Search

DevSecOps Engineer

PublishedPublished: 6/14/2022
Real Estate

Job Description

This person is the security guard embedded in the DevOps process. Instead of bolting security on at the end, they build it into every step — scanning code for vulnerabilities, locking down containers, managing digital certificates/secrets, and making sure the company can prove it's meeting compliance requirements. Their job is to stop security problems before they ship, not clean them up after.

\n

Responsibilities

\n

    \n
  • Define and enforce application deployment security design across Kubernetes, Service Fabric, and legacy systems.
  • \n

  • Implement NeuVector for container runtime security and vulnerability detection.
  • \n

  • Neuvector is a security platform built specially for containerized environments
  • \n

  • Manage JFrog code scanning for artifact integrity and compliance.
  • \n

  • Core product is Artifactory
  • \n

  • Oversee PKI lifecycle management using OpenBoa for secure secrets distribution.
  • \n

  • Openboa is opensource secrets management system
  • \n

  • Harden DevOps tooling (TerraKube, AWX) and IaC templates for secure deployments.
  • \n

  • Develop mitigation strategies for vulnerabilities in containers, VMs, and supporting infrastructure.
  • \n

  • Automate compliance reporting and policy enforcement (Policy as Code).
  • \n

  • Conduct threat modeling and risk assessments.
  • \n

\n

Required Skills

\n

    \n
  • Kubernetes security (network policies, RBAC, container hardening).
  • \n

  • DevSecOps tools: SonarQube (for code quality and security analysis – catches problems early in development), Snyk (developer first security platform that finds/fixes vulnerabilities across the whole software stack), OWASP ZAP (Opensource tool for finding security vulnerabilities), Trivy (opensource vulnerability scanner), NeuVector.
  • \n

  • Compliance automation and reporting frameworks.
  • \n

  • Secrets management and secure artifact handling.
  • \n

  • Experience with CI/CD security integration (SAST, DAST, SCA).
  • \n

  • Familiarity with cloud-native security (IAM, security groups, audit logging).
  • \n

\n

Nice to Have

\n

    \n
  • Certified DevSecOps Professional (CDP) or equivalent.
  • \n

  • Experience with GitOps security workflows.
  • \n

  • Knowledge of threat modeling and risk assessment.
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...