling.
- Experience with CI/CD security integration (SAST, DAST, SCA).
- Familiarity with cloud-native security (IAM, security groups, audit logging).
\n
\n
\n
\n
\n
\n
\n
Nice to Have
\n
- \n
- Certified DevSecOps Professional (CDP) or equivalent.
- Experience with GitOps security workflows.
- Knowledge of threat modeling and risk assessment.
\n
\n
\n
\n
