- Help build and execute our software supply chain security strategy to expand upon State Street’s ability to deploy secure-by-default open-source artifacts, etc., across the enterprise.
- Partner with Engineering teams leads to create, implement, and apply DevSecOps, and AppSec principles and processes.
- Assist application teams with onboarding to the adopted security tools/technologies; working with vendors to troubleshoot the platform and issues related to such integrations.
- Deliver and communicate reporting via dashboard, and metrics.
- Develop and maintain supply chain security and DevSecOps documentation.
- Work with teams to continuously improve DevSecOps, & Software Supply Chain Security processes and tools.
- Deliver tasks based on project objectives; technically support projects through to completion.
Requirements
- 14+ years of relevant combined experience across development, CI/CD, software supply chain security and application security.
- Experience with application security tooling and its operations with modern CI/CD, and DevSecOps best practices.
- Experience partnering with Dev community to influence without authority to adopt application security best practices, and tooling.
- Bachelor's degree in Computer Science, Information Technology, Information Security, Engineering, or a related discipline.
- Certifications like Security+, CISSP are highly desirable
- Previous experience developing software in technologies such as Java, .Net, Python, and Node.js etc.
- Experience in cloud technologies such as Azure and AWS.
- Extensive experience in developing and managing solutions for application and software supply chain security including managing artifact caches, locking down artifact sourcing, and continuous security assessment.
- Experience with automation and orchestration tools, such as Ansible, Terraform, or Kubernetes, is valuable.
- Proven technical solutioning experience with current and emerging technologies including, but not limited to: Agile Development, DevOps, Cloud Engineering, System Hardening, DevSecOps, Cybersecurity, Cloud Security.
- Excellent verbal and written communication skills across internal and external organizations.
- Ability to prioritize and manage several projects or priorities simultaneously.
Core Competencies
Demonstrates extensive expertise in Software Supply Chain Security and DevSecOps, with a strong focus on application security tooling, CI/CD processes, and cloud technologies. Proven ability to collaborate with engineering teams to enhance security practices and deliver effective solutions.
Highest-signal resume keywords
- 14+ Years Experience in Software Supply Chain Security
- Application Security Tooling Operations
- DevSecOps Best Practices
- Cloud Technologies: Azure and AWS
- Certifications: Security+ and CISSP
ATS Optimization Keywords
Hard Skills
- Java
- C#
- Python
- Node.js
- CI/CD
- DevSecOps
- Agile Development
- Cybersecurity
- System Hardening
- Automation and Orchestration
Soft Skills
- Excellent Verbal Communication
- Excellent Written Communication
- Project Management
- Prioritization
Certifications & Qualifications
Industry Keywords
- Software Supply Chain Security
- Application Security
- DevSecOps
- Cloud Security
- Continuous Security Assessment
Tools & Technologies
- Ansible
- Terraform
- Kubernetes
- Security Tools
- Dashboard Reporting