Overview
We are seeking a DevOps Engineer with expertise in vulnerability management and patching for Adobe products, cURL, Jenkins, Notepad++, NumPy, and Vim. The ideal candidate will be responsible for identifying, assessing, and mitigating security vulnerabilities in these tools while ensuring system stability, compliance, and automation of patching processes.
Responsibilities
- Vulnerability Management: Identify, analyze, and remediate security vulnerabilities in Adobe, cURL, Jenkins, Notepad++, NumPy, and Vim across development and production environments.
- Patch Deployment: Apply security patches and updates efficiently to mitigate risks while ensuring minimal downtime.
- Automation & Scripting: Develop automation scripts (PowerShell, Bash, Python, Ansible) to streamline vulnerability patching.
- Configuration Management: Utilize SCCM, Intune, Ansible, Puppet, or Chef to enforce secure configurations and manage patch deployments.
- CI/CD Pipeline Security: Ensure Jenkins updates and security fixes are integrated into CI/CD pipelines to prevent pipeline vulnerabilities.
- Monitoring & Compliance: Implement monitoring solutions and security best practices to ensure compliance with CIS, NIST, ISO 27001, and PCI-DSS.
- Incident Response: Work with security teams to investigate and remediate security incidents related to vulnerabilities in the specified software.
- Documentation & Reporting: Maintain accurate documentation of patching activities, vulnerability reports, and risk assessments.
Requirements
- Required Skills & Experience:
- xx years of experience in DevOps, IT Security, or System Administration.
- Strong experience with vulnerability patching for Adobe, cURL, Jenkins, Notepad++, NumPy, and Vim.
- Proficiency in Windows and Linux administration, including package management tools (APT, YUM, Chocolatey, Winget).
- Experience with patch management tools (WSUS, SCCM, Intune, or third-party patching solutions like Ivanti, Qualys, or Tenable).
- Expertise in PowerShell, Bash, or Python scripting for automation and deployment.
- Hands-on experience with Jenkins administration, security hardening, and plugin management.
- Familiarity with vulnerability scanning tools (Nessus, Qualys, Tenable, Rapid7).
- Understanding of CI/CD security best practices and open-source security risks.
- Knowledge of cloud platforms (AWS, Azure, GCP) and infrastructure-as-code (Terraform, Ansible).
- Collaborate closely with Dev teams and work on remediation solutions by understanding application architecture.
- Preferred Qualifications:
- Certifications such as AWS Certified DevOps Engineer, Microsoft Certified: Security Operations Analyst, RHCE, or CISSP.
- Experience working in Telecom industries.
- Prior experience with endpoint security and system hardening.