DevSecOps Engineer
Job description
DevSecOps Engineer at Bamboohr.
About the role
As a DevSecOps Engineer at Bamboohr, you will play a role in integrating security practices within the DevOps process. Your expertise will help streamline development and operational workflows while ensuring that security is a fundamental component of the software development lifecycle. You will collaborate with cross-functional teams to enhance application security, automate security testing, and implement best practices in cloud environments. This position is ideal for someone who is about security and automation and is looking to make a significant impact in a dynamic and innovative company.
Key facts
What you'll do
- Design and implement security solutions throughout the software development lifecycle, ensuring that security is integrated from the start.
- Collaborate with development teams to establish security requirements and best practices for application development.
- Automate security testing processes using tools such as static and dynamic analysis, vulnerability scanning, and penetration testing.
- Monitor and analyze security incidents, providing timely responses and remediation strategies to minimize risks.
- Develop and maintain security policies, procedures, and documentation to ensure compliance with industry standards and regulations.
- Conduct security assessments and audits of applications and infrastructure to identify vulnerabilities and recommend improvements.
- Work closely with operations teams to secure cloud environments and manage access controls and identity management.
- Provide training and guidance to development and operations teams on secure coding practices and security awareness.
- Stay up-to-date with the latest security trends, threats, and technologies to continuously improve the security posture of the organization.
- Participate in incident response planning and execution, ensuring that security incidents are handled effectively and efficiently.
- Collaborate with external security partners and vendors to enhance the organization's security capabilities.
- Contribute to the development of a culture of security within the organization by promoting security best practices and awareness.
Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related field, or equivalent experience.
- A minimum of 3 years of experience in DevSecOps, security engineering, or a related role.
- Proficiency in scripting and automation using languages such as Python, Bash, or PowerShell.
- Experience with CI/CD tools such as Jenkins, GitLab CI, or CircleCI, and familiarity with containerization technologies like Docker and Kubernetes.
- Strong understanding of cloud security principles, particularly in AWS, Azure, or Google Cloud Platform.
- Knowledge of security frameworks and standards such as NIST, ISO 27001, or OWASP.
- Familiarity with security tools for vulnerability management, such as Nessus, Qualys, or Burp Suite.
- Excellent problem-solving skills and the ability to work collaboratively in a fast-paced environment.
- Strong communication skills, both verbal and written, with the ability to convey complex security concepts to non-technical stakeholders.
Nice to have
- Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or AWS Certified Security Specialty.
- Experience with infrastructure as code (IaC) tools like Terraform or CloudFormation.
- Knowledge of compliance frameworks such as PCI-DSS, HIPAA, or GDPR.
- Familiarity with security information and event management (SIEM) tools.
- Experience in threat modeling and risk assessment methodologies.
Skills & tools
- Proficient in security automation and orchestration tools.
- Strong understanding of network security concepts and practices.
- Familiarity with application security testing tools and methodologies.
- Experience with version control systems, particularly Git.
- Knowledge of Agile and DevOps methodologies.
- Proficient in using monitoring and logging tools to ensure security visibility.
Practical notes
- This position is based in Washington, D.C., and may require occasional travel for training or conferences.
- The salary for this role is competitive and will be determined based on your experience and qualifications.
- Bamboohr is committed to fostering a diverse and inclusive workplace and encourages applications from all qualified candidates.
- Interested candidates can apply through the provided link: https://technalink.bamboohr.com/careers/32.
- For any inquiries regarding the application process or the role, please reach out to the HR department at Bamboohr.
META
Company: Bamboohr
Title: DevSecOps Engineer
Listed
location: Washington, District of Columbia
Job type: Full-time